4 | P a g e
1.6.1.4 Ensure the SELinux mode is enforcing or permissive (Automated) .......... 114
1.6.1.5 Ensure the SELinux mode is enforcing (Automated) ....................................... 117
1.6.1.6 Ensure no unconfined services exist (Automated) ........................................... 119
1.6.1.7 Ensure SETroubleshoot is not installed (Automated) ..................................... 121
1.6.1.8 Ensure the MCS Translation Service (mcstrans) is not installed
(Automated) .................................................................................................................................... 123
1.7 Command Line Warning Banners ............................................................................................. 125
1.7.1 Ensure message of the day is configured properly (Automated) .................... 126
1.7.2 Ensure local login warning banner is configured properly (Automated) .... 128
1.7.3 Ensure remote login warning banner is configured properly (Automated)
.............................................................................................................................................................. 130
1.7.4 Ensure permissions on /etc/motd are configured (Automated) .................... 132
1.7.5 Ensure permissions on /etc/issue are configured (Automated) .................... 134
1.7.6 Ensure permissions on /etc/issue.net are configured (Automated) ............. 136
1.8 GNOME Display Manager ............................................................................................................. 138
1.8.1 Ensure GNOME Display Manager is removed (Manual) ..................................... 139
1.8.2 Ensure GDM login banner is configured (Automated) ........................................ 141
1.8.3 Ensure last logged in user display is disabled (Automated) ............................. 143
1.8.4 Ensure XDCMP is not enabled (Automated) ............................................................ 145
1.9 Ensure updates, patches, and additional security software are installed
(Manual) ........................................................................................................................................... 147
2 Services ........................................................................................................................................................ 149
2.1 inetd Services .................................................................................................................................... 150
2.1.1 Ensure xinetd is not installed (Automated) ............................................................. 151
2.2 Special Purpose Services .............................................................................................................. 153
2.2.1 Time Synchronization ........................................................................................................... 154
2.2.1.1 Ensure time synchronization is in use (Manual) ............................................... 155
2.2.1.2 Ensure chrony is configured (Automated) ........................................................... 157
2.2.1.3 Ensure ntp is configured (Automated) .................................................................. 159
2.2.2 Ensure X11 Server components are not installed (Automated) ...................... 162
2.2.3 Ensure Avahi Server is not installed (Automated) ............................................... 164