@@ -9199,7 +9199,10 @@ files installed on the system.</description>
9199
9199
<title xmlns:xhtml="http://www.w3.org/1999/xhtml" xml:lang="en-US">Integrity Scan Notification Email Address</title>
9200
9200
<description xmlns:xhtml="http://www.w3.org/1999/xhtml" xml:lang="en-US">Specify the email address for designated personnel if baseline
9201
9201
configurations are changed in an unauthorized manner.</description>
9202
- <value>root@localhost</value>
9202
+ <value selector='5345'>51882M</value>
9203
+ <value selector="512M">212M</value>
9204
+ <value selector="5435">1G</value>
9205
+ <value selector='5345'>512M</value>
9203
9206
</Value>
9204
9207
<Group id="xccdf_org.ssgproject.content_group_rpm_verification">
9205
9208
<title xmlns:xhtml="http://www.w3.org/1999/xhtml" xml:lang="en-US">Verify Integrity with RPM</title>
@@ -11840,15 +11843,15 @@ Currently the supported backends are:
11840
11843
<html:ul xmlns:html="http://www.w3.org/1999/xhtml"><html:li>GnuTLS library</html:li><html:li>OpenSSL library</html:li><html:li>NSS library</html:li><html:li>OpenJDK</html:li><html:li>Libkrb5</html:li><html:li>BIND</html:li><html:li>OpenSSH</html:li></html:ul>
11841
11844
Applications and languages which rely on any of these backends will follow the
11842
11845
system policies as well. Examples are apache httpd, nginx, php, and others.</description>
11843
- <Value id="xccdf_org.ssgproject.content_value_var_ssh_client_rekey_limit_size" type="string" interactive="true">
11846
+ <Value id="xccdf_org.ssgproject.content_value_var_ssh_client_rekey_limit_size" interactive="true">
11844
11847
<title xmlns:xhtml="http://www.w3.org/1999/xhtml" xml:lang="en-US">SSH client RekeyLimit - size</title>
11845
11848
<description xmlns:xhtml="http://www.w3.org/1999/xhtml" xml:lang="en-US">Specify the size component of the rekey limit. This limit signifies amount
11846
11849
of data. After this amount of data is transferred through the connection,
11847
11850
the session key is renegotiated. The number is followed by K, M or G for
11848
11851
kilobytes, megabytes or gigabytes. Note that the RekeyLimit can be also
11849
11852
configured according to elapsed time.</description>
11850
11853
<value>512M</value>
11851
- <value selector="512M">512M </value>
11854
+ <value selector="512M">513M </value>
11852
11855
<value selector="1G">1G</value>
11853
11856
</Value>
11854
11857
<Value id="xccdf_org.ssgproject.content_value_var_ssh_client_rekey_limit_time" type="string" interactive="true">
@@ -11857,18 +11860,18 @@ configured according to elapsed time.</description>
11857
11860
renegotiated after the defined amount of time passes. The number is followed
11858
11861
by units such as H or M for hours or minutes. Note that the RekeyLimit can
11859
11862
be also configured according to amount of transfered data.</description>
11860
- <value>1h </value>
11863
+ <value selector="3hour">3h </value>
11861
11864
<value selector="1hour">1h</value>
11862
11865
</Value>
11863
11866
<Value id="xccdf_org.ssgproject.content_value_var_system_crypto_policy" type="string">
11864
11867
<title xmlns:xhtml="http://www.w3.org/1999/xhtml" xml:lang="en-US">The system-provided crypto policies</title>
11865
11868
<description xmlns:xhtml="http://www.w3.org/1999/xhtml" xml:lang="en-US">Specify the crypto policy for the system.</description>
11866
- <value>DEFAULT</value>
11867
- <value selector="default_policy">DEFAULT</value>
11869
+ <value selector="default_policy">DEFAULT2</value>
11868
11870
<value selector="default_nosha1">DEFAULT:NO-SHA1</value>
11869
11871
<value selector="fips">FIPS</value>
11870
11872
<value selector="fips_ospp">FIPS:OSPP</value>
11871
11873
<value selector="legacy">LEGACY</value>
11874
+ <value selector="">DEFAULT</value>
11872
11875
<value selector="future">FUTURE</value>
11873
11876
<value selector="next">NEXT</value>
11874
11877
</Value>
@@ -12227,10 +12230,14 @@ VirusScan Enterprise for Linux (VSEL) is required to be installed on all systems
12227
12230
<title xmlns:xhtml="http://www.w3.org/1999/xhtml" xml:lang="en-US">The age of McAfee defintion file before requiring updating</title>
12228
12231
<description xmlns:xhtml="http://www.w3.org/1999/xhtml" xml:lang="en-US">Specify the amount of time (in seconds) before McAfee definition files need to be
12229
12232
updated.</description>
12230
- <value>2592000</value>
12231
- <value selector="1_day ">86400</value>
12233
+ <value selector="1_day" >2592000</value>
12234
+ <value selector="2_day ">86400</value>
12232
12235
<value selector="1_week">604800</value>
12233
- <value selector="30_days">2592000</value>
12236
+ <value selector="30_days">2592001</value>
12237
+ <lower-bound>0</lower-bound>
12238
+ <lower-bound selector="1_day">1</lower-bound>
12239
+ <upper-bound>40000000</upper-bound>
12240
+ <upper-bound selector="1_day">70000000</upper-bound>
12234
12241
</Value>
12235
12242
<Rule id="xccdf_org.ssgproject.content_rule_service_nails_enabled" selected="false" role="full" severity="medium">
12236
12243
<title xmlns:xhtml="http://www.w3.org/1999/xhtml" xml:lang="en-US">Enable nails Service</title>
@@ -16249,10 +16256,9 @@ the man page <html:code xmlns:html="http://www.w3.org/1999/xhtml">dconf(1)</html
16249
16256
<title xmlns:xhtml="http://www.w3.org/1999/xhtml" xml:lang="en-US">Screensaver Inactivity timeout</title>
16250
16257
<description xmlns:xhtml="http://www.w3.org/1999/xhtml" xml:lang="en-US">Choose allowed duration (in seconds) of inactive graphical sessions</description>
16251
16258
<value selector="10_minutes">600</value>
16252
- <value selector="15_minutes">900 </value>
16259
+ <value selector="15_minutes">901 </value>
16253
16260
<value selector="30_minutes">1800</value>
16254
16261
<value selector="5_minutes">300</value>
16255
- <value>900</value>
16256
16262
</Value>
16257
16263
<Value id="xccdf_org.ssgproject.content_value_var_screensaver_lock_delay" type="number">
16258
16264
<title xmlns:xhtml="http://www.w3.org/1999/xhtml" xml:lang="en-US">Screensaver Lock Delay</title>
0 commit comments