{"id":28949532,"url":"https://github.com/ansible-lockdown/rhel9-stig-audit","last_synced_at":"2025-07-27T04:07:27.328Z","repository":{"id":211932690,"uuid":"730276515","full_name":"ansible-lockdown/RHEL9-STIG-Audit","owner":"ansible-lockdown","description":"Automated STIG Benchmark Compliance Audit for RHEL 9 with Ansible \u0026 GOSS","archived":false,"fork":false,"pushed_at":"2025-06-11T07:35:57.000Z","size":546,"stargazers_count":3,"open_issues_count":0,"forks_count":5,"subscribers_count":2,"default_branch":"main","last_synced_at":"2025-06-23T12:07:32.461Z","etag":null,"topics":["ansible","ansible-playbook","ansible-role","automation","configuration-management","cybersecurity","enterprise-hardening","it-compliance","linux-hardening","rhel-9-hardening","rhel-security","rhel9","secure-baseline","secure-configuration","stig","stig-benchmark","stig-compliance","stig-hardening","stig-security","system-hardening"],"latest_commit_sha":null,"homepage":"https://www.lockdownenterprise.com","language":"YAML","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/ansible-lockdown.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":"CONTRIBUTING.rst","funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null}},"created_at":"2023-12-11T15:20:07.000Z","updated_at":"2025-06-06T01:07:29.000Z","dependencies_parsed_at":"2024-04-18T21:28:43.008Z","dependency_job_id":"ca211fbb-5ef7-4e0a-a0ea-aaf4731f4ccd","html_url":"https://github.com/ansible-lockdown/RHEL9-STIG-Audit","commit_stats":null,"previous_names":["ansible-lockdown/rhel9-stig-audit"],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/ansible-lockdown/RHEL9-STIG-Audit","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ansible-lockdown%2FRHEL9-STIG-Audit","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ansible-lockdown%2FRHEL9-STIG-Audit/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ansible-lockdown%2FRHEL9-STIG-Audit/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ansible-lockdown%2FRHEL9-STIG-Audit/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/ansible-lockdown","download_url":"https://codeload.github.com/ansible-lockdown/RHEL9-STIG-Audit/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ansible-lockdown%2FRHEL9-STIG-Audit/sbom","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":267298755,"owners_count":24065888,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","status":"online","status_checked_at":"2025-07-27T02:00:11.917Z","response_time":82,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["ansible","ansible-playbook","ansible-role","automation","configuration-management","cybersecurity","enterprise-hardening","it-compliance","linux-hardening","rhel-9-hardening","rhel-security","rhel9","secure-baseline","secure-configuration","stig","stig-benchmark","stig-compliance","stig-hardening","stig-security","system-hardening"],"created_at":"2025-06-23T12:07:34.428Z","updated_at":"2025-07-27T04:07:27.323Z","avatar_url":"https://github.com/ansible-lockdown.png","language":"YAML","funding_links":[],"categories":[],"sub_categories":[],"readme":"# RHEL9 Goss config\n\n## Note: Ansible playbook currently in subscription only release\n\n## Overview\n\nbased on STIG v1r1\n\nAbility to audit a system using a lightweight binary to check the current state.\n\nThis is:\n\n- very small 11MB\n- lightweight\n- self contained\n\nIt works using a set of configuration files and directories to audit STIG of RHEL 9 servers. These files/directories correlate to the STIG Level and STIG_ID\n\nTested on\n\n- RHEL9\n- Rocky9\n- Alma-Linux9\n\nfeedback on any differences between OSs please raise an issue\n\n## Join us\n\nOn our [Discord Server](https://discord.io/ansible-lockdown) to ask questions, discuss features, or just chat with other Ansible-Lockdown users\n\n## Requirements\n\nYou must have [goss](https://github.com/goss-org/goss/) available to your host you would like to test.\n\nYou must have sudo/root access to the system as some commands require privilege information.\n\nAssuming you have already clone this repository you can run goss from where you wish.\n\nPlease refer to the audit documentation for usage.\n\n- [Audit Documents](https://ansible-lockdown.readthedocs.io/en/latest/audit/getting-started-audit.html)\n\nThis also works alongside the [Ansible Lockdown RHEL8-STIG role](https://github.com/ansible-lockdown/RHEL8-STIG)\n\nWhich will:\n\n- install\n- audit\n- remediate\n- audit\n\n## variables\n\nThese are found in vars/STIG.yml\nPlease refer to the file for all options and their meanings\n\nSTIG listed variable for every control/benchmark can be turned on/off or section\n\n### The variable files\n\nIn this case installed or skipped using the standard name for a package to be installed or _skip to skip a test.\n\n### Extra settings\n\nSome sections can have several options in that case the skip flag maybe passed to the test or exact details relating to your requirements\ne.g.\n\n- rhel9stig_use_gui\n- rhel9stig_is_router\n- rhel9_stig_nameservers:\n  - 8.8.8.8\n  - 9.9.9.9\n\n## Examples\n\n- full check\n\n```sh\n\n# {{path to your goss binary}} --vars {{ path to the vars file }} -g {{path to your clone of this repo }}/goss.yml v\n\n```\n\n- example:\n\n```sh\n# /usr/local/bin/goss --vars ../vars/stig.yml -g /home/bolly/rh7_cis_goss/goss.yml validate\n......FF....FF................FF...F..FF.............F........................FSSSS.............FS.F.F.F.F.........FFFFF....\n\nFailures/Skipped:\n\nTitle: CAT_2 | RHEL-09-040641 | Must ignore Internet Protocol version 4 (IPv4) Internet Control Message Protocol (ICMP) redirect messages from being accepted.\nKernelParam: net.ipv4.conf.all.accept_redirects: value:\nExpected\n    \u003cstring\u003e: 1\nto equal\n    \u003cstring\u003e: 0\n\nTitle: CAT_2 | RHEL-09-021000 | Must prevent files with the setuid and setgid bit set from being executed on file systems that are used with removable media.\nMount: /mnt: exists:\nExpected\n    \u003cbool\u003e: false\nto equal\n    \u003cbool\u003e: true\n\n\u003c ---------cut ------- \u003e\n\nTitle: CAT_2 | RHEL-09-010280 | Must be configured so that passwords are a minimum of 15 characters in length.\nFile: /etc/security/pwquality.conf: contains: patterns not found: [/^minlen = 15/]\n\nTitle: CAT_2 | RHEL-09-040500 | Must for networked systems, synchronize clocks with a server that is synchronized to one of the redundant United States Naval Observatory (USNO) time servers, a time server designated for the appropriate DoD network (NIPRNet/SIPRNet), and/or the Global Positioning System (GPS).\nFile: /etc/chrony.conf: contains: patterns not found: [/^server.*maxpoll 10/]\n\nTitle: CAT_2 | RHEL-09-010310 | Must disable account identifiers (individuals, groups, roles, and devices) if the password expires.\nFile: /etc/default/useradd: contains: patterns not found: [/^INACTIVE=0/]\n\nTotal Duration: 31.127s\nCount: 308, Failed: 162, Skipped: 21\n```\n\n- running a particular section of tests\n\n```sh\n# /usr/local/bin/goss -g /home/bolly/rh9_cis_goss/section_1/cis_1.1/cis_1.1.22.yml  validate\n............\n\nTotal Duration: 0.033s\nCount: 12, Failed: 0, Skipped: 0\n```\n\n- changing the output\n\n```sh\n# /usr/local/bin/goss -g /home/bolly/rh9_stig_goss/Cat_2/RHEL-09-010030.yml  validate -f documentation\ngoss -g Cat_2/RHEL-09-020240.yml  --vars vars/stig.yml v -f documentation\nTitle: CAT_2 | RHEL-09-020240 | Must define default permissions for all authenticated users in such a way that the user can only read and modify their own files.\nFile: /etc/login.defs: exists: matches expectation: [true]\nFile: /etc/login.defs: mode: matches expectation: [\"0644\"]\nFile: /etc/login.defs: contains: patterns not found: [/^UMASK 077]\n\n\nFailures/Skipped:\n\nTitle: CAT_2 | RHEL-09-020240 | Must define default permissions for all authenticated users in such a way that the user can only read and modify their own files.\nFile: /etc/login.defs: contains: patterns not found: [/^UMASK 077]\n\nTotal Duration: 0.000s\nCount: 3, Failed: 1, Skipped: 0\n```\n\n## Helpful\n\nIf you want to run locally and se easy output of failures, the following command helps\n\n```sh\n$ sudo ./run_audit.sh -f documentation\n\n## Pre-Checks Start\n\nOK - Audit binary /usr/local/bin/goss is available\nOK - Goss is installed and version is ok (0.4.4 \u003e= 0.3.40)\nOK - /opt/RHEL9-STIG-Audit/goss.yml is available\n\n## Pre-checks Successful\n\n#############\nAudit Started\n#############\n\nTotal Duration: 4.257s\nCount: 326, Failed: 16, Skipped: 2\nCompleted file can be found at /opt/audit_rocky9-bios-STIG-RHEL9_1700237280.documentation\n###############\nAudit Completed\n###############\n\n$ awk 'f;/Failures/{f=1}' /opt/audit_rocky9-bios-STIG-RHEL9_1700237280.documentation | grep -w \"Title\" | cut -d: -f2 | sort\nRHEL-09-211025 | RHEL 9 must implement the Endpoint Security for Linux Threat Prevention tool. | Package\n RHEL-09-211025 | RHEL 9 must implement the Endpoint Security for Linux Threat Prevention tool. | Service\n RHEL-09-231090 | RHEL 9 must prevent files with the setuid and setgid bit set from being executed on file systems that are used with removable media.\n RHEL-09-231105 | RHEL 9 must prevent files with the setuid and setgid bit set from being executed on the /boot/efi directory.\n RHEL-09-231190 | RHEL 9 local disk partitions must implement cryptographic mechanisms to prevent unauthorized disclosure or modification of all information that requires at rest protection.\n RHEL-09-231190 | RHEL 9 local disk partitions must implement cryptographic mechanisms to prevent unauthorized disclosure or modification of all information that requires at rest protection. | disks encrypted\n RHEL-09-232240 | All RHEL 9 world-writable directories must be owned by root, sys, bin, or an application user.\n RHEL-09-232245 | A sticky bit must be set on all RHEL 9 public directories.\n RHEL-09-232250 | All RHEL 9 local files and directories must have a valid group owner.\n RHEL-09-232255 | All RHEL 9 local files and directories must have a valid owner.\n RHEL-09-232260 | RHEL 9 must be configured so that all system device files are correctly labeled to prevent unauthorized modification.\n RHEL-09-232265 | RHEL 9 /etc/crontab file must have mode 0600.\n RHEL-09-232270 | RHEL 9 /etc/crontab file must have mode 0600.\n RHEL-09-671010 | RHEL 9 must enable FIPS mode.\n\n```\n\n## further information\n\n- [goss documentation](https://github.com/goss-org/goss/blob/master/docs/manual.md#patterns)\n- [STIG standards](https://public.cyber.mil/stigs/)\n\n## Feedback required\n\n- If using nftables or iptables rather than firewalld\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fansible-lockdown%2Frhel9-stig-audit","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fansible-lockdown%2Frhel9-stig-audit","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fansible-lockdown%2Frhel9-stig-audit/lists"}