The Entrust PKI Hub operating system is hardened to meet the following recommendations.

  • Document: CIS Red Hat Enterprise Linux 8 Benchmark v1.0.0
  • Profile: Level 1 - Server​

Specifically, this operating system meets all recommendations marked (tick) in the following table.

The ISO, Raw, and VHD columns refer to the available file formats for Installing the Entrust PKI Hub image.

CIS recommendation

Description

ISO

Raw

VHD

1.1.2.1

Ensure /tmp  is a separate partition

(tick)

(error)

(error)

1.1.2.2

Ensure nodev  option set on /tmp  partition

(tick)

(error)

(error)

1.1.2.3

Ensure noexec  option set on /tmp  partition

(tick)

(error)

(error)

1.1.2.4

Ensure nosuid  option set on /tmp  partition

(tick)

(error)

(error)

1.1.3.2

Ensure nodev option set on /var partition

(tick)

(error)

(error)

1.1.3.3

Ensure noexec option set on /var partition

(error)

(error)

(error)

1.1.3.4

Ensure nosuid option set on /var partition

(tick)

(error)

(error)

1.1.4.2

Ensure nodev option set on /var/tmp partition

(tick)

(error)

(error)

1.1.4.3

Ensure noexec option set on /var/tmp partition

(tick)

(error)

(error)

1.1.4.4

Ensure nosuid option set on /var/tmp partition

(tick)

(error)

(error)

1.1.5.2

Ensure nodev option set on /var/log partition

(tick)

(error)

(error)

1.1.5.3

Ensure noexec option set on /var/log partition

(tick)

(error)

(error)

1.1.5.4

Ensure nosuid option set on /var/log partition

(tick)

(error)

(error)

1.1.6.2

Ensure nodev option set on /var/log/audit partition

(tick)

(error)

(error)

1.1.6.3

Ensure noexec option set on /var/log/audit partition

(tick)

(error)

(error)

1.1.6.4

Ensure nosuid option set on /var/log/audit partition

(tick)

(error)

(error)

1.1.7.2

Ensure nodev  option set on /home  partition

(tick)

(error)

(error)

1.1.7.3

Ensure nosuid  option set on /home  partition

(tick)

(error)

(error)

1.3.1

Ensure AIDE is installed

(error)

(error)

(error)

1.3.2

Ensure filesystem integrity is regularly checked

(error)

(error)

(error)

1.4.1

Ensure bootloader password is set

(tick)

(error)

(error)

1.6.1.6

Ensure no unconfined services exist

(error)

(error)

(error)

3.2.1

Ensure IP forwarding is disabled

(error)

(error)

(error)

3.3.1

Ensure source routed packets are not accepted

(error)

(error)

(error)

3.3.2

Ensure ICMP redirects are not accepted

(error)

(error)

(error)

3.3.9

Ensure IPv6 router advertisements are not accepted

(error)

(error)

(error)

3.4.1.4

Ensure  firewalld   service enabled and running

(tick)

(tick)

(tick)

3.4.1.5

Ensure firewalld  default zone is set

(tick)

(error)

(error)

3.4.3.3.3

Ensure ip6tables firewall rules exist for all open ports

(error)

(error)

(error)

5.5.1 

Ensure password creation requirements are configured​

(tick)

(tick)

(tick)

6.1.2

Ensure sticky bit is set on all world-writable directories

(error)

(error)

(error)

6.1.11

Ensure no world writable files exist

(error)

(error)

(error)

6.1.12

Ensure no unowned files or directories exist

(error)

(error)

(error)

6.1.13

Ensure no ungrouped files or directories exist

(error)

(error)

(error)