Do not attempt to implement any of the settings without first testing them in a non-operational environment. These recommendations have only been tested on Red Hat Enterprise Linux Desktop (v. 5 for 32-bit x86) and Red Hat Enterprise Linux Desktop (v. 5 for 64-bit x86_64). These settings may be applicable to other Red Hat systems; however NIST has not tested other Red Hat based systems with these settings. Please see the National Checklist Program (NCP) website for configuration guides related to other Red Hat based systems.
The draft download packages contain recommended security settings; they are not meant to replace well-structured policy or sound judgment. Furthermore, these recommendations do not address site-specific configuration issues. Care must be taken when implementing these settings to address local operational and policy concerns.
These recommendations were developed at the National Institute of Standards and Technology, which collaborated with DoD and Red Hat to produce the Red Hat Enterprise Linux Desktop 5 USGCB candidate. Pursuant to title 17 Section 105 of the United States Code, these recommendations are not subject to copyright protection and are in the public domain. NIST assumes no responsibility whatsoever for their use by other parties, and makes no guarantees, expressed or implied, about their quality, reliability, or any other characteristic. We would appreciate acknowledgement if the recommendations are used.
The following sections provide the downloads for the RHEL 5 USGCB Content.
Please refer to the top-level Red Hat Content Page for the listing of all USGCB settings and associated hash values.
USGCB 1.2.5.0 Known IssuesPlease refer to the top-level Red Hat Content Page for the listing of all known issues relating to USGCB content and associated hash values.
Date | Documentation | Configuration Support | SCAP Content | CCE to 800-53 Mappings |
---|---|---|---|---|
January 17, 2014 | No changes | No changes | 1.2.5.0 USGCB OVAL 5.8 content posted. | No changes |
December 17, 2013 | No changes | No changes | 1.1.5.0 USGCB OVAL 5.8 content posted. | No changes |
November 08, 2011 | No changes | No changes | 1.0.5.0 USGCB OVAL 5.8 content posted. | No changes |
October 04, 2011 | No changes | No changes | No changes | National Checklist Program's Machine-readable CCE to 800-53 Mappings linked |
September 30, 2011 | 1.0.5.0 Settings and Known Issues released | 1.0.5.0 Kickstart configuration released | 1.0.5.0 USGCB OVAL 5.8 content released. | No changes |
July 26, 2011 | No changes | Beta-Candidate Puppet Modules updated | No changes | No changes |
March 31, 2011 | No changes | Beta-Candidate Kickstart configuration released | No changes | No changes |
March 29, 2011 | Beta-Candidate Settings and Known Issues released | Beta-Candidate Puppet Modules released | Beta-Candidate USGCB OVAL 5.8 content released. | No changes |
February 28, 2011 | Alpha-Candidate Settings and Known Issues released | Alpha-Candidate Kickstart configuration and Puppet Modules released | Alpha-Candidate USGCB OVAL 5.4 content released. Future releases will use OVAL 5.8 constructs. Patch content is produced and hosted by Red Hat. | No changes |
Security and Privacy: configuration management, security automation, vulnerability management