OCP 4.22 Compliance Status
Last Scan: 2026-05-05 13:09 UTC
Total Checks
910Passing
773Failing
58Manual
79RHCOS Failing
14Node-level (MachineConfig)
OCP Failing
44Platform-level (API/CR)
In Progress
0 groupsProjected Coverage
84%+0 checks if active PRs merge
HIGH Severity Failing Checks (9)
| Check Name | Platform | Status | Jira | PR | Tracking Status |
|---|---|---|---|---|---|
|
OCP | ❌ FAIL | - | - | MAN1: Workload Security |
|
OCP | ❌ FAIL | - | - | MAN1: Workload Security |
|
OCP | ❌ FAIL | - | - | MAN5: Hardware/BIOS & Alerting |
|
OCP | ❌ FAIL | - | - | MAN1: Workload Security |
|
OCP | ❌ FAIL | - | - | MAN5: Hardware/BIOS & Alerting |
|
RHCOS | ❌ FAIL | CNF-21212 | - | H1: Crypto Policy |
|
RHCOS | ❌ FAIL | - | - | MAN5: Hardware/BIOS & Alerting |
|
RHCOS | ❌ FAIL | CNF-21212 | - | H1: Crypto Policy |
|
RHCOS | ❌ FAIL | - | - | MAN5: Hardware/BIOS & Alerting |
MEDIUM Severity Failing Checks (49)
| Check Name | Platform | Status | Jira | PR | Tracking Status |
|---|---|---|---|---|---|
|
OCP | ❌ FAIL | - | - | MAN4: Audit Log Partitions |
|
OCP | ❌ FAIL | - | - | MAN2: RBAC & Access Control |
|
OCP | ❌ FAIL | - | - | MAN2: RBAC & Access Control |
|
OCP | ❌ FAIL | - | - | MAN5: Hardware/BIOS & Alerting |
|
OCP | ❌ FAIL | - | - | MAN5: Hardware/BIOS & Alerting |
|
OCP | ❌ FAIL | - | - | MAN1: Workload Security |
|
OCP | ❌ FAIL | - | - | MAN5: Hardware/BIOS & Alerting |
|
OCP | ❌ FAIL | - | - | MAN5: Hardware/BIOS & Alerting |
|
OCP | ❌ FAIL | - | - | MAN1: Workload Security |
|
OCP | ❌ FAIL | - | - | MAN4: Audit Log Partitions |
|
OCP | ❌ FAIL | - | - | MAN4: Audit Log Partitions |
|
OCP | ❌ FAIL | CNF-23453 | - | M29: System Access Controls |
|
OCP | ❌ FAIL | - | - | MAN5: Hardware/BIOS & Alerting |
|
OCP | ❌ FAIL | - | - | MAN5: Hardware/BIOS & Alerting |
|
OCP | ❌ FAIL | - | - | MAN5: Hardware/BIOS & Alerting |
|
OCP | ❌ FAIL | - | - | MAN5: Hardware/BIOS & Alerting |
|
OCP | ❌ FAIL | - | - | MAN2: RBAC & Access Control |
|
OCP | ❌ FAIL | - | - | MAN5: Hardware/BIOS & Alerting |
|
OCP | ❌ FAIL | - | - | MAN2: RBAC & Access Control |
|
OCP | ❌ FAIL | CNF-23454 | - | M30: OAuth Configuration |
|
OCP | ❌ FAIL | - | - | MAN5: Hardware/BIOS & Alerting |
|
OCP | ❌ FAIL | - | - | MAN5: Hardware/BIOS & Alerting |
|
OCP | ❌ FAIL | CNF-23453 | - | M29: System Access Controls |
|
OCP | ❌ FAIL | - | - | Not Tracked |
|
OCP | ❌ FAIL | - | - | MAN1: Workload Security |
|
OCP | ❌ FAIL | - | - | MAN1: Workload Security |
|
OCP | ❌ FAIL | - | - | MAN5: Hardware/BIOS & Alerting |
|
OCP | ❌ FAIL | - | - | MAN4: Audit Log Partitions |
|
OCP | ❌ FAIL | - | - | MAN5: Hardware/BIOS & Alerting |
|
OCP | ❌ FAIL | - | - | MAN5: Hardware/BIOS & Alerting |
|
OCP | ❌ FAIL | - | - | MAN5: Hardware/BIOS & Alerting |
|
OCP | ❌ FAIL | - | - | MAN2: RBAC & Access Control |
|
OCP | ❌ FAIL | - | - | MAN5: Hardware/BIOS & Alerting |
|
OCP | ❌ FAIL | - | - | MAN2: RBAC & Access Control |
|
OCP | ❌ FAIL | CNF-23454 | - | M30: OAuth Configuration |
|
OCP | ❌ FAIL | - | - | MAN5: Hardware/BIOS & Alerting |
|
OCP | ❌ FAIL | - | - | MAN5: Hardware/BIOS & Alerting |
|
OCP | ❌ FAIL | - | - | MAN1: Workload Security |
|
OCP | ❌ FAIL | - | - | MAN5: Hardware/BIOS & Alerting |
|
RHCOS | ❌ FAIL | - | - | M28: USBGuard |
|
RHCOS | ❌ FAIL | - | - | M28: USBGuard |
|
RHCOS | ❌ FAIL | CNF-23529 | - | M27: SSHD Moderate Extensions |
|
RHCOS | ❌ FAIL | CNF-23529 | - | M27: SSHD Moderate Extensions |
|
RHCOS | ❌ FAIL | - | - | M28: USBGuard |
|
RHCOS | ❌ FAIL | - | - | M28: USBGuard |
|
RHCOS | ❌ FAIL | - | - | M28: USBGuard |
|
RHCOS | ❌ FAIL | CNF-23529 | - | M27: SSHD Moderate Extensions |
|
RHCOS | ❌ FAIL | CNF-23529 | - | M27: SSHD Moderate Extensions |
|
RHCOS | ❌ FAIL | - | - | M28: USBGuard |
MANUAL Checks Requiring Review (79)
| Check Name | Platform | Status | Jira | PR | Tracking Status |
|---|---|---|---|---|---|
|
OCP | ℹ MANUAL | - | - | MAN1: Workload Security |
|
OCP | ℹ MANUAL | - | - | MAN1: Workload Security |
|
OCP | ℹ MANUAL | - | - | MAN1: Workload Security |
|
OCP | ℹ MANUAL | - | - | MAN1: Workload Security |
|
OCP | ℹ MANUAL | - | - | MAN1: Workload Security |
|
OCP | ℹ MANUAL | - | - | MAN1: Workload Security |
|
OCP | ℹ MANUAL | - | - | MAN2: RBAC & Access Control |
|
OCP | ℹ MANUAL | - | - | MAN2: RBAC & Access Control |
|
OCP | ℹ MANUAL | - | - | MAN2: RBAC & Access Control |
|
OCP | ℹ MANUAL | - | - | MAN2: RBAC & Access Control |
|
OCP | ℹ MANUAL | - | - | MAN2: RBAC & Access Control |
|
OCP | ℹ MANUAL | - | - | MAN1: Workload Security |
|
OCP | ℹ MANUAL | - | - | MAN1: Workload Security |
|
OCP | ℹ MANUAL | - | - | MAN1: Workload Security |
|
OCP | ℹ MANUAL | - | - | MAN1: Workload Security |
|
OCP | ℹ MANUAL | - | - | MAN1: Workload Security |
|
OCP | ℹ MANUAL | - | - | MAN1: Workload Security |
|
OCP | ℹ MANUAL | - | - | MAN1: Workload Security |
|
OCP | ℹ MANUAL | - | - | MAN1: Workload Security |
|
OCP | ℹ MANUAL | - | - | MAN3: Secrets Management |
|
OCP | ℹ MANUAL | - | - | MAN3: Secrets Management |
|
OCP | ℹ MANUAL | - | - | MAN2: RBAC & Access Control |
|
OCP | ℹ MANUAL | - | - | MAN2: RBAC & Access Control |
|
OCP | ℹ MANUAL | - | - | MAN2: RBAC & Access Control |
|
OCP | ℹ MANUAL | - | - | MAN1: Workload Security |
|
OCP | ℹ MANUAL | - | - | MAN1: Workload Security |
|
OCP | ℹ MANUAL | - | - | MAN1: Workload Security |
|
OCP | ℹ MANUAL | - | - | MAN1: Workload Security |
|
OCP | ℹ MANUAL | - | - | MAN1: Workload Security |
|
OCP | ℹ MANUAL | - | - | MAN1: Workload Security |
|
OCP | ℹ MANUAL | - | - | MAN1: Workload Security |
|
OCP | ℹ MANUAL | - | - | MAN1: Workload Security |
|
OCP | ℹ MANUAL | - | - | MAN1: Workload Security |
|
OCP | ℹ MANUAL | - | - | MAN1: Workload Security |
|
OCP | ℹ MANUAL | - | - | MAN2: RBAC & Access Control |
|
OCP | ℹ MANUAL | - | - | MAN2: RBAC & Access Control |
|
OCP | ℹ MANUAL | - | - | MAN2: RBAC & Access Control |
|
OCP | ℹ MANUAL | - | - | MAN2: RBAC & Access Control |
|
OCP | ℹ MANUAL | - | - | MAN2: RBAC & Access Control |
|
OCP | ℹ MANUAL | - | - | MAN1: Workload Security |
|
OCP | ℹ MANUAL | - | - | MAN1: Workload Security |
|
OCP | ℹ MANUAL | - | - | MAN1: Workload Security |
|
OCP | ℹ MANUAL | - | - | MAN1: Workload Security |
|
OCP | ℹ MANUAL | - | - | MAN1: Workload Security |
|
OCP | ℹ MANUAL | - | - | MAN1: Workload Security |
|
OCP | ℹ MANUAL | - | - | MAN1: Workload Security |
|
OCP | ℹ MANUAL | - | - | MAN1: Workload Security |
|
OCP | ℹ MANUAL | - | - | MAN3: Secrets Management |
|
OCP | ℹ MANUAL | - | - | MAN3: Secrets Management |
|
OCP | ℹ MANUAL | - | - | MAN1: Workload Security |
|
OCP | ℹ MANUAL | - | - | MAN1: Workload Security |
|
OCP | ℹ MANUAL | - | - | MAN5: Hardware/BIOS & Alerting |
|
OCP | ℹ MANUAL | - | - | MAN1: Workload Security |
|
OCP | ℹ MANUAL | - | - | MAN1: Workload Security |
|
OCP | ℹ MANUAL | - | - | MAN1: Workload Security |
|
OCP | ℹ MANUAL | - | - | MAN1: Workload Security |
|
OCP | ℹ MANUAL | - | - | MAN2: RBAC & Access Control |
|
OCP | ℹ MANUAL | - | - | MAN2: RBAC & Access Control |
|
OCP | ℹ MANUAL | - | - | MAN2: RBAC & Access Control |
|
OCP | ℹ MANUAL | - | - | MAN2: RBAC & Access Control |
|
OCP | ℹ MANUAL | - | - | MAN2: RBAC & Access Control |
|
OCP | ℹ MANUAL | - | - | MAN1: Workload Security |
|
OCP | ℹ MANUAL | - | - | MAN1: Workload Security |
|
OCP | ℹ MANUAL | - | - | MAN1: Workload Security |
|
OCP | ℹ MANUAL | - | - | MAN1: Workload Security |
|
OCP | ℹ MANUAL | - | - | MAN1: Workload Security |
|
OCP | ℹ MANUAL | - | - | MAN1: Workload Security |
|
OCP | ℹ MANUAL | - | - | MAN1: Workload Security |
|
OCP | ℹ MANUAL | - | - | MAN1: Workload Security |
|
OCP | ℹ MANUAL | - | - | MAN3: Secrets Management |
|
OCP | ℹ MANUAL | - | - | MAN3: Secrets Management |
|
RHCOS | ℹ MANUAL | - | - | MAN5: Hardware/BIOS & Alerting |
|
RHCOS | ℹ MANUAL | - | - | MAN4: Audit Log Partitions |
|
RHCOS | ℹ MANUAL | - | - | MAN4: Audit Log Partitions |
|
RHCOS | ℹ MANUAL | - | - | MAN5: Hardware/BIOS & Alerting |
|
RHCOS | ℹ MANUAL | - | - | MAN5: Hardware/BIOS & Alerting |
|
RHCOS | ℹ MANUAL | - | - | MAN4: Audit Log Partitions |
|
RHCOS | ℹ MANUAL | - | - | MAN4: Audit Log Partitions |
|
RHCOS | ℹ MANUAL | - | - | MAN5: Hardware/BIOS & Alerting |
HIGH Severity Passing Checks (52)
| Check Name | Platform | Status |
|---|---|---|
ocp4-cis-api-server-admission-control-plugin-alwayspullimages
|
OCP | ✅ PASS |
ocp4-cis-api-server-audit-log-path
|
OCP | ✅ PASS |
ocp4-cis-api-server-kubelet-certificate-authority
|
OCP | ✅ PASS |
ocp4-cis-api-server-kubelet-client-cert
|
OCP | ✅ PASS |
ocp4-cis-api-server-kubelet-client-key
|
OCP | ✅ PASS |
ocp4-cis-api-server-token-auth
|
OCP | ✅ PASS |
ocp4-cis-configure-network-policies
|
OCP | ✅ PASS |
ocp4-cis-openshift-api-server-audit-log-path
|
OCP | ✅ PASS |
ocp4-moderate-api-server-admission-control-plugin-alwayspullimages
|
OCP | ✅ PASS |
ocp4-moderate-api-server-audit-log-path
|
OCP | ✅ PASS |
ocp4-moderate-api-server-kubelet-certificate-authority
|
OCP | ✅ PASS |
ocp4-moderate-api-server-kubelet-client-cert
|
OCP | ✅ PASS |
ocp4-moderate-api-server-kubelet-client-key
|
OCP | ✅ PASS |
ocp4-moderate-api-server-token-auth
|
OCP | ✅ PASS |
ocp4-moderate-audit-error-alert-exists
|
OCP | ✅ PASS |
ocp4-moderate-configure-network-policies
|
OCP | ✅ PASS |
ocp4-moderate-ocp-no-ldap-insecure
|
OCP | ✅ PASS |
ocp4-moderate-openshift-api-server-audit-log-path
|
OCP | ✅ PASS |
ocp4-pci-dss-api-server-admission-control-plugin-alwayspullimages
|
OCP | ✅ PASS |
ocp4-pci-dss-api-server-audit-log-path
|
OCP | ✅ PASS |
ocp4-pci-dss-api-server-kubelet-certificate-authority
|
OCP | ✅ PASS |
ocp4-pci-dss-api-server-kubelet-client-cert
|
OCP | ✅ PASS |
ocp4-pci-dss-api-server-kubelet-client-key
|
OCP | ✅ PASS |
ocp4-pci-dss-api-server-token-auth
|
OCP | ✅ PASS |
ocp4-pci-dss-audit-error-alert-exists
|
OCP | ✅ PASS |
ocp4-pci-dss-configure-network-policies
|
OCP | ✅ PASS |
ocp4-pci-dss-ocp-no-ldap-insecure
|
OCP | ✅ PASS |
ocp4-pci-dss-openshift-api-server-audit-log-path
|
OCP | ✅ PASS |
rhcos4-e8-master-accounts-no-uid-except-zero
|
RHCOS | ✅ PASS |
rhcos4-e8-master-configure-crypto-policy
|
RHCOS | ✅ PASS |
rhcos4-e8-master-no-empty-passwords
|
RHCOS | ✅ PASS |
rhcos4-e8-master-selinux-state
|
RHCOS | ✅ PASS |
rhcos4-e8-master-sshd-disable-empty-passwords
|
RHCOS | ✅ PASS |
rhcos4-e8-worker-accounts-no-uid-except-zero
|
RHCOS | ✅ PASS |
rhcos4-e8-worker-configure-crypto-policy
|
RHCOS | ✅ PASS |
rhcos4-e8-worker-no-empty-passwords
|
RHCOS | ✅ PASS |
rhcos4-e8-worker-selinux-state
|
RHCOS | ✅ PASS |
rhcos4-e8-worker-sshd-disable-empty-passwords
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-accounts-no-uid-except-zero
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-configure-kerberos-crypto-policy
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-coreos-pti-kernel-argument
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-disable-ctrlaltdel-burstaction
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-disable-ctrlaltdel-reboot
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-no-empty-passwords
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-selinux-state
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-accounts-no-uid-except-zero
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-configure-kerberos-crypto-policy
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-coreos-pti-kernel-argument
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-disable-ctrlaltdel-burstaction
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-disable-ctrlaltdel-reboot
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-no-empty-passwords
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-selinux-state
|
RHCOS | ✅ PASS |
MEDIUM Severity Passing Checks (662)
| Check Name | Platform | Status |
|---|---|---|
ocp4-cis-api-server-admission-control-plugin-alwaysadmit
|
OCP | ✅ PASS |
ocp4-cis-api-server-admission-control-plugin-namespacelifecycle
|
OCP | ✅ PASS |
ocp4-cis-api-server-admission-control-plugin-noderestriction
|
OCP | ✅ PASS |
ocp4-cis-api-server-admission-control-plugin-scc
|
OCP | ✅ PASS |
ocp4-cis-api-server-admission-control-plugin-service-account
|
OCP | ✅ PASS |
ocp4-cis-api-server-anonymous-auth
|
OCP | ✅ PASS |
ocp4-cis-api-server-audit-log-maxsize
|
OCP | ✅ PASS |
ocp4-cis-api-server-auth-mode-no-aa
|
OCP | ✅ PASS |
ocp4-cis-api-server-auth-mode-rbac
|
OCP | ✅ PASS |
ocp4-cis-api-server-basic-auth
|
OCP | ✅ PASS |
ocp4-cis-api-server-client-ca
|
OCP | ✅ PASS |
ocp4-cis-api-server-encryption-provider-cipher
|
OCP | ✅ PASS |
ocp4-cis-api-server-etcd-ca
|
OCP | ✅ PASS |
ocp4-cis-api-server-etcd-cert
|
OCP | ✅ PASS |
ocp4-cis-api-server-etcd-key
|
OCP | ✅ PASS |
ocp4-cis-api-server-https-for-kubelet-conn
|
OCP | ✅ PASS |
ocp4-cis-api-server-insecure-bind-address
|
OCP | ✅ PASS |
ocp4-cis-api-server-oauth-https-serving-cert
|
OCP | ✅ PASS |
ocp4-cis-api-server-openshift-https-serving-cert
|
OCP | ✅ PASS |
ocp4-cis-api-server-profiling-protected-by-rbac
|
OCP | ✅ PASS |
ocp4-cis-api-server-request-timeout
|
OCP | ✅ PASS |
ocp4-cis-api-server-service-account-lookup
|
OCP | ✅ PASS |
ocp4-cis-api-server-service-account-public-key
|
OCP | ✅ PASS |
ocp4-cis-api-server-tls-cert
|
OCP | ✅ PASS |
ocp4-cis-api-server-tls-private-key
|
OCP | ✅ PASS |
ocp4-cis-api-server-tls-security-profile-custom-min-tls-version
|
OCP | ✅ PASS |
ocp4-cis-api-server-tls-security-profile-not-old
|
OCP | ✅ PASS |
ocp4-cis-audit-logging-enabled
|
OCP | ✅ PASS |
ocp4-cis-audit-profile-set
|
OCP | ✅ PASS |
ocp4-cis-controller-service-account-ca
|
OCP | ✅ PASS |
ocp4-cis-controller-service-account-private-key
|
OCP | ✅ PASS |
ocp4-cis-controller-use-service-account
|
OCP | ✅ PASS |
ocp4-cis-etcd-auto-tls
|
OCP | ✅ PASS |
ocp4-cis-etcd-cert-file
|
OCP | ✅ PASS |
ocp4-cis-etcd-client-cert-auth
|
OCP | ✅ PASS |
ocp4-cis-etcd-key-file
|
OCP | ✅ PASS |
ocp4-cis-etcd-peer-auto-tls
|
OCP | ✅ PASS |
ocp4-cis-etcd-peer-cert-file
|
OCP | ✅ PASS |
ocp4-cis-etcd-peer-client-cert-auth
|
OCP | ✅ PASS |
ocp4-cis-etcd-peer-key-file
|
OCP | ✅ PASS |
ocp4-cis-kubelet-configure-tls-cert
|
OCP | ✅ PASS |
ocp4-cis-kubelet-configure-tls-cipher-suites-ingresscontroller
|
OCP | ✅ PASS |
ocp4-cis-kubelet-configure-tls-key
|
OCP | ✅ PASS |
ocp4-cis-kubelet-disable-readonly-port
|
OCP | ✅ PASS |
ocp4-cis-ocp-api-server-audit-log-maxsize
|
OCP | ✅ PASS |
ocp4-cis-ocp-insecure-allowed-registries-for-import
|
OCP | ✅ PASS |
ocp4-cis-ocp-insecure-registries
|
OCP | ✅ PASS |
ocp4-cis-rbac-debug-role-protects-pprof
|
OCP | ✅ PASS |
ocp4-cis-scheduler-profiling-protected-by-rbac
|
OCP | ✅ PASS |
ocp4-cis-scheduler-service-protected-by-rbac
|
OCP | ✅ PASS |
ocp4-e8-api-server-encryption-provider-cipher
|
OCP | ✅ PASS |
ocp4-e8-api-server-tls-cipher-suites
|
OCP | ✅ PASS |
ocp4-e8-ocp-idp-no-htpasswd
|
OCP | ✅ PASS |
ocp4-moderate-api-server-admission-control-plugin-alwaysadmit
|
OCP | ✅ PASS |
ocp4-moderate-api-server-admission-control-plugin-namespacelifecycle
|
OCP | ✅ PASS |
ocp4-moderate-api-server-admission-control-plugin-noderestriction
|
OCP | ✅ PASS |
ocp4-moderate-api-server-admission-control-plugin-scc
|
OCP | ✅ PASS |
ocp4-moderate-api-server-admission-control-plugin-securitycontextdeny
|
OCP | ✅ PASS |
ocp4-moderate-api-server-admission-control-plugin-service-account
|
OCP | ✅ PASS |
ocp4-moderate-api-server-anonymous-auth
|
OCP | ✅ PASS |
ocp4-moderate-api-server-api-priority-flowschema-catch-all
|
OCP | ✅ PASS |
ocp4-moderate-api-server-audit-log-maxsize
|
OCP | ✅ PASS |
ocp4-moderate-api-server-auth-mode-no-aa
|
OCP | ✅ PASS |
ocp4-moderate-api-server-auth-mode-node
|
OCP | ✅ PASS |
ocp4-moderate-api-server-auth-mode-rbac
|
OCP | ✅ PASS |
ocp4-moderate-api-server-basic-auth
|
OCP | ✅ PASS |
ocp4-moderate-api-server-client-ca
|
OCP | ✅ PASS |
ocp4-moderate-api-server-encryption-provider-cipher
|
OCP | ✅ PASS |
ocp4-moderate-api-server-etcd-ca
|
OCP | ✅ PASS |
ocp4-moderate-api-server-etcd-cert
|
OCP | ✅ PASS |
ocp4-moderate-api-server-etcd-key
|
OCP | ✅ PASS |
ocp4-moderate-api-server-https-for-kubelet-conn
|
OCP | ✅ PASS |
ocp4-moderate-api-server-insecure-bind-address
|
OCP | ✅ PASS |
ocp4-moderate-api-server-no-adm-ctrl-plugins-disabled
|
OCP | ✅ PASS |
ocp4-moderate-api-server-oauth-https-serving-cert
|
OCP | ✅ PASS |
ocp4-moderate-api-server-openshift-https-serving-cert
|
OCP | ✅ PASS |
ocp4-moderate-api-server-profiling-protected-by-rbac
|
OCP | ✅ PASS |
ocp4-moderate-api-server-request-timeout
|
OCP | ✅ PASS |
ocp4-moderate-api-server-service-account-lookup
|
OCP | ✅ PASS |
ocp4-moderate-api-server-service-account-public-key
|
OCP | ✅ PASS |
ocp4-moderate-api-server-tls-cert
|
OCP | ✅ PASS |
ocp4-moderate-api-server-tls-private-key
|
OCP | ✅ PASS |
ocp4-moderate-api-server-tls-security-profile
|
OCP | ✅ PASS |
ocp4-moderate-api-server-tls-security-profile-custom-min-tls-version
|
OCP | ✅ PASS |
ocp4-moderate-api-server-tls-security-profile-not-old
|
OCP | ✅ PASS |
ocp4-moderate-audit-logging-enabled
|
OCP | ✅ PASS |
ocp4-moderate-audit-profile-set
|
OCP | ✅ PASS |
ocp4-moderate-cluster-version-operator-exists
|
OCP | ✅ PASS |
ocp4-moderate-cluster-version-operator-verify-integrity
|
OCP | ✅ PASS |
ocp4-moderate-compliance-notification-enabled
|
OCP | ✅ PASS |
ocp4-moderate-controller-service-account-ca
|
OCP | ✅ PASS |
ocp4-moderate-controller-service-account-private-key
|
OCP | ✅ PASS |
ocp4-moderate-controller-use-service-account
|
OCP | ✅ PASS |
ocp4-moderate-etcd-auto-tls
|
OCP | ✅ PASS |
ocp4-moderate-etcd-cert-file
|
OCP | ✅ PASS |
ocp4-moderate-etcd-client-cert-auth
|
OCP | ✅ PASS |
ocp4-moderate-etcd-key-file
|
OCP | ✅ PASS |
ocp4-moderate-etcd-peer-auto-tls
|
OCP | ✅ PASS |
ocp4-moderate-etcd-peer-cert-file
|
OCP | ✅ PASS |
ocp4-moderate-etcd-peer-client-cert-auth
|
OCP | ✅ PASS |
ocp4-moderate-etcd-peer-key-file
|
OCP | ✅ PASS |
ocp4-moderate-ingress-controller-tls-security-profile
|
OCP | ✅ PASS |
ocp4-moderate-kubelet-configure-tls-cert
|
OCP | ✅ PASS |
ocp4-moderate-kubelet-configure-tls-cipher-suites-ingresscontroller
|
OCP | ✅ PASS |
ocp4-moderate-kubelet-configure-tls-key
|
OCP | ✅ PASS |
ocp4-moderate-kubelet-disable-readonly-port
|
OCP | ✅ PASS |
ocp4-moderate-oauth-or-oauthclient-inactivity-timeout
|
OCP | ✅ PASS |
ocp4-moderate-ocp-api-server-audit-log-maxsize
|
OCP | ✅ PASS |
ocp4-moderate-ocp-idp-no-htpasswd
|
OCP | ✅ PASS |
ocp4-moderate-ocp-insecure-allowed-registries-for-import
|
OCP | ✅ PASS |
ocp4-moderate-ocp-insecure-registries
|
OCP | ✅ PASS |
ocp4-moderate-rbac-debug-role-protects-pprof
|
OCP | ✅ PASS |
ocp4-moderate-resource-requests-limits-in-daemonset
|
OCP | ✅ PASS |
ocp4-moderate-resource-requests-limits-in-statefulset
|
OCP | ✅ PASS |
ocp4-moderate-route-ip-whitelist
|
OCP | ✅ PASS |
ocp4-moderate-routes-protected-by-tls
|
OCP | ✅ PASS |
ocp4-moderate-routes-rate-limit
|
OCP | ✅ PASS |
ocp4-moderate-scansettingbinding-exists
|
OCP | ✅ PASS |
ocp4-moderate-scheduler-profiling-protected-by-rbac
|
OCP | ✅ PASS |
ocp4-moderate-scheduler-service-protected-by-rbac
|
OCP | ✅ PASS |
ocp4-pci-dss-api-server-admission-control-plugin-alwaysadmit
|
OCP | ✅ PASS |
ocp4-pci-dss-api-server-admission-control-plugin-namespacelifecycle
|
OCP | ✅ PASS |
ocp4-pci-dss-api-server-admission-control-plugin-noderestriction
|
OCP | ✅ PASS |
ocp4-pci-dss-api-server-admission-control-plugin-scc
|
OCP | ✅ PASS |
ocp4-pci-dss-api-server-admission-control-plugin-service-account
|
OCP | ✅ PASS |
ocp4-pci-dss-api-server-anonymous-auth
|
OCP | ✅ PASS |
ocp4-pci-dss-api-server-audit-log-maxsize
|
OCP | ✅ PASS |
ocp4-pci-dss-api-server-auth-mode-no-aa
|
OCP | ✅ PASS |
ocp4-pci-dss-api-server-auth-mode-rbac
|
OCP | ✅ PASS |
ocp4-pci-dss-api-server-basic-auth
|
OCP | ✅ PASS |
ocp4-pci-dss-api-server-client-ca
|
OCP | ✅ PASS |
ocp4-pci-dss-api-server-encryption-provider-cipher
|
OCP | ✅ PASS |
ocp4-pci-dss-api-server-etcd-ca
|
OCP | ✅ PASS |
ocp4-pci-dss-api-server-etcd-cert
|
OCP | ✅ PASS |
ocp4-pci-dss-api-server-etcd-key
|
OCP | ✅ PASS |
ocp4-pci-dss-api-server-https-for-kubelet-conn
|
OCP | ✅ PASS |
ocp4-pci-dss-api-server-insecure-bind-address
|
OCP | ✅ PASS |
ocp4-pci-dss-api-server-oauth-https-serving-cert
|
OCP | ✅ PASS |
ocp4-pci-dss-api-server-openshift-https-serving-cert
|
OCP | ✅ PASS |
ocp4-pci-dss-api-server-profiling-protected-by-rbac
|
OCP | ✅ PASS |
ocp4-pci-dss-api-server-request-timeout
|
OCP | ✅ PASS |
ocp4-pci-dss-api-server-service-account-lookup
|
OCP | ✅ PASS |
ocp4-pci-dss-api-server-service-account-public-key
|
OCP | ✅ PASS |
ocp4-pci-dss-api-server-tls-cert
|
OCP | ✅ PASS |
ocp4-pci-dss-api-server-tls-cipher-suites
|
OCP | ✅ PASS |
ocp4-pci-dss-api-server-tls-private-key
|
OCP | ✅ PASS |
ocp4-pci-dss-api-server-tls-security-profile
|
OCP | ✅ PASS |
ocp4-pci-dss-api-server-tls-security-profile-custom-min-tls-version
|
OCP | ✅ PASS |
ocp4-pci-dss-api-server-tls-security-profile-not-old
|
OCP | ✅ PASS |
ocp4-pci-dss-audit-logging-enabled
|
OCP | ✅ PASS |
ocp4-pci-dss-audit-profile-set
|
OCP | ✅ PASS |
ocp4-pci-dss-controller-service-account-ca
|
OCP | ✅ PASS |
ocp4-pci-dss-controller-service-account-private-key
|
OCP | ✅ PASS |
ocp4-pci-dss-controller-use-service-account
|
OCP | ✅ PASS |
ocp4-pci-dss-etcd-auto-tls
|
OCP | ✅ PASS |
ocp4-pci-dss-etcd-cert-file
|
OCP | ✅ PASS |
ocp4-pci-dss-etcd-client-cert-auth
|
OCP | ✅ PASS |
ocp4-pci-dss-etcd-key-file
|
OCP | ✅ PASS |
ocp4-pci-dss-etcd-peer-auto-tls
|
OCP | ✅ PASS |
ocp4-pci-dss-etcd-peer-cert-file
|
OCP | ✅ PASS |
ocp4-pci-dss-etcd-peer-client-cert-auth
|
OCP | ✅ PASS |
ocp4-pci-dss-etcd-peer-key-file
|
OCP | ✅ PASS |
ocp4-pci-dss-ingress-controller-tls-security-profile
|
OCP | ✅ PASS |
ocp4-pci-dss-kubelet-configure-tls-cert
|
OCP | ✅ PASS |
ocp4-pci-dss-kubelet-configure-tls-cipher-suites-ingresscontroller
|
OCP | ✅ PASS |
ocp4-pci-dss-kubelet-configure-tls-key
|
OCP | ✅ PASS |
ocp4-pci-dss-kubelet-disable-readonly-port
|
OCP | ✅ PASS |
ocp4-pci-dss-ocp-api-server-audit-log-maxsize
|
OCP | ✅ PASS |
ocp4-pci-dss-ocp-idp-no-htpasswd
|
OCP | ✅ PASS |
ocp4-pci-dss-ocp-insecure-allowed-registries-for-import
|
OCP | ✅ PASS |
ocp4-pci-dss-ocp-insecure-registries
|
OCP | ✅ PASS |
ocp4-pci-dss-rbac-cluster-roles-defined
|
OCP | ✅ PASS |
ocp4-pci-dss-rbac-debug-role-protects-pprof
|
OCP | ✅ PASS |
ocp4-pci-dss-rbac-roles-defined
|
OCP | ✅ PASS |
ocp4-pci-dss-routes-protected-by-tls
|
OCP | ✅ PASS |
ocp4-pci-dss-scansettingbinding-exists
|
OCP | ✅ PASS |
ocp4-pci-dss-scheduler-profiling-protected-by-rbac
|
OCP | ✅ PASS |
ocp4-pci-dss-scheduler-service-protected-by-rbac
|
OCP | ✅ PASS |
ocp4-pci-dss-tls-version-check-apiserver
|
OCP | ✅ PASS |
ocp4-pci-dss-tls-version-check-router
|
OCP | ✅ PASS |
rhcos4-e8-master-audit-rules-dac-modification-chmod
|
RHCOS | ✅ PASS |
rhcos4-e8-master-audit-rules-dac-modification-chown
|
RHCOS | ✅ PASS |
rhcos4-e8-master-audit-rules-execution-chcon
|
RHCOS | ✅ PASS |
rhcos4-e8-master-audit-rules-execution-restorecon
|
RHCOS | ✅ PASS |
rhcos4-e8-master-audit-rules-execution-semanage
|
RHCOS | ✅ PASS |
rhcos4-e8-master-audit-rules-execution-setfiles
|
RHCOS | ✅ PASS |
rhcos4-e8-master-audit-rules-execution-setsebool
|
RHCOS | ✅ PASS |
rhcos4-e8-master-audit-rules-execution-seunshare
|
RHCOS | ✅ PASS |
rhcos4-e8-master-audit-rules-kernel-module-loading-delete
|
RHCOS | ✅ PASS |
rhcos4-e8-master-audit-rules-kernel-module-loading-finit
|
RHCOS | ✅ PASS |
rhcos4-e8-master-audit-rules-kernel-module-loading-init
|
RHCOS | ✅ PASS |
rhcos4-e8-master-audit-rules-login-events
|
RHCOS | ✅ PASS |
rhcos4-e8-master-audit-rules-login-events-faillock
|
RHCOS | ✅ PASS |
rhcos4-e8-master-audit-rules-login-events-lastlog
|
RHCOS | ✅ PASS |
rhcos4-e8-master-audit-rules-login-events-tallylog
|
RHCOS | ✅ PASS |
rhcos4-e8-master-audit-rules-networkconfig-modification
|
RHCOS | ✅ PASS |
rhcos4-e8-master-audit-rules-sysadmin-actions
|
RHCOS | ✅ PASS |
rhcos4-e8-master-audit-rules-time-adjtimex
|
RHCOS | ✅ PASS |
rhcos4-e8-master-audit-rules-time-clock-settime
|
RHCOS | ✅ PASS |
rhcos4-e8-master-audit-rules-time-settimeofday
|
RHCOS | ✅ PASS |
rhcos4-e8-master-audit-rules-time-stime
|
RHCOS | ✅ PASS |
rhcos4-e8-master-audit-rules-time-watch-localtime
|
RHCOS | ✅ PASS |
rhcos4-e8-master-audit-rules-usergroup-modification
|
RHCOS | ✅ PASS |
rhcos4-e8-master-auditd-data-retention-flush
|
RHCOS | ✅ PASS |
rhcos4-e8-master-auditd-freq
|
RHCOS | ✅ PASS |
rhcos4-e8-master-auditd-local-events
|
RHCOS | ✅ PASS |
rhcos4-e8-master-auditd-name-format
|
RHCOS | ✅ PASS |
rhcos4-e8-master-auditd-write-logs
|
RHCOS | ✅ PASS |
rhcos4-e8-master-configure-ssh-crypto-policy
|
RHCOS | ✅ PASS |
rhcos4-e8-master-selinux-policytype
|
RHCOS | ✅ PASS |
rhcos4-e8-master-sshd-disable-gssapi-auth
|
RHCOS | ✅ PASS |
rhcos4-e8-master-sshd-disable-rhosts
|
RHCOS | ✅ PASS |
rhcos4-e8-master-sshd-disable-root-login
|
RHCOS | ✅ PASS |
rhcos4-e8-master-sshd-disable-user-known-hosts
|
RHCOS | ✅ PASS |
rhcos4-e8-master-sshd-do-not-permit-user-env
|
RHCOS | ✅ PASS |
rhcos4-e8-master-sshd-enable-strictmodes
|
RHCOS | ✅ PASS |
rhcos4-e8-master-sshd-print-last-log
|
RHCOS | ✅ PASS |
rhcos4-e8-master-sysctl-kernel-kptr-restrict
|
RHCOS | ✅ PASS |
rhcos4-e8-master-sysctl-kernel-randomize-va-space
|
RHCOS | ✅ PASS |
rhcos4-e8-master-sysctl-kernel-unprivileged-bpf-disabled
|
RHCOS | ✅ PASS |
rhcos4-e8-master-sysctl-kernel-yama-ptrace-scope
|
RHCOS | ✅ PASS |
rhcos4-e8-master-sysctl-net-core-bpf-jit-harden
|
RHCOS | ✅ PASS |
rhcos4-e8-worker-audit-rules-dac-modification-chmod
|
RHCOS | ✅ PASS |
rhcos4-e8-worker-audit-rules-dac-modification-chown
|
RHCOS | ✅ PASS |
rhcos4-e8-worker-audit-rules-execution-chcon
|
RHCOS | ✅ PASS |
rhcos4-e8-worker-audit-rules-execution-restorecon
|
RHCOS | ✅ PASS |
rhcos4-e8-worker-audit-rules-execution-semanage
|
RHCOS | ✅ PASS |
rhcos4-e8-worker-audit-rules-execution-setfiles
|
RHCOS | ✅ PASS |
rhcos4-e8-worker-audit-rules-execution-setsebool
|
RHCOS | ✅ PASS |
rhcos4-e8-worker-audit-rules-execution-seunshare
|
RHCOS | ✅ PASS |
rhcos4-e8-worker-audit-rules-kernel-module-loading-delete
|
RHCOS | ✅ PASS |
rhcos4-e8-worker-audit-rules-kernel-module-loading-finit
|
RHCOS | ✅ PASS |
rhcos4-e8-worker-audit-rules-kernel-module-loading-init
|
RHCOS | ✅ PASS |
rhcos4-e8-worker-audit-rules-login-events
|
RHCOS | ✅ PASS |
rhcos4-e8-worker-audit-rules-login-events-faillock
|
RHCOS | ✅ PASS |
rhcos4-e8-worker-audit-rules-login-events-lastlog
|
RHCOS | ✅ PASS |
rhcos4-e8-worker-audit-rules-login-events-tallylog
|
RHCOS | ✅ PASS |
rhcos4-e8-worker-audit-rules-networkconfig-modification
|
RHCOS | ✅ PASS |
rhcos4-e8-worker-audit-rules-sysadmin-actions
|
RHCOS | ✅ PASS |
rhcos4-e8-worker-audit-rules-time-adjtimex
|
RHCOS | ✅ PASS |
rhcos4-e8-worker-audit-rules-time-clock-settime
|
RHCOS | ✅ PASS |
rhcos4-e8-worker-audit-rules-time-settimeofday
|
RHCOS | ✅ PASS |
rhcos4-e8-worker-audit-rules-time-stime
|
RHCOS | ✅ PASS |
rhcos4-e8-worker-audit-rules-time-watch-localtime
|
RHCOS | ✅ PASS |
rhcos4-e8-worker-audit-rules-usergroup-modification
|
RHCOS | ✅ PASS |
rhcos4-e8-worker-auditd-data-retention-flush
|
RHCOS | ✅ PASS |
rhcos4-e8-worker-auditd-freq
|
RHCOS | ✅ PASS |
rhcos4-e8-worker-auditd-local-events
|
RHCOS | ✅ PASS |
rhcos4-e8-worker-auditd-name-format
|
RHCOS | ✅ PASS |
rhcos4-e8-worker-auditd-write-logs
|
RHCOS | ✅ PASS |
rhcos4-e8-worker-configure-ssh-crypto-policy
|
RHCOS | ✅ PASS |
rhcos4-e8-worker-selinux-policytype
|
RHCOS | ✅ PASS |
rhcos4-e8-worker-sshd-disable-gssapi-auth
|
RHCOS | ✅ PASS |
rhcos4-e8-worker-sshd-disable-rhosts
|
RHCOS | ✅ PASS |
rhcos4-e8-worker-sshd-disable-root-login
|
RHCOS | ✅ PASS |
rhcos4-e8-worker-sshd-disable-user-known-hosts
|
RHCOS | ✅ PASS |
rhcos4-e8-worker-sshd-do-not-permit-user-env
|
RHCOS | ✅ PASS |
rhcos4-e8-worker-sshd-enable-strictmodes
|
RHCOS | ✅ PASS |
rhcos4-e8-worker-sshd-print-last-log
|
RHCOS | ✅ PASS |
rhcos4-e8-worker-sysctl-kernel-kptr-restrict
|
RHCOS | ✅ PASS |
rhcos4-e8-worker-sysctl-kernel-randomize-va-space
|
RHCOS | ✅ PASS |
rhcos4-e8-worker-sysctl-kernel-unprivileged-bpf-disabled
|
RHCOS | ✅ PASS |
rhcos4-e8-worker-sysctl-kernel-yama-ptrace-scope
|
RHCOS | ✅ PASS |
rhcos4-e8-worker-sysctl-net-core-bpf-jit-harden
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-dac-modification-chmod
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-dac-modification-chown
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-dac-modification-fchmod
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-dac-modification-fchmodat
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-dac-modification-fchown
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-dac-modification-fchownat
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-dac-modification-fremovexattr
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-dac-modification-fsetxattr
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-dac-modification-lchown
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-dac-modification-lremovexattr
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-dac-modification-lsetxattr
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-dac-modification-removexattr
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-dac-modification-setxattr
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-etc-group-open
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-etc-group-open-by-handle-at
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-etc-group-openat
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-etc-gshadow-open
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-etc-gshadow-open-by-handle-at
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-etc-gshadow-openat
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-etc-passwd-open
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-etc-passwd-open-by-handle-at
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-etc-passwd-openat
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-etc-shadow-open
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-etc-shadow-open-by-handle-at
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-etc-shadow-openat
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-execution-chcon
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-execution-restorecon
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-execution-semanage
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-execution-setfiles
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-execution-setsebool
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-execution-seunshare
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-file-deletion-events-rename
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-file-deletion-events-renameat
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-file-deletion-events-rmdir
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-file-deletion-events-unlink
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-file-deletion-events-unlinkat
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-immutable
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-kernel-module-loading-delete
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-kernel-module-loading-finit
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-kernel-module-loading-init
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-login-events-faillock
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-login-events-lastlog
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-login-events-tallylog
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-mac-modification
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-media-export
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-networkconfig-modification
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-privileged-commands-at
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-privileged-commands-chage
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-privileged-commands-chsh
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-privileged-commands-crontab
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-privileged-commands-gpasswd
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-privileged-commands-mount
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-privileged-commands-newgidmap
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-privileged-commands-newgrp
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-privileged-commands-newuidmap
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-privileged-commands-pam-timestamp-check
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-privileged-commands-passwd
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-privileged-commands-postdrop
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-privileged-commands-postqueue
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-privileged-commands-pt-chown
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-privileged-commands-ssh-keysign
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-privileged-commands-su
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-privileged-commands-sudo
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-privileged-commands-sudoedit
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-privileged-commands-umount
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-privileged-commands-unix-chkpwd
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-privileged-commands-userhelper
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-privileged-commands-usernetctl
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-session-events
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-sysadmin-actions
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-time-adjtimex
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-time-clock-settime
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-time-settimeofday
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-time-stime
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-time-watch-localtime
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-unsuccessful-file-modification-chmod
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-unsuccessful-file-modification-chown
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-unsuccessful-file-modification-creat
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-unsuccessful-file-modification-fchmod
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-unsuccessful-file-modification-fchmodat
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-unsuccessful-file-modification-fchown
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-unsuccessful-file-modification-fchownat
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-unsuccessful-file-modification-fremovexattr
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-unsuccessful-file-modification-fsetxattr
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-unsuccessful-file-modification-ftruncate
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-unsuccessful-file-modification-lchown
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-unsuccessful-file-modification-lremovexattr
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-unsuccessful-file-modification-lsetxattr
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-unsuccessful-file-modification-open
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-unsuccessful-file-modification-open-by-handle-at
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-unsuccessful-file-modification-open-by-handle-at-o-creat
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-unsuccessful-file-modification-open-by-handle-at-o-trunc-write
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-unsuccessful-file-modification-open-by-handle-at-rule-order
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-unsuccessful-file-modification-open-o-creat
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-unsuccessful-file-modification-open-o-trunc-write
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-unsuccessful-file-modification-open-rule-order
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-unsuccessful-file-modification-openat
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-unsuccessful-file-modification-openat-o-creat
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-unsuccessful-file-modification-openat-o-trunc-write
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-unsuccessful-file-modification-openat-rule-order
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-unsuccessful-file-modification-removexattr
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-unsuccessful-file-modification-rename
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-unsuccessful-file-modification-renameat
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-unsuccessful-file-modification-setxattr
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-unsuccessful-file-modification-truncate
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-unsuccessful-file-modification-unlink
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-unsuccessful-file-modification-unlinkat
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-usergroup-modification-group
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-usergroup-modification-gshadow
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-usergroup-modification-opasswd
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-usergroup-modification-passwd
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-audit-rules-usergroup-modification-shadow
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-auditd-data-disk-error-action
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-auditd-data-disk-full-action
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-auditd-data-retention-admin-space-left-action
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-auditd-data-retention-flush
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-auditd-data-retention-max-log-file
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-auditd-data-retention-max-log-file-action
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-auditd-data-retention-num-logs
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-auditd-data-retention-space-left
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-auditd-data-retention-space-left-action
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-auditd-freq
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-auditd-local-events
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-auditd-name-format
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-auditd-write-logs
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-banner-etc-issue
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-chronyd-or-ntpd-set-maxpoll
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-chronyd-or-ntpd-specify-multiple-servers
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-chronyd-or-ntpd-specify-remote-server
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-configure-openssl-crypto-policy
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-configure-ssh-crypto-policy
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-coredump-disable-backtraces
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-coredump-disable-storage
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-coreos-audit-backlog-limit-kernel-argument
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-coreos-audit-option
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-coreos-disable-interactive-boot
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-coreos-enable-selinux-kernel-argument
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-coreos-nousb-kernel-argument
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-coreos-page-poison-kernel-argument
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-coreos-vsyscall-kernel-argument
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-directory-access-var-log-audit
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-directory-permissions-var-log-audit
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-disable-users-coredumps
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-ensure-logrotate-activated
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-file-groupowner-sshd-config
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-file-owner-sshd-config
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-file-ownership-var-log-audit
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-file-permissions-sshd-config
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-file-permissions-sshd-private-key
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-file-permissions-sshd-pub-key
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-file-permissions-var-log-audit
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-kernel-module-atm-disabled
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-kernel-module-bluetooth-disabled
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-kernel-module-can-disabled
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-kernel-module-cfg80211-disabled
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-kernel-module-iwlmvm-disabled
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-kernel-module-iwlwifi-disabled
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-kernel-module-mac80211-disabled
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-kernel-module-sctp-disabled
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-kernel-module-usb-storage-disabled
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-no-direct-root-logins
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-no-netrc-files
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-no-shelllogin-for-systemaccounts
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-package-audit-installed
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-package-sudo-installed
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-require-singleuser-auth
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-selinux-policytype
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-service-auditd-enabled
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-service-bluetooth-disabled
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-service-chronyd-or-ntpd-enabled
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-service-debug-shell-disabled
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-service-systemd-coredump-disabled
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-sshd-disable-rhosts
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-sysctl-fs-protected-hardlinks
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-sysctl-fs-protected-symlinks
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-sysctl-kernel-core-pattern
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-sysctl-kernel-kexec-load-disabled
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-sysctl-kernel-kptr-restrict
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-sysctl-kernel-unprivileged-bpf-disabled
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-sysctl-kernel-yama-ptrace-scope
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-sysctl-net-core-bpf-jit-harden
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-sysctl-net-ipv4-conf-all-accept-redirects
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-sysctl-net-ipv4-conf-all-accept-source-route
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-sysctl-net-ipv4-conf-all-rp-filter
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-sysctl-net-ipv4-conf-all-secure-redirects
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-sysctl-net-ipv4-conf-all-send-redirects
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-sysctl-net-ipv4-conf-default-accept-redirects
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-sysctl-net-ipv4-conf-default-accept-source-route
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-sysctl-net-ipv4-conf-default-rp-filter
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-sysctl-net-ipv4-conf-default-secure-redirects
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-sysctl-net-ipv4-conf-default-send-redirects
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-sysctl-net-ipv4-icmp-echo-ignore-broadcasts
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-sysctl-net-ipv4-tcp-syncookies
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-sysctl-net-ipv6-conf-all-accept-ra
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-sysctl-net-ipv6-conf-all-accept-redirects
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-sysctl-net-ipv6-conf-all-accept-source-route
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-sysctl-net-ipv6-conf-default-accept-ra
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-sysctl-net-ipv6-conf-default-accept-redirects
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-sysctl-net-ipv6-conf-default-accept-source-route
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-dac-modification-chmod
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-dac-modification-chown
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-dac-modification-fchmod
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-dac-modification-fchmodat
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-dac-modification-fchown
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-dac-modification-fchownat
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-dac-modification-fremovexattr
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-dac-modification-fsetxattr
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-dac-modification-lchown
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-dac-modification-lremovexattr
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-dac-modification-lsetxattr
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-dac-modification-removexattr
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-dac-modification-setxattr
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-etc-group-open
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-etc-group-open-by-handle-at
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-etc-group-openat
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-etc-gshadow-open
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-etc-gshadow-open-by-handle-at
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-etc-gshadow-openat
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-etc-passwd-open
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-etc-passwd-open-by-handle-at
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-etc-passwd-openat
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-etc-shadow-open
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-etc-shadow-open-by-handle-at
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-etc-shadow-openat
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-execution-chcon
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-execution-restorecon
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-execution-semanage
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-execution-setfiles
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-execution-setsebool
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-execution-seunshare
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-file-deletion-events-rename
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-file-deletion-events-renameat
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-file-deletion-events-rmdir
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-file-deletion-events-unlink
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-file-deletion-events-unlinkat
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-immutable
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-kernel-module-loading-delete
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-kernel-module-loading-finit
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-kernel-module-loading-init
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-login-events-faillock
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-login-events-lastlog
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-login-events-tallylog
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-mac-modification
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-media-export
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-networkconfig-modification
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-privileged-commands-at
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-privileged-commands-chage
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-privileged-commands-chsh
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-privileged-commands-crontab
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-privileged-commands-gpasswd
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-privileged-commands-mount
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-privileged-commands-newgidmap
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-privileged-commands-newgrp
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-privileged-commands-newuidmap
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-privileged-commands-pam-timestamp-check
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-privileged-commands-passwd
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-privileged-commands-postdrop
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-privileged-commands-postqueue
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-privileged-commands-pt-chown
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-privileged-commands-ssh-keysign
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-privileged-commands-su
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-privileged-commands-sudo
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-privileged-commands-sudoedit
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-privileged-commands-umount
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-privileged-commands-unix-chkpwd
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-privileged-commands-userhelper
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-privileged-commands-usernetctl
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-session-events
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-sysadmin-actions
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-time-adjtimex
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-time-clock-settime
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-time-settimeofday
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-time-stime
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-time-watch-localtime
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-unsuccessful-file-modification-chmod
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-unsuccessful-file-modification-chown
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-unsuccessful-file-modification-creat
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-unsuccessful-file-modification-fchmod
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-unsuccessful-file-modification-fchmodat
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-unsuccessful-file-modification-fchown
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-unsuccessful-file-modification-fchownat
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-unsuccessful-file-modification-fremovexattr
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-unsuccessful-file-modification-fsetxattr
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-unsuccessful-file-modification-ftruncate
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-unsuccessful-file-modification-lchown
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-unsuccessful-file-modification-lremovexattr
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-unsuccessful-file-modification-lsetxattr
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-unsuccessful-file-modification-open
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-unsuccessful-file-modification-open-by-handle-at
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-unsuccessful-file-modification-open-by-handle-at-o-creat
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-unsuccessful-file-modification-open-by-handle-at-o-trunc-write
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-unsuccessful-file-modification-open-by-handle-at-rule-order
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-unsuccessful-file-modification-open-o-creat
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-unsuccessful-file-modification-open-o-trunc-write
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-unsuccessful-file-modification-open-rule-order
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-unsuccessful-file-modification-openat
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-unsuccessful-file-modification-openat-o-creat
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-unsuccessful-file-modification-openat-o-trunc-write
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-unsuccessful-file-modification-openat-rule-order
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-unsuccessful-file-modification-removexattr
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-unsuccessful-file-modification-rename
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-unsuccessful-file-modification-renameat
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-unsuccessful-file-modification-setxattr
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-unsuccessful-file-modification-truncate
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-unsuccessful-file-modification-unlink
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-unsuccessful-file-modification-unlinkat
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-usergroup-modification-group
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-usergroup-modification-gshadow
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-usergroup-modification-opasswd
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-usergroup-modification-passwd
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-audit-rules-usergroup-modification-shadow
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-auditd-data-disk-error-action
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-auditd-data-disk-full-action
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-auditd-data-retention-admin-space-left-action
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-auditd-data-retention-flush
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-auditd-data-retention-max-log-file
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-auditd-data-retention-max-log-file-action
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-auditd-data-retention-num-logs
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-auditd-data-retention-space-left
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-auditd-data-retention-space-left-action
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-auditd-freq
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-auditd-local-events
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-auditd-name-format
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-auditd-write-logs
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-banner-etc-issue
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-chronyd-or-ntpd-set-maxpoll
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-chronyd-or-ntpd-specify-multiple-servers
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-chronyd-or-ntpd-specify-remote-server
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-configure-openssl-crypto-policy
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-configure-ssh-crypto-policy
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-coredump-disable-backtraces
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-coredump-disable-storage
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-coreos-audit-backlog-limit-kernel-argument
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-coreos-audit-option
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-coreos-disable-interactive-boot
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-coreos-enable-selinux-kernel-argument
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-coreos-nousb-kernel-argument
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-coreos-page-poison-kernel-argument
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-coreos-vsyscall-kernel-argument
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-directory-access-var-log-audit
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-directory-permissions-var-log-audit
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-disable-users-coredumps
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-ensure-logrotate-activated
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-file-groupowner-sshd-config
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-file-owner-sshd-config
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-file-ownership-var-log-audit
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-file-permissions-sshd-config
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-file-permissions-sshd-private-key
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-file-permissions-sshd-pub-key
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-file-permissions-var-log-audit
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-kernel-module-atm-disabled
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-kernel-module-bluetooth-disabled
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-kernel-module-can-disabled
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-kernel-module-cfg80211-disabled
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-kernel-module-iwlmvm-disabled
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-kernel-module-iwlwifi-disabled
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-kernel-module-mac80211-disabled
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-kernel-module-sctp-disabled
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-kernel-module-usb-storage-disabled
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-no-direct-root-logins
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-no-netrc-files
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-no-shelllogin-for-systemaccounts
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-package-audit-installed
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-package-sudo-installed
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-require-singleuser-auth
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-selinux-policytype
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-service-auditd-enabled
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-service-bluetooth-disabled
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-service-chronyd-or-ntpd-enabled
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-service-debug-shell-disabled
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-service-systemd-coredump-disabled
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-sshd-disable-rhosts
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-sysctl-fs-protected-hardlinks
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-sysctl-fs-protected-symlinks
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-sysctl-kernel-core-pattern
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-sysctl-kernel-kexec-load-disabled
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-sysctl-kernel-kptr-restrict
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-sysctl-kernel-unprivileged-bpf-disabled
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-sysctl-kernel-yama-ptrace-scope
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-sysctl-net-core-bpf-jit-harden
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-sysctl-net-ipv4-conf-all-accept-redirects
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-sysctl-net-ipv4-conf-all-accept-source-route
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-sysctl-net-ipv4-conf-all-rp-filter
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-sysctl-net-ipv4-conf-all-secure-redirects
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-sysctl-net-ipv4-conf-all-send-redirects
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-sysctl-net-ipv4-conf-default-accept-redirects
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-sysctl-net-ipv4-conf-default-accept-source-route
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-sysctl-net-ipv4-conf-default-rp-filter
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-sysctl-net-ipv4-conf-default-secure-redirects
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-sysctl-net-ipv4-conf-default-send-redirects
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-sysctl-net-ipv4-icmp-echo-ignore-broadcasts
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-sysctl-net-ipv4-tcp-syncookies
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-sysctl-net-ipv6-conf-all-accept-ra
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-sysctl-net-ipv6-conf-all-accept-redirects
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-sysctl-net-ipv6-conf-all-accept-source-route
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-sysctl-net-ipv6-conf-default-accept-ra
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-sysctl-net-ipv6-conf-default-accept-redirects
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-sysctl-net-ipv6-conf-default-accept-source-route
|
RHCOS | ✅ PASS |
LOW Severity Passing Checks (51)
| Check Name | Platform | Status |
|---|---|---|
ocp4-cis-api-server-audit-log-maxbackup
|
OCP | ✅ PASS |
ocp4-cis-api-server-bind-address
|
OCP | ✅ PASS |
ocp4-cis-controller-insecure-port-disabled
|
OCP | ✅ PASS |
ocp4-cis-controller-secure-port
|
OCP | ✅ PASS |
ocp4-cis-ocp-api-server-audit-log-maxbackup
|
OCP | ✅ PASS |
ocp4-moderate-api-server-audit-log-maxbackup
|
OCP | ✅ PASS |
ocp4-moderate-api-server-bind-address
|
OCP | ✅ PASS |
ocp4-moderate-controller-insecure-port-disabled
|
OCP | ✅ PASS |
ocp4-moderate-controller-secure-port
|
OCP | ✅ PASS |
ocp4-moderate-ocp-api-server-audit-log-maxbackup
|
OCP | ✅ PASS |
ocp4-pci-dss-api-server-audit-log-maxbackup
|
OCP | ✅ PASS |
ocp4-pci-dss-api-server-bind-address
|
OCP | ✅ PASS |
ocp4-pci-dss-controller-insecure-port-disabled
|
OCP | ✅ PASS |
ocp4-pci-dss-controller-secure-port
|
OCP | ✅ PASS |
ocp4-pci-dss-ocp-api-server-audit-log-maxbackup
|
OCP | ✅ PASS |
rhcos4-e8-master-auditd-log-format
|
RHCOS | ✅ PASS |
rhcos4-e8-master-sshd-set-loglevel-info
|
RHCOS | ✅ PASS |
rhcos4-e8-master-sysctl-kernel-dmesg-restrict
|
RHCOS | ✅ PASS |
rhcos4-e8-worker-auditd-log-format
|
RHCOS | ✅ PASS |
rhcos4-e8-worker-sshd-set-loglevel-info
|
RHCOS | ✅ PASS |
rhcos4-e8-worker-sysctl-kernel-dmesg-restrict
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-auditd-log-format
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-chronyd-client-only
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-chronyd-no-chronyc-network
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-kernel-module-cramfs-disabled
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-kernel-module-firewire-core-disabled
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-kernel-module-freevxfs-disabled
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-kernel-module-hfs-disabled
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-kernel-module-hfsplus-disabled
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-kernel-module-jffs2-disabled
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-kernel-module-squashfs-disabled
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-kernel-module-tipc-disabled
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-kernel-module-udf-disabled
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-no-tmux-in-shells
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-sysctl-kernel-dmesg-restrict
|
RHCOS | ✅ PASS |
rhcos4-moderate-master-sysctl-kernel-perf-event-paranoid
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-auditd-log-format
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-chronyd-client-only
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-chronyd-no-chronyc-network
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-kernel-module-cramfs-disabled
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-kernel-module-firewire-core-disabled
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-kernel-module-freevxfs-disabled
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-kernel-module-hfs-disabled
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-kernel-module-hfsplus-disabled
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-kernel-module-jffs2-disabled
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-kernel-module-squashfs-disabled
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-kernel-module-tipc-disabled
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-kernel-module-udf-disabled
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-no-tmux-in-shells
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-sysctl-kernel-dmesg-restrict
|
RHCOS | ✅ PASS |
rhcos4-moderate-worker-sysctl-kernel-perf-event-paranoid
|
RHCOS | ✅ PASS |