← Back to Home 📄 View Raw XML

🔍 OSCAP Scan Result - Management and monitoring server running Ubuntu 24.04 LTS

Target System: ubuntu-mgmt-01.example.com
IP Address: 192.168.1.105
OS: Ubuntu 24.04 LTS
Scan Start: 2026-05-08T16:16:56.232025
Scan End: 2026-05-08T16:23:56.232025

87

Passed

6

Failed

0

Other

Rule Check Results

Rule ID Result Severity Message
accounts_password_pam_unix_enabled PASS LOW -
accounts_root_gid_zero PASS MEDIUM -
accounts_umask_etc_bashrc PASS LOW -
accounts_umask_etc_login_defs FAIL LOW Check failed: accounts_umask_etc_login_defs
accounts_umask_etc_profile PASS LOW -
accounts_umask_root PASS LOW -
ensure_pam_wheel_group_empty PASS HIGH -
ensure_root_access_controlled PASS MEDIUM -
file_groupowner_sshd_config PASS MEDIUM -
file_owner_sshd_config PASS LOW -
file_permissions_sshd_config PASS MEDIUM -
file_permissions_sshd_private_key PASS HIGH -
file_permissions_sshd_pub_key PASS HIGH -
groups_no_zero_gid_except_root PASS MEDIUM -
no_invalid_shell_accounts_unlocked PASS LOW -
no_shelllogin_for_systemaccounts PASS HIGH -
sshd_limit_user_access PASS LOW -
use_pam_wheel_group_for_su PASS MEDIUM -
sshd_use_strong_ciphers PASS HIGH -
sshd_use_strong_kex PASS HIGH -
sshd_use_strong_macs PASS LOW -
accounts_password_pam_pwhistory_use_authtok PASS MEDIUM -
accounts_password_pam_unix_authtok PASS HIGH -
set_password_hashing_algorithm_logindefs PASS HIGH -
set_password_hashing_algorithm_systemauth PASS HIGH -
account_disable_post_pw_expiration PASS LOW -
accounts_maximum_age_login_defs PASS MEDIUM -
accounts_minimum_age_login_defs PASS HIGH -
accounts_password_last_change_is_in_past PASS HIGH -
accounts_password_pam_dcredit PASS LOW -
accounts_password_pam_dictcheck PASS MEDIUM -
accounts_password_pam_difok PASS LOW -
accounts_password_pam_enforce_root PASS MEDIUM -
accounts_password_pam_enforcing PASS HIGH -
accounts_password_pam_lcredit PASS LOW -
accounts_password_pam_maxrepeat PASS LOW -
accounts_password_pam_maxsequence PASS MEDIUM -
accounts_password_pam_minclass PASS HIGH -
accounts_password_pam_minlen PASS MEDIUM -
accounts_password_pam_ocredit PASS HIGH -
accounts_password_pam_pwhistory_enabled PASS LOW -
accounts_password_pam_pwhistory_enforce_root PASS MEDIUM -
accounts_password_pam_pwhistory_remember PASS LOW -
accounts_password_pam_pwquality_enabled PASS LOW -
accounts_password_pam_ucredit PASS MEDIUM -
accounts_password_pam_unix_no_remember PASS MEDIUM -
accounts_password_set_max_life_existing PASS MEDIUM -
accounts_password_set_min_life_existing PASS HIGH -
no_empty_passwords_unix PASS MEDIUM -
sshd_disable_empty_passwords PASS LOW -
sshd_disable_gssapi_auth PASS LOW -
sshd_disable_rhosts FAIL MEDIUM Check failed: sshd_disable_rhosts
sshd_enable_pam PASS HIGH -
accounts_password_warn_age_login_defs PASS LOW -
sshd_disable_forwarding PASS LOW -
accounts_tmout PASS LOW -
package_sudo_installed PASS HIGH -
sshd_disable_root_login PASS HIGH -
sudo_add_use_pty PASS HIGH -
sudo_remove_no_authenticate PASS HIGH -
sudo_require_authentication PASS LOW -
sudo_require_reauthentication PASS LOW -
accounts_passwords_pam_faillock_deny PASS LOW -
accounts_passwords_pam_faillock_enabled FAIL MEDIUM Check failed: accounts_passwords_pam_faillock_enabled
accounts_passwords_pam_faillock_root_unlock_time PASS MEDIUM -
accounts_passwords_pam_faillock_unlock_time PASS HIGH -
sshd_set_loglevel_info FAIL MEDIUM Check failed: sshd_set_loglevel_info
sshd_set_max_auth_tries PASS LOW -
sudo_custom_logfile FAIL MEDIUM Check failed: sudo_custom_logfile
account_automated_provisioning_enabled PASS HIGH -
account_temporary_expiration_configured PASS MEDIUM -
account_disable_inactive_accounts PASS HIGH -
sudo_security_function_authorization PASS MEDIUM -
service_nonprivileged_user_execution PASS LOW -
screen_lock_timeout_configured PASS MEDIUM -
screen_lock_pattern_hiding_enabled PASS MEDIUM -
sshd_logging_enabled PASS MEDIUM -
auditd_extended_information_enabled FAIL MEDIUM Check failed: auditd_extended_information_enabled
log_analysis_tool_configured PASS LOW -
change_control_documentation_required PASS LOW -
service_periodic_review_enabled PASS LOW -
package_update_automation_configured PASS MEDIUM -
intrusion_detection_tool_installed PASS HIGH -
encrypted_traffic_inspection_configured PASS HIGH -
privileged_command_network_restriction PASS HIGH -
concurrent_session_limit_configured PASS LOW -
auditd_storage_threshold_alert PASS MEDIUM -
auditd_realtime_alerts_enabled PASS MEDIUM -
centralized_logging_configured PASS HIGH -
audit_logs_remote_storage PASS MEDIUM -
audit_logs_encrypted PASS LOW -
critical_action_signing_enabled PASS MEDIUM -
time_synchronization_configured PASS LOW -