← Back to Home 📄 View Raw XML

🔍 OSCAP Scan Result - Tertiary web server running Ubuntu 24.04 LTS

Target System: ubuntu-web-03.example.com
IP Address: 192.168.1.106
OS: Ubuntu 24.04 LTS
Scan Start: 2026-05-07T08:16:56.232025
Scan End: 2026-05-07T08:29:56.232025

79

Passed

14

Failed

0

Other

Rule Check Results

Rule ID Result Severity Message
accounts_password_pam_unix_enabled PASS MEDIUM -
accounts_root_gid_zero PASS LOW -
accounts_umask_etc_bashrc PASS LOW -
accounts_umask_etc_login_defs FAIL LOW Check failed: accounts_umask_etc_login_defs
accounts_umask_etc_profile PASS LOW -
accounts_umask_root PASS MEDIUM -
ensure_pam_wheel_group_empty PASS MEDIUM -
ensure_root_access_controlled PASS MEDIUM -
file_groupowner_sshd_config PASS LOW -
file_owner_sshd_config FAIL LOW Check failed: file_owner_sshd_config
file_permissions_sshd_config FAIL HIGH Check failed: file_permissions_sshd_config
file_permissions_sshd_private_key PASS HIGH -
file_permissions_sshd_pub_key FAIL HIGH Check failed: file_permissions_sshd_pub_key
groups_no_zero_gid_except_root PASS MEDIUM -
no_invalid_shell_accounts_unlocked PASS MEDIUM -
no_shelllogin_for_systemaccounts PASS MEDIUM -
sshd_limit_user_access PASS HIGH -
use_pam_wheel_group_for_su PASS LOW -
sshd_use_strong_ciphers PASS HIGH -
sshd_use_strong_kex PASS HIGH -
sshd_use_strong_macs PASS HIGH -
accounts_password_pam_pwhistory_use_authtok PASS LOW -
accounts_password_pam_unix_authtok PASS MEDIUM -
set_password_hashing_algorithm_logindefs PASS LOW -
set_password_hashing_algorithm_systemauth PASS MEDIUM -
account_disable_post_pw_expiration PASS HIGH -
accounts_maximum_age_login_defs FAIL LOW Check failed: accounts_maximum_age_login_defs
accounts_minimum_age_login_defs PASS MEDIUM -
accounts_password_last_change_is_in_past PASS HIGH -
accounts_password_pam_dcredit PASS HIGH -
accounts_password_pam_dictcheck PASS MEDIUM -
accounts_password_pam_difok PASS LOW -
accounts_password_pam_enforce_root PASS MEDIUM -
accounts_password_pam_enforcing PASS MEDIUM -
accounts_password_pam_lcredit PASS LOW -
accounts_password_pam_maxrepeat PASS MEDIUM -
accounts_password_pam_maxsequence PASS LOW -
accounts_password_pam_minclass PASS HIGH -
accounts_password_pam_minlen PASS MEDIUM -
accounts_password_pam_ocredit PASS LOW -
accounts_password_pam_pwhistory_enabled PASS MEDIUM -
accounts_password_pam_pwhistory_enforce_root PASS LOW -
accounts_password_pam_pwhistory_remember PASS MEDIUM -
accounts_password_pam_pwquality_enabled PASS MEDIUM -
accounts_password_pam_ucredit PASS MEDIUM -
accounts_password_pam_unix_no_remember PASS LOW -
accounts_password_set_max_life_existing PASS LOW -
accounts_password_set_min_life_existing PASS HIGH -
no_empty_passwords_unix FAIL MEDIUM Check failed: no_empty_passwords_unix
sshd_disable_empty_passwords PASS HIGH -
sshd_disable_gssapi_auth FAIL LOW Check failed: sshd_disable_gssapi_auth
sshd_disable_rhosts PASS LOW -
sshd_enable_pam PASS HIGH -
accounts_password_warn_age_login_defs PASS HIGH -
sshd_disable_forwarding PASS LOW -
accounts_tmout PASS MEDIUM -
package_sudo_installed PASS LOW -
sshd_disable_root_login FAIL MEDIUM Check failed: sshd_disable_root_login
sudo_add_use_pty PASS LOW -
sudo_remove_no_authenticate PASS LOW -
sudo_require_authentication PASS HIGH -
sudo_require_reauthentication PASS LOW -
accounts_passwords_pam_faillock_deny PASS MEDIUM -
accounts_passwords_pam_faillock_enabled PASS HIGH -
accounts_passwords_pam_faillock_root_unlock_time PASS MEDIUM -
accounts_passwords_pam_faillock_unlock_time PASS HIGH -
sshd_set_loglevel_info FAIL LOW Check failed: sshd_set_loglevel_info
sshd_set_max_auth_tries PASS MEDIUM -
sudo_custom_logfile FAIL HIGH Check failed: sudo_custom_logfile
account_automated_provisioning_enabled PASS MEDIUM -
account_temporary_expiration_configured PASS LOW -
account_disable_inactive_accounts PASS HIGH -
sudo_security_function_authorization PASS HIGH -
service_nonprivileged_user_execution PASS HIGH -
screen_lock_timeout_configured PASS HIGH -
screen_lock_pattern_hiding_enabled FAIL MEDIUM Check failed: screen_lock_pattern_hiding_enabled
sshd_logging_enabled PASS LOW -
auditd_extended_information_enabled PASS MEDIUM -
log_analysis_tool_configured PASS HIGH -
change_control_documentation_required PASS MEDIUM -
service_periodic_review_enabled PASS HIGH -
package_update_automation_configured FAIL MEDIUM Check failed: package_update_automation_configured
intrusion_detection_tool_installed FAIL HIGH Check failed: intrusion_detection_tool_installed
encrypted_traffic_inspection_configured FAIL HIGH Check failed: encrypted_traffic_inspection_configured
privileged_command_network_restriction PASS LOW -
concurrent_session_limit_configured PASS LOW -
auditd_storage_threshold_alert PASS LOW -
auditd_realtime_alerts_enabled PASS HIGH -
centralized_logging_configured PASS MEDIUM -
audit_logs_remote_storage PASS LOW -
audit_logs_encrypted PASS LOW -
critical_action_signing_enabled PASS HIGH -
time_synchronization_configured PASS LOW -