|
| 1 | +--- |
| 2 | +title: Reference - CIS Security Benchmarks for AlmaLinux via Machine Configuration |
| 3 | +description: Reference - CIS Security Benchmarks for AlmaLinux via Machine Configuration |
| 4 | +ms.date: 11/07/2025 |
| 5 | +author: pallakatos |
| 6 | +ms.author: pallakatos |
| 7 | +ms.topic: reference |
| 8 | +ms.custom: generated |
| 9 | +--- |
| 10 | +# Release notes - AlmaLinux |
| 11 | + |
| 12 | +This article provides detailed information about the CIS Security Benchmarks for AlmaLinux, including supported benchmarks, mismatched rules, and configurable parameters across all supported versions. |
| 13 | + |
| 14 | +## Supported benchmarks |
| 15 | + |
| 16 | +|AlmaLinux Version|Benchmark Title| |
| 17 | +|---|---| |
| 18 | +|AlmaLinux 8|[CIS AlmaLinux OS 8 Benchmark 3.0.0 Level 1 + Level 2 - Server](#cis-almalinux-os-8-benchmark-300-level-1--level-2---server)| |
| 19 | +|AlmaLinux 9|[CIS AlmaLinux OS 9 Benchmark 2.0.0 Level 1 + Level 2 - Server](#cis-almalinux-os-9-benchmark-200-level-1--level-2---server)| |
| 20 | + |
| 21 | +## CIS AlmaLinux OS 8 Benchmark 3.0.0 Level 1 + Level 2 - Server |
| 22 | + |
| 23 | +### Mismatched rules |
| 24 | + |
| 25 | +> [!NOTE] |
| 26 | +> The mismatched rules are the ones that in some circumstances the assessment might differ from CIS-CAT® Pro Assessor; usually our implementation enforces stricter criteria. |
| 27 | +
|
| 28 | +- Ensure only one logging system is in use |
| 29 | + |
| 30 | +### Not implemented rules |
| 31 | + |
| 32 | +- Ensure access to the su command is restricted |
| 33 | + |
| 34 | +### Configurable parameters |
| 35 | + |
| 36 | +|Rule|Parameter|Default Value| |
| 37 | +|---|---|---| |
| 38 | +|Ensure dns server services are not in use|serviceName|named.service| |
| 39 | +||expectedUnitFileState|enabled| |
| 40 | +||expectedActiveState|active| |
| 41 | +||packageName|bind| |
| 42 | +|Ensure permissions on /etc/crontab are configured|mask|0177| |
| 43 | +||owner|root| |
| 44 | +||group|root| |
| 45 | +|Ensure permissions on /etc/cron.hourly are configured|mask|0077| |
| 46 | +||owner|root| |
| 47 | +||group|root| |
| 48 | +|Ensure permissions on /etc/cron.daily are configured|mask|0077| |
| 49 | +||owner|root| |
| 50 | +||group|root| |
| 51 | +||packageName|cron| |
| 52 | +||alternativePackageName|cronie| |
| 53 | +|Ensure permissions on /etc/cron.weekly are configured|mask|0077| |
| 54 | +||owner|root| |
| 55 | +||group|root| |
| 56 | +|Ensure permissions on /etc/cron.monthly are configured|mask|0077| |
| 57 | +||owner|root| |
| 58 | +||group|root| |
| 59 | +||alternativePackageName|cronie| |
| 60 | +|Ensure permissions on /etc/cron.d are configured|mask|0077| |
| 61 | +||owner|root| |
| 62 | +||group|root| |
| 63 | +|Ensure permissions on /etc/ssh/sshd_config are configured|mask|0177| |
| 64 | +||owner|root| |
| 65 | +||group|root| |
| 66 | +|Ensure permissions on /etc/passwd are configured|mask|0133| |
| 67 | +||owner|root| |
| 68 | +||group|root| |
| 69 | +|Ensure permissions on /etc/passwd- are configured|mask|0133| |
| 70 | +||owner|root| |
| 71 | +||group|root| |
| 72 | +|Ensure permissions on /etc/group are configured|mask|0133| |
| 73 | +||owner|root| |
| 74 | +||group|root| |
| 75 | +|Ensure permissions on /etc/group- are configured|mask|0133| |
| 76 | +||owner|root| |
| 77 | +||group|root| |
| 78 | +|Ensure permissions on /etc/shadow are configured|mask|0137| |
| 79 | +||owner|root| |
| 80 | +||group|root\|shadow| |
| 81 | +|Ensure permissions on /etc/shadow- are configured|mask|0137| |
| 82 | +||owner|root| |
| 83 | +||group|root\|shadow| |
| 84 | +|Ensure permissions on /etc/gshadow are configured|mask|0137| |
| 85 | +||owner|root| |
| 86 | +||group|shadow\|root| |
| 87 | +|Ensure permissions on /etc/gshadow- are configured|mask|0137| |
| 88 | +||owner|root| |
| 89 | +||group|shadow\|root| |
| 90 | +|Ensure permissions on /etc/shells are configured|mask|0133| |
| 91 | +||owner|root| |
| 92 | +||group|root| |
| 93 | +|Ensure permissions on /etc/security/opasswd are configured|mask|0177| |
| 94 | +||owner|root| |
| 95 | +||group|root| |
| 96 | + |
| 97 | +## CIS AlmaLinux OS 9 Benchmark 2.0.0 Level 1 + Level 2 - Server |
| 98 | + |
| 99 | +### Mismatched rules |
| 100 | + |
| 101 | +> [!NOTE] |
| 102 | +> The mismatched rules are the ones that in some circumstances the assessment might differ from CIS-CAT® Pro Assessor; usually our implementation enforces stricter criteria. |
| 103 | +
|
| 104 | +- Ensure only one logging system is in use |
| 105 | + |
| 106 | +### Not implemented rules |
| 107 | + |
| 108 | +- Ensure access to the su command is restricted |
| 109 | + |
| 110 | +### Configurable parameters |
| 111 | + |
| 112 | +|Rule|Parameter|Default Value| |
| 113 | +|---|---|---| |
| 114 | +|Ensure dns server services are not in use|serviceName|named.service| |
| 115 | +||expectedUnitFileState|enabled| |
| 116 | +||expectedActiveState|active| |
| 117 | +||packageName|bind| |
| 118 | +|Ensure permissions on /etc/crontab are configured|mask|0177| |
| 119 | +||owner|root| |
| 120 | +||group|root| |
| 121 | +|Ensure permissions on /etc/cron.hourly are configured|mask|0077| |
| 122 | +||owner|root| |
| 123 | +||group|root| |
| 124 | +|Ensure permissions on /etc/cron.daily are configured|mask|0077| |
| 125 | +||owner|root| |
| 126 | +||group|root| |
| 127 | +||packageName|cron| |
| 128 | +||alternativePackageName|cronie| |
| 129 | +|Ensure permissions on /etc/cron.weekly are configured|mask|0077| |
| 130 | +||owner|root| |
| 131 | +||group|root| |
| 132 | +|Ensure permissions on /etc/cron.monthly are configured|mask|0077| |
| 133 | +||owner|root| |
| 134 | +||group|root| |
| 135 | +||alternativePackageName|cronie| |
| 136 | +|Ensure permissions on /etc/cron.d are configured|mask|0077| |
| 137 | +||owner|root| |
| 138 | +||group|root| |
| 139 | +|Ensure permissions on /etc/ssh/sshd_config are configured|mask|0177| |
| 140 | +||owner|root| |
| 141 | +||group|root| |
| 142 | +|Ensure permissions on /etc/passwd are configured|mask|0133| |
| 143 | +||owner|root| |
| 144 | +||group|root| |
| 145 | +|Ensure permissions on /etc/passwd- are configured|mask|0133| |
| 146 | +||owner|root| |
| 147 | +||group|root| |
| 148 | +|Ensure permissions on /etc/group are configured|mask|0133| |
| 149 | +||owner|root| |
| 150 | +||group|root| |
| 151 | +|Ensure permissions on /etc/group- are configured|mask|0133| |
| 152 | +||owner|root| |
| 153 | +||group|root| |
| 154 | +|Ensure permissions on /etc/shadow are configured|mask|0137| |
| 155 | +||owner|root| |
| 156 | +||group|root\|shadow| |
| 157 | +|Ensure permissions on /etc/shadow- are configured|mask|0137| |
| 158 | +||owner|root| |
| 159 | +||group|root\|shadow| |
| 160 | +|Ensure permissions on /etc/gshadow are configured|mask|0137| |
| 161 | +||owner|root| |
| 162 | +||group|shadow\|root| |
| 163 | +|Ensure permissions on /etc/gshadow- are configured|mask|0137| |
| 164 | +||owner|root| |
| 165 | +||group|shadow\|root| |
| 166 | +|Ensure permissions on /etc/shells are configured|mask|0133| |
| 167 | +||owner|root| |
| 168 | +||group|root| |
| 169 | +|Ensure permissions on /etc/security/opasswd are configured|mask|0177| |
| 170 | +||owner|root| |
| 171 | +||group|root| |
0 commit comments