The Manager Appliance requires additional configuration after installation to comply with the US DoD DISA STIGs and SRGs. The following tasks should be performed in the Manager shell immediately after installation to configure the Linux based Manager in accordance with the DoDIN APL tested configurations:
Note
The SUT uses Security-Enhanced Linux (SELinux) which must be approved by the local authorizing official. In Red HAT Linux STIG version 2, release 8 the language requiring the AO approval for the use of Security-Enhanced Linux (SELinux) has been removed. The site is no longer required to obtain AO approval for using Security-Enhanced Linux (SELinux) instead of HIPS.
Configure the system to encrypt the boot password for root (RHEL-07-010480)
- Log in to the Manager shell.
- Enter the private mode.
Note
Trellix recommends you to contact Support if you are required to access the private mode in the Linux based Manager.
- Generate an encrypted grub2 password for root with the following command:
# grub2-mkpasswd-pbkdf2 Enter Password: Reenter Password:Make a note of the hash from the grub2-mkpasswd-pbkdf2 command.
- Edit
/etc/grub.d/40_custom and add the following lines below the comments:
# vi /etc/grub.d/40_custom set superusers="root" password_pbkdf2 root {hash from grub2-mkpasswd-pbkdf2 command} - Generate a new
grub.conf file with the new password with the following commands:
# grub2-mkconfig --output=/tmp/grub2.cfg # mv /tmp/grub2.cfg /boot/grub2/grub.cfg
Removal of FTP user account
- Log in to the Manager shell.
- Enter the private mode.
Note
Trellix recommends you to contact Support if you are required to access the private mode in the Linux based Manager.
- Execute
id ftp command.
uid=14(ftp) gid=50(ftp) groups=50(ftp) is displayed.
- To delete the FTP user account, execute userdel ftp command.
- To confirm, execute
id ftp command.
id: ftp: no such user is displayed.
Steps to make the DNS network configuration immutable
- Log in to the Manager shell.
- Enter the private mode.
Note
Trellix recommends you to contact Support if you are required to access the private mode in the Linux based Manager.
- Execute
chattr +i -V /etc/resolv.conf command. The following is displayed:
chattr 1.42.9 (28-Dec-2013)
Flags of /etc/resolv.conf set as ----i--------e--
Configure Network Time Protocol (NTP) service
To configure the Network time Protocol (NTP) service in the Manager, do the following:
- Log in to the Manager shell.
Note
For Manager shell, the default user name is admin and password is MLOSnsmApp.
- Stop the Network time Protocol (NTP) service using the ntp stop command.
- Configure the Network time Protocol (NTP) servers using the
set network ntp <NTP server Domain Name/IP Address> command.
Note
The maximum number of NTP servers configured in the Linux based Manager is 10.
Note
You can configure the NTP servers for the Linux based Manager simultaneously using the set network ntp command. Make sure the IP Addresses configured simultaneously are separated by a single space.
- Start the Network time Protocol (NTP) service using the ntp start command.
- Execute
edit ntp.conf file to add or update as follows:
server 0.rhel.pool.ntp.org iburst maxpoll 10 - Restart the Network time Protocol (NTP) service using the ntp stop and ntp start commands.
Configure Syslog for the Linux based Manager
To configure the Linux based Manager operating system for forwarding the rsyslog output to an aggregation server (RHEL-07-031000), do the following:
- Log in to the Manager shell.
- Execute the edit rsyslog.conf command to open the rsyslog.conf file in the vi editor.
- Configure the Manager to send all rsyslog output to an aggregation server using the following command block in the
rsyslog.conf file:
*.* @@<remote-host-IP>:514 - Save the changes.
Configure audit control to shutdown the Manager on audit processing failure
To configure audit control to shutdown the Manager on audit processing failure, do the following:
- Log in to the Manager shell.
- Execute the edit audit.rules command.
- Add or modify the below command block:
-f <1|2>Note
- -f 1: The system is configured to only send information to the kernel log regarding the failure.
- -f 2: The system is configured to shut down in the event of an auditing failure.
- Save the changes.
Configure audit partition free space threshold
Configure the operating system to initiate an action to notify the SA and ISSO (at a minimum), when allocated audit record storage volume reaches 75 percent of the repository maximum audit record storage capacity.
- Determine the size of the
/var/log/audit/ partition using the following:
# df -h /var/log/audit/ - Set the value of the space_left keyword in /etc/audit/auditd.conf to 75 percent of the partition size.
Configure audit processing alert email
The SA and ISSO (at a minimum) should be notified when the threshold for the repository maximum audit record storage capacity is reached. To configure the Linux based Manager operating system to send the notification, do the following:
- Log in to the Manager shell.
- Execute the edit auditd.conf command.
- Uncomment the following command block:
space_left_action - Edit the above command block as seen below:
space_left_action = email - Save the changes.
Configure PAM post-login configuration
To configure PAM post-login configuration in the Linux based Manager, do the following:
- Log in to the Manager shell.
- Execute
edit postlogin file to add the following command block in the beginning:
session required pam_lastlog.so showfailed - Save the changes.
Configure audisp-remote
The operating system should be configured to encrypt the transfer of off-loaded audit records onto a different system or media from the system being audited. Perform the following to configure audisp-remote:
- Log in to the Manager shell.
-
Set the remote server option in audisp-remote.conf with the IP address of the log aggregation server.
remote_server = <x.x.x.x> - Execute
audisp-remote.conf file to uncomment the following:
enable_krb5 = yesdisk_full_action = syslog | Single | haltnetwork_failure_action = syslog | Single | halt - Save the changes.