<?xml version='1.0' encoding='utf-8'?>
<oval-def:oval_definitions xmlns:ind="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent" xmlns:linux="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:unix="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd  http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd  http://oval.mitre.org/XMLSchema/oval-definitions-5#independent independent-definitions-schema.xsd  http://oval.mitre.org/XMLSchema/oval-definitions-5#unix unix-definitions-schema.xsd  http://oval.mitre.org/XMLSchema/oval-definitions-5#linux linux-definitions-schema.xsd">
  <oval-def:generator>
    <oval:product_name>OVALFileLinker from SCAP Security Guide</oval:product_name>
    <oval:product_version>ssg: [0, 1, 81], python: 3.14.3</oval:product_version>
    <oval:schema_version>5.11.2</oval:schema_version>
    <oval:timestamp>2026-04-01T21:16:40</oval:timestamp>
  </oval-def:generator>
  <oval-def:definitions>
    <oval-def:definition id="oval:ssg-auditd_audispd_configure_remote_server:def:1" version="1" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Configure audispd Plugin To Send Logs To Remote Server</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="auditd_audispd_configure_remote_server" source="ssg" />
        <oval-def:description>remote_server setting in /etc/audit/audisp-remote.conf is set to a certain IP address or hostname</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="AND">
        <oval-def:criterion comment="remote_server setting in audisp-remote.conf" test_ref="oval:ssg-test_auditd_audispd_configure_remote_server:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-auditd_data_disk_full_action:def:1" version="1" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Configure auditd Disk Full Action when Disk Space Is Full</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="auditd_data_disk_full_action" source="ssg" />
        <oval-def:description>disk_full_action setting in /etc/audit/auditd.conf is set to a certain action</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="AND">
        <oval-def:criterion comment="disk_full_action setting in auditd.conf" test_ref="oval:ssg-test_auditd_data_disk_full_action:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-auditd_data_retention_action_mail_acct:def:1" version="2" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Configure auditd mail_acct Action on Low Disk Space</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="auditd_data_retention_action_mail_acct" source="ssg" />
        <oval-def:description>action_mail_acct setting in /etc/audit/auditd.conf is set to a certain account</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="AND">
        <oval-def:criterion comment="action_mail_acct setting in auditd.conf" test_ref="oval:ssg-test_auditd_data_retention_action_mail_acct:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-auditd_data_retention_space_left_action:def:1" version="3" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Configure auditd space_left Action on Low Disk Space</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="auditd_data_retention_space_left_action" source="ssg" />
        <oval-def:description>space_left_action setting in /etc/audit/auditd.conf is set to a certain action</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="AND">
        <oval-def:criterion comment="space_left_action setting in auditd.conf" test_ref="oval:ssg-test_auditd_data_retention_space_left_action:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-auditd_data_retention_space_left_percentage:def:1" version="2" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Configure auditd space_left on Low Disk Space</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="auditd_data_retention_space_left_percentage" source="ssg" />
        <oval-def:description>space_left setting in /etc/audit/auditd.conf is set to at least a certain value</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="AND">
        <oval-def:criterion comment="space_left setting in auditd.conf" test_ref="oval:ssg-test_auditd_data_retention_space_left_percentage:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-auditd_offload_logs:def:1" version="1" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Offload audit Logs to External Media</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="auditd_offload_logs" source="ssg" />
        <oval-def:description>Check if a script for audit offload exists in /etc/cron.weekly/</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="AND">
        <oval-def:criterion comment="audit offload script" test_ref="oval:ssg-test_etc_cron_weekly_audit_offload_exists:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-apt_conf_disallow_unauthenticated:def:1" version="1" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Disable unauthenticated repositories in APT configuration</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="apt_conf_disallow_unauthenticated" source="ssg" />
        <oval-def:description>Accessing a repository should be allowed only when the repository is authenticated.</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria comment="Check if allow-unauthenticated is set to false or is undefined" operator="AND">
        <oval-def:criterion comment="Check if allow-unauthenticated is set to false or is undefined" test_ref="oval:ssg-test_apt_conf_disallow_unauthenticated:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-chronyd_or_ntpd_set_maxpoll:def:1" version="1" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Configure Time Service Maxpoll Interval</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="chronyd_or_ntpd_set_maxpoll" source="ssg" />
        <oval-def:description>Configure the maxpoll setting in /etc/ntp.conf or chrony.conf
      to continuously poll the time source servers.</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="OR">
        <oval-def:criteria operator="AND">
          <oval-def:criterion comment="check if maxpoll is set in /etc/ntp.conf" test_ref="oval:ssg-test_ntp_set_maxpoll:tst:1" />
          <oval-def:criterion comment="check if all server entries have maxpoll set in /etc/ntp.conf" test_ref="oval:ssg-test_ntp_all_server_has_maxpoll:tst:1" />
        </oval-def:criteria>
        <oval-def:criteria operator="AND">
          <oval-def:criterion comment="check if maxpoll is set in /etc/chrony/chrony.conf or /etc/chrony/conf.d/" test_ref="oval:ssg-test_chrony_set_maxpoll:tst:1" />
          <oval-def:criterion comment="check if all server entries have maxpoll set in /etc/chrony/chrony.conf or /etc/chrony/conf.d/" test_ref="oval:ssg-test_chrony_all_server_has_maxpoll:tst:1" />
        </oval-def:criteria>
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-sssd_certification_path_trust_anchor:def:1" version="1" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Certificate trust path in SSSD</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="sssd_certification_path_trust_anchor" source="ssg" />
        <oval-def:description>SSSD should be configured with trust path to an accepted trust anchor.</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="AND">
        <oval-def:criterion comment="check value of certificate_verification in sssd configuration" test_ref="oval:ssg-test_sssd_certification_path_trust_anchor:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-sssd_enable_pam_services:def:1" version="1" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Configure PAM in SSSD Services</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="sssd_enable_pam_services" source="ssg" />
        <oval-def:description>SSSD should be configured to run SSSD PAM services.
      </oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="AND">
        <oval-def:criterion comment="check if pam is configured in the services setting of the sssd section" test_ref="oval:ssg-test_sssd_enable_pam_services:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-sssd_enable_smartcards:def:1" version="1" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Enable Smartcards in SSSD</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="sssd_enable_smartcards" source="ssg" />
        <oval-def:description>SSSD should be configured to authenticate access to the system
    using smart cards.</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="AND">
        <oval-def:criterion comment="Check pam_cert_auth in /etc/sssd/sssd.conf" test_ref="oval:ssg-test_sssd_enable_smartcards:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-sssd_enable_user_cert:def:1" version="1" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Enable Certificates Mapping in SSSD</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="sssd_enable_user_cert" source="ssg" />
        <oval-def:description>SSSD should be configured to map the certificate to
            correct user or group</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="AND">
        <oval-def:criterion comment="check value of ldap_user_certificate in sssd configuration" test_ref="oval:ssg-test_sssd_enable_user_cert:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-sssd_offline_cred_expiration:def:1" version="1" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Configure SSSD to Expire Offline Credentials</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="sssd_offline_cred_expiration" source="ssg" />
        <oval-def:description>SSSD should be configured to expire offline credentials after 1 day.</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="OR">
        <oval-def:criterion comment="Check offline_credentials_expiration in /etc/sssd/sssd.conf" test_ref="oval:ssg-test_sssd_offline_cred_expiration:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-enable_authselect:def:1" version="1" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Enable authselect</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="enable_authselect" source="ssg" />
        <oval-def:description>Check that authselect is enabled</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria comment="Check that authselect symlinks are set up properly." operator="AND">
        <oval-def:criterion comment="The 'fingerprint-auth' PAM config is a symlink to its authselect counterpart" test_ref="oval:ssg-test_pam_fingerprint_symlinked_to_authselect:tst:1" />
        <oval-def:criterion comment="The 'password-auth' PAM config is a symlink to its authselect counterpart" test_ref="oval:ssg-test_pam_password_symlinked_to_authselect:tst:1" />
        <oval-def:criterion comment="The 'postlogin' PAM config is a symlink to its authselect counterpart" test_ref="oval:ssg-test_pam_postlogin_symlinked_to_authselect:tst:1" />
        <oval-def:criterion comment="The 'smartcard-auth' PAM config is a symlink to its authselect counterpart" test_ref="oval:ssg-test_pam_smartcard_symlinked_to_authselect:tst:1" />
        <oval-def:criterion comment="The 'system-auth' PAM config is a symlink to its authselect counterpart" test_ref="oval:ssg-test_pam_system_symlinked_to_authselect:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-banner_etc_issue_net:def:1" version="2" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Modify the System Login Banner for Remote Connections</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="banner_etc_issue_net" source="ssg" />
        <oval-def:description>The system login banner text should be set correctly.</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="AND">
        <oval-def:criterion comment="/etc/issue.net is set appropriately" test_ref="oval:ssg-test_banner_etc_issue_net:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-accounts_passwords_pam_faillock_audit:def:1" version="5" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Account Lockouts Must Be Logged</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="accounts_passwords_pam_faillock_audit" source="ssg" />
        <oval-def:description>Account Lockouts Must Be Logged</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria comment="Check expected value for pam_faillock.so audit parameter" operator="OR">
        <oval-def:criteria comment="Check expected pam_faillock.so audit parameter in pam files" operator="AND">
          <oval-def:criterion comment="Check the audit parameter in auth section of system-auth file" test_ref="oval:ssg-test_pam_faillock_audit_parameter_system_auth:tst:1" />
          <oval-def:criterion comment="Check the audit parameter in auth section of password-auth file" test_ref="oval:ssg-test_pam_faillock_audit_parameter_password_auth:tst:1" />
          <oval-def:criterion comment="Ensure /etc/security/faillock.conf is not used together with pam files" test_ref="oval:ssg-test_pam_faillock_audit_parameter_no_faillock_conf:tst:1" />
        </oval-def:criteria>
        <oval-def:criteria comment="Check expected pam_faillock.so audit parameter in faillock.conf" operator="AND">
          <oval-def:criterion comment="Check the audit parameter is not present system-auth file" test_ref="oval:ssg-test_pam_faillock_audit_parameter_no_pamd_system:tst:1" />
          <oval-def:criterion comment="Check the audit parameter is not present password-auth file" test_ref="oval:ssg-test_pam_faillock_audit_parameter_no_pamd_password:tst:1" />
          <oval-def:criterion comment="Ensure the audit parameter is present in /etc/security/faillock.conf" test_ref="oval:ssg-test_pam_faillock_audit_parameter_faillock_conf:tst:1" />
        </oval-def:criteria>
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-accounts_passwords_pam_faillock_silent:def:1" version="5" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Do Not Show System Messages When Unsuccessful Logon Attempts Occur</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="accounts_passwords_pam_faillock_silent" source="ssg" />
        <oval-def:description>Prevent System Messages When Three Unsuccessful Logon Attempts Occur</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria comment="Check expected value for pam_faillock.so silent parameter" operator="OR">
        <oval-def:criteria comment="Check expected pam_faillock.so silent parameter in pam files" operator="AND">
          <oval-def:criterion comment="Check the silent parameter in auth section of system-auth file" test_ref="oval:ssg-test_pam_faillock_silent_parameter_system_auth:tst:1" />
          <oval-def:criterion comment="Check the silent parameter in auth section of password-auth file" test_ref="oval:ssg-test_pam_faillock_silent_parameter_password_auth:tst:1" />
          <oval-def:criterion comment="Ensure /etc/security/faillock.conf is not used together with pam files" test_ref="oval:ssg-test_pam_faillock_silent_parameter_no_faillock_conf:tst:1" />
        </oval-def:criteria>
        <oval-def:criteria comment="Check expected pam_faillock.so silent parameter in faillock.conf" operator="AND">
          <oval-def:criterion comment="Check the silent parameter is not present system-auth file" test_ref="oval:ssg-test_pam_faillock_silent_parameter_no_pamd_system:tst:1" />
          <oval-def:criterion comment="Check the silent parameter is not present password-auth file" test_ref="oval:ssg-test_pam_faillock_silent_parameter_no_pamd_password:tst:1" />
          <oval-def:criterion comment="Ensure the silent parameter is present in /etc/security/faillock.conf" test_ref="oval:ssg-test_pam_faillock_silent_parameter_faillock_conf:tst:1" />
        </oval-def:criteria>
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-accounts_password_pam_retry:def:1" version="2" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Ensure PAM Enforces Password Requirements - Authentication Retry Prompts Permitted Per-Session</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="accounts_password_pam_retry" source="ssg" />
        <oval-def:description>The password retry should meet minimum requirements</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria comment="The password retry should meet minimum requirements" operator="AND">
        <oval-def:extend_definition definition_ref="oval:ssg-enable_authselect:def:1" />
        <oval-def:criteria comment="Conditions for retry are satisfied" operator="OR">
          <oval-def:criteria comment="Conditions for retry in PAM files are satisfied" operator="AND">
            <oval-def:criterion comment="pam_pwquality has correctly set the retry argument in  system-auth" test_ref="oval:ssg-test_password_pam_pwquality_retry_system_auth:tst:1" />
          </oval-def:criteria>
          <oval-def:criteria comment="Conditions for retry in /etc/security/pwquality.conf file are satisfied" operator="AND">
            <oval-def:criterion comment="retry value not set in PAM files" test_ref="oval:ssg-test_password_pam_pwquality_retry_system_auth_not_set:tst:1" />
            <oval-def:criterion comment="check retry parameter in /etc/security/pwquality.conf" test_ref="oval:ssg-test_password_pam_pwquality_retry_pwquality_conf:tst:1" />
          </oval-def:criteria>
        </oval-def:criteria>
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-set_password_hashing_algorithm_auth_stig:def:1" version="2" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Set Password Hashing Algorithm for PAM</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="set_password_hashing_algorithm_auth_stig" source="ssg" />
        <oval-def:description>The password hashing algorithm should be set correctly in {{{ pam_file }}}.</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="AND">
        <oval-def:criterion test_ref="oval:ssg-test_pam_unix_hashing_algorithm_commonauth:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-set_password_hashing_algorithm_logindefs:def:1" version="2" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Set Password Hashing Algorithm in /etc/login.defs</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="set_password_hashing_algorithm_logindefs" source="ssg" />
        <oval-def:description>The password hashing algorithm should be set correctly in /usr/etc/login.defs.</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="AND">
        <oval-def:criterion test_ref="oval:ssg-test_set_password_hashing_algorithm_logindefs:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-disable_ctrlaltdel_reboot:def:1" version="1" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Disable Ctrl-Alt-Del Reboot Activation</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="disable_ctrlaltdel_reboot" source="ssg" />
        <oval-def:description>By default, the system will reboot when the
      Ctrl-Alt-Del key sequence is pressed.</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="AND">
        <oval-def:criterion comment="Disable Ctrl-Alt-Del systemd softlink exists" test_ref="oval:ssg-test_disable_ctrlaltdel_exists:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-account_disable_post_pw_expiration:def:1" version="2" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Set Account Expiration Following Inactivity</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="account_disable_post_pw_expiration" source="ssg" />
        <oval-def:description>The accounts should be configured to expire automatically following password expiration.</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria comment="the value INACTIVE parameter should be set appropriately in /etc/default/useradd" operator="AND">
        <oval-def:criterion test_ref="oval:ssg-test_etc_default_useradd_inactive:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-accounts_maximum_age_login_defs:def:1" version="3" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Set Password Maximum Age</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="accounts_maximum_age_login_defs" source="ssg" />
        <oval-def:description>The maximum password age policy should meet minimum requirements.</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria comment="The value PASS_MAX_DAYS should be set appropriately in /etc/login.defs" operator="AND">
        <oval-def:criterion test_ref="oval:ssg-test_pass_max_days:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-accounts_minimum_age_login_defs:def:1" version="3" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Set Password Minimum Age</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="accounts_minimum_age_login_defs" source="ssg" />
        <oval-def:description>The minimum password age policy should be set appropriately.</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria comment="The value of PASS_MIN_DAYS should be set appropriately in /etc/login.defs" operator="AND">
        <oval-def:criterion test_ref="oval:ssg-test_pass_min_days:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-accounts_password_pam_unix_rounds_password_auth:def:1" version="1" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Set number of Password Hashing Rounds - password-auth</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="accounts_password_pam_unix_rounds_password_auth" source="ssg" />
        <oval-def:description>The number of rounds for password hashing should be set correctly.</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria comment="Check if rounds option of pam_unix is as expected" operator="OR">
        <oval-def:criterion comment="The value of rounds is set correctly in pam_unix.so" test_ref="oval:ssg-test_password_auth_pam_unix_rounds_is_set:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-no_empty_passwords:def:1" version="1" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Prevent Login to Accounts With Empty Password</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="no_empty_passwords" source="ssg" />
        <oval-def:description>The file /etc/pam.d/system-auth should not contain the nullok option</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="AND">
        <oval-def:criterion comment="make sure the nullok option is not used in /etc/pam.d/system-auth" test_ref="oval:ssg-test_no_empty_passwords:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-no_empty_passwords_etc_shadow:def:1" version="1" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Ensure There Are No Accounts With Blank or Null Passwords</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="no_empty_passwords_etc_shadow" source="ssg" />
        <oval-def:description>The file /etc/shadow shows that there aren't empty passwords</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="AND">
        <oval-def:criterion comment="make sure there aren't blank or null passwords in /etc/shadow" test_ref="oval:ssg-test_no_empty_passwords_etc_shadow:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-prevent_direct_root_logins:def:1" version="1" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Direct root Logins Are Not Allowed</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="prevent_direct_root_logins" source="ssg" />
        <oval-def:description>Direct root Logins Are Not Allowed</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="AND">
        <oval-def:criterion comment="verify root account is locked" test_ref="oval:ssg-test_root_access_locked_etc_shadow:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-accounts_max_concurrent_login_sessions:def:1" version="1" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Limit the Number of Concurrent Login Sessions Allowed Per User</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="accounts_max_concurrent_login_sessions" source="ssg" />
        <oval-def:description>The maximum number of concurrent login sessions per user should meet
      minimum requirements.</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="OR">
        <oval-def:criterion comment="the value maxlogins should be set appropriately in /etc/security/limits.d/*.conf" test_ref="oval:ssg-test_limitsd_maxlogins:tst:1" />
        <oval-def:criteria operator="AND">
          <oval-def:criterion negate="true" comment="the value maxlogins should not be set at all in /etc/security/limits.d/*.conf" test_ref="oval:ssg-test_limitsd_maxlogins_exists:tst:1" />
          <oval-def:criterion comment="the value maxlogins should be set appropriately in /etc/security/limits.conf" test_ref="oval:ssg-test_maxlogins:tst:1" />
        </oval-def:criteria>
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-accounts_tmout:def:1" version="4" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Set Interactive Session Timeout</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="accounts_tmout" source="ssg" />
        <oval-def:description>Checks interactive shell timeout</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="AND">
        <oval-def:criterion comment="TMOUT value in /etc/profile &lt;= var_accounts_tmout" test_ref="oval:ssg-test_etc_profile_tmout:tst:1" />
        <oval-def:criterion comment="TMOUT value in /etc/profile.d/*.sh &lt;= var_accounts_tmout" test_ref="oval:ssg-test_etc_profiled_tmout:tst:1" />
        <oval-def:criterion comment="At least one config file has TMOUT defined" test_ref="oval:ssg-test_accounts_tmout_defined:tst:1" />
        <oval-def:criterion comment="All configured TMOUT values must be &gt;= 1" test_ref="oval:ssg-test_accounts_tmout_lower_bound:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-grub2_password:def:1" version="1" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Set Boot Loader Password in grub2</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="grub2_password" source="ssg" />
        <oval-def:description>The grub2 boot loader should have password protection enabled.</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="OR">
        <oval-def:criteria operator="AND">
          <oval-def:criteria comment="check both files to account for procedure change in documentation" operator="OR">
            <oval-def:criterion comment="make sure a password is defined in /boot/grub/user.cfg" test_ref="oval:ssg-test_grub2_password_usercfg:tst:1" />
            <oval-def:criterion comment="make sure a password is defined in /boot/grub/grub.cfg" test_ref="oval:ssg-test_grub2_password_grubcfg:tst:1" />
          </oval-def:criteria>
          <oval-def:criterion comment="make sure a superuser is defined in /boot/grub/grub.cfg" test_ref="oval:ssg-test_bootloader_superuser:tst:1" />
        </oval-def:criteria>
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-grub2_uefi_password:def:1" version="1" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Set the UEFI Boot Loader Password</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="grub2_uefi_password" source="ssg" />
        <oval-def:description>The UEFI grub2 boot loader should have password protection enabled.</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="OR">
        <oval-def:criterion comment="make sure a password is defined in /boot/efi/EFI/ubuntu/user.cfg" test_ref="oval:ssg-test_grub2_uefi_password_usercfg:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-ensure_rtc_utc_configuration:def:1" version="1" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Ensure real-time clock is set to UTC</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="ensure_rtc_utc_configuration" source="ssg" />
        <oval-def:description>Ensure RTC is using UTC as its time base</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="AND">
        <oval-def:criterion comment="Check softlink exists for /etc/localtime and look for UTC pattern" test_ref="oval:ssg-test_ensure_rtc_utc_configuration:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-rsyslog_remote_access_monitoring:def:1" version="1" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Ensure remote access methods are monitored in Rsyslog</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="rsyslog_remote_access_monitoring" source="ssg" />
        <oval-def:description>Rsyslog should be configured to monitor remote access methods.</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria comment="remote access methods are configured in rsyslog" operator="AND">
        <oval-def:criterion comment="ensure 'auth.*' remote method is configured in rsyslog" test_ref="oval:ssg-test_remote_method_monitoring_auth:tst:1" />
        <oval-def:criterion comment="ensure 'authpriv.*' remote method is configured in rsyslog" test_ref="oval:ssg-test_remote_method_monitoring_authpriv:tst:1" />
        <oval-def:criterion comment="ensure 'daemon.*' remote method is configured in rsyslog" test_ref="oval:ssg-test_remote_method_monitoring_daemon:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-wireless_disable_interfaces:def:1" version="1" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Deactivate Wireless Network Interfaces</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="wireless_disable_interfaces" source="ssg" />
        <oval-def:description>All wireless interfaces should be disabled.</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="AND">
        <oval-def:criterion negate="true" comment="check if wifi interfaces are disabled" test_ref="oval:ssg-test_wireless_disable_interfaces:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-dir_perms_world_writable_sticky_bits:def:1" version="2" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Verify that All World-Writable Directories Have Sticky Bits Set</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="dir_perms_world_writable_sticky_bits" source="ssg" />
        <oval-def:description>The sticky bit should be set for all world-writable directories.</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="AND">
        <oval-def:criterion comment="All local world-writable directories have sticky bit set" test_ref="oval:ssg-test_dir_perms_world_writable_sticky_bits:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-file_groupownership_system_commands_dirs:def:1" version="1" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Verify that system commands files are group owned by root or a system account</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="file_groupownership_system_commands_dirs" source="ssg" />
        <oval-def:description>
        Checks that system commands in /bin /sbin /usr/bin /usr/sbin /usr/local/bin /usr/local/sbin 
        are owned by root group or a system account.
      </oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="AND">
        <oval-def:criterion test_ref="oval:ssg-test_groupownership_system_commands_dirs:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-file_ownership_binary_dirs:def:1" version="2" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Verify that System Executables Have Root Ownership</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="file_ownership_binary_dirs" source="ssg" />
        <oval-def:description>
        Checks that /bin, /sbin, /usr/bin, /usr/sbin, /usr/local/bin,
        /usr/local/sbin, /usr/libexec, and objects therein, are owned by root.
      </oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="AND">
        <oval-def:criterion test_ref="oval:ssg-test_ownership_binary_directories:tst:1" />
        <oval-def:criterion test_ref="oval:ssg-test_ownership_binary_files:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-file_permissions_binary_dirs:def:1" version="2" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Verify that System Executables Have Restrictive Permissions</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="file_permissions_binary_dirs" source="ssg" />
        <oval-def:description>
        Checks that binary files under /bin, /sbin, /usr/bin, /usr/sbin,
        /usr/local/bin, /usr/local/sbin, and /usr/libexec are not group-writable or world-writable.
      </oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="AND">
        <oval-def:criterion test_ref="oval:ssg-test_perms_binary_files:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-bios_enable_execution_restrictions:def:1" version="2" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Enable NX or XD Support in the BIOS</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="bios_enable_execution_restrictions" source="ssg" />
        <oval-def:description>The NX (no-execution) bit flag should be set on the system.</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="AND">
        <oval-def:criterion comment="NX bit is set" test_ref="oval:ssg-test_NX_cpu_support:tst:1" />
        <oval-def:criterion comment="NX is not disabled in the kernel command line" test_ref="oval:ssg-test_noexec_cmd_line:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-is_fips_mode_enabled:def:1" version="1" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Verify '/proc/sys/crypto/fips_enabled' exists</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="is_fips_mode_enabled" source="ssg" />
        <oval-def:description>Inspect the contents of /proc/sys/crypto/fips_enabled</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="AND">
        <oval-def:criterion comment="Check contents of file" test_ref="oval:ssg-is_fips_mode_enabled_test_whole_file_contents_fips_equal_to_one:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-sudo_remove_no_authenticate:def:1" version="1" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Ensure Users Re-Authenticate for Privilege Escalation - sudo !authenticate</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="sudo_remove_no_authenticate" source="ssg" />
        <oval-def:description>Checks sudo usage without authentication</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="AND">
        <oval-def:criterion comment="!authenticate does not exist in /etc/sudoers" test_ref="oval:ssg-test_no_authenticate_etc_sudoers:tst:1" />
        <oval-def:criterion comment="!authenticate does not exist in /etc/sudoers.d" test_ref="oval:ssg-test_no_authenticate_etc_sudoers_d:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-sudo_remove_nopasswd:def:1" version="1" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Ensure Users Re-Authenticate for Privilege Escalation - sudo NOPASSWD</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="sudo_remove_nopasswd" source="ssg" />
        <oval-def:description>Checks sudo usage without password</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="AND">
        <oval-def:criterion comment="NOPASSWD is not configured in /etc/sudoers" test_ref="oval:ssg-test_nopasswd_etc_sudoers:tst:1" />
        <oval-def:criterion comment="NOPASSWD is not configured in /etc/sudoers.d" test_ref="oval:ssg-test_nopasswd_etc_sudoers_d:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-sudo_restrict_privilege_elevation_to_authorized:def:1" version="1" class="compliance">
      <oval-def:metadata>
        <oval-def:title>The operating system must restrict privilege elevation to authorized personnel</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="sudo_restrict_privilege_elevation_to_authorized" source="ssg" />
        <oval-def:description>Check that sudoers doesn't allow all users to run commands via sudo</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="AND">
        <oval-def:criterion comment="Make sure that sudoers has restrictions on which users can run sudo for any target user" test_ref="oval:ssg-test_not_all_users_can_sudo_to_users:tst:1" />
        <oval-def:criterion comment="Make sure that sudoers has restrictions on which users can run sudo for any target group" test_ref="oval:ssg-test_not_all_users_can_sudo_to_group:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-clean_components_post_updating:def:1" version="1" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Ensure apt_get Removes Previous Package Versions</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="clean_components_post_updating" source="ssg" />
        <oval-def:description>The clean_requirements_on_remove option should be used to ensure that old
      versions of software components are removed after updating.</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="AND">
        <oval-def:criterion comment="check value of clean_requirements_on_remove in /etc/apt/apt.conf" test_ref="oval:ssg-test_yum_clean_components_post_updating:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-accounts_password_pam_enforcing:def:1" version="1" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Ensure PAM Enforces Password Requirements - Enforcing</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="accounts_password_pam_enforcing" source="ssg" />
        <oval-def:description>Check presence of enforcing = 1 in /etc/security/pwquality.conf</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria comment="Test conditions - presence of the file plus 0 extra definitions." operator="AND">
        <oval-def:criterion comment="Check that /etc/security/pwquality.conf contains a line with certain text" test_ref="oval:ssg-test_accounts_password_pam_enforcing:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-accounts_passwords_pam_faildelay_delay:def:1" version="3" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Enforce Delay After Failed Logon Attempts</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="accounts_passwords_pam_faildelay_delay" source="ssg" />
        <oval-def:description>Configure PAM module</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria comment="Make sure arguments are properly configured in /etc/pam.d/common-auth" operator="AND">
        <oval-def:criterion comment="Verify delay is set to the desired state" test_ref="oval:ssg-test_pam_auth_pam_faildelay_delay:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-accounts_passwords_pam_faillock_deny:def:1" version="6" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Lock Accounts After Failed Password Attempts</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="accounts_passwords_pam_faillock_deny" source="ssg" />
        <oval-def:description>Lockout account after failed login attempts.</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria comment="Check the proper configuration of pam_faillock.so" operator="AND">
        <oval-def:criteria comment="Check if pam_faillock.so is properly enabled" operator="AND">
          <oval-def:criteria comment="Count occurrences of pam_unix.so in system-auth and password-auth" operator="AND">
            <oval-def:criterion comment="pam_unix.so appears only once in auth section of system-auth" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_deny_system_pam_unix_auth:tst:1" />
            <oval-def:criterion comment="pam_unix.so appears only once in auth section of password-auth" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_deny_password_pam_unix_auth:tst:1" />
          </oval-def:criteria>
          <oval-def:criteria comment="Check common definition of pam_faillock.so" operator="AND">
            <oval-def:criterion comment="pam_faillock.so is properly defined in auth section of system-auth" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_deny_system_pam_faillock_auth:tst:1" />
            <oval-def:criterion comment="pam_faillock.so is properly defined in account section of system-auth" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_deny_system_pam_faillock_account:tst:1" />
            <oval-def:criterion comment="pam_faillock.so is properly defined in auth section of password-auth" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_deny_password_pam_faillock_auth:tst:1" />
            <oval-def:criterion comment="pam_faillock.so is properly defined in account section of password-auth" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_deny_password_pam_faillock_account:tst:1" />
          </oval-def:criteria>
        </oval-def:criteria>
        <oval-def:criteria comment="Check expected value for pam_faillock.so deny parameter" operator="OR">
          <oval-def:criteria comment="Check expected pam_faillock.so deny parameter in pam files" operator="AND">
            <oval-def:criterion comment="Check the deny parameter in auth section of system-auth file" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_deny_parameter_pamd_system:tst:1" />
            <oval-def:criterion comment="Check the deny parameter in auth section of password-auth file" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_deny_parameter_pamd_password:tst:1" />
            <oval-def:criterion comment="Ensure the deny parameter is not present in /etc/security/faillock.conf" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_deny_parameter_no_faillock_conf:tst:1" />
          </oval-def:criteria>
          <oval-def:criteria comment="Check expected pam_faillock.so deny parameter in /etc/security/faillock.conf" operator="AND">
            <oval-def:criterion comment="Check the deny parameter is not present system-auth file" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_deny_parameter_no_pamd_system:tst:1" />
            <oval-def:criterion comment="Check the deny parameter is not present password-auth file" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_deny_parameter_no_pamd_password:tst:1" />
            <oval-def:criterion comment="Ensure the deny parameter is present in /etc/security/faillock.conf" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_deny_parameter_faillock_conf:tst:1" />
          </oval-def:criteria>
        </oval-def:criteria>
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-accounts_passwords_pam_faillock_interval:def:1" version="6" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Set Interval For Counting Failed Password Attempts</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="accounts_passwords_pam_faillock_interval" source="ssg" />
        <oval-def:description>The number of allowed failed logins should be set correctly.</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria comment="Check the proper configuration of pam_faillock.so" operator="AND">
        <oval-def:criteria comment="Check if pam_faillock.so is properly enabled" operator="AND">
          <oval-def:criteria comment="Count occurrences of pam_unix.so in system-auth and password-auth" operator="AND">
            <oval-def:criterion comment="pam_unix.so appears only once in auth section of system-auth" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_fail_interval_system_pam_unix_auth:tst:1" />
            <oval-def:criterion comment="pam_unix.so appears only once in auth section of password-auth" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_fail_interval_password_pam_unix_auth:tst:1" />
          </oval-def:criteria>
          <oval-def:criteria comment="Check common definition of pam_faillock.so" operator="AND">
            <oval-def:criterion comment="pam_faillock.so is properly defined in auth section of system-auth" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_fail_interval_system_pam_faillock_auth:tst:1" />
            <oval-def:criterion comment="pam_faillock.so is properly defined in account section of system-auth" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_fail_interval_system_pam_faillock_account:tst:1" />
            <oval-def:criterion comment="pam_faillock.so is properly defined in auth section of password-auth" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_fail_interval_password_pam_faillock_auth:tst:1" />
            <oval-def:criterion comment="pam_faillock.so is properly defined in account section of password-auth" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_fail_interval_password_pam_faillock_account:tst:1" />
          </oval-def:criteria>
        </oval-def:criteria>
        <oval-def:criteria comment="Check expected value for pam_faillock.so fail_interval parameter" operator="OR">
          <oval-def:criteria comment="Check expected pam_faillock.so fail_interval parameter in pam files" operator="AND">
            <oval-def:criterion comment="Check the fail_interval parameter in auth section of system-auth file" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_fail_interval_parameter_pamd_system:tst:1" />
            <oval-def:criterion comment="Check the fail_interval parameter in auth section of password-auth file" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_fail_interval_parameter_pamd_password:tst:1" />
            <oval-def:criterion comment="Ensure the fail_interval parameter is not present in /etc/security/faillock.conf" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_fail_interval_parameter_no_faillock_conf:tst:1" />
          </oval-def:criteria>
          <oval-def:criteria comment="Check expected pam_faillock.so fail_interval parameter in /etc/security/faillock.conf" operator="AND">
            <oval-def:criterion comment="Check the fail_interval parameter is not present system-auth file" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_fail_interval_parameter_no_pamd_system:tst:1" />
            <oval-def:criterion comment="Check the fail_interval parameter is not present password-auth file" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_fail_interval_parameter_no_pamd_password:tst:1" />
            <oval-def:criterion comment="Ensure the fail_interval parameter is present in /etc/security/faillock.conf" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_fail_interval_parameter_faillock_conf:tst:1" />
          </oval-def:criteria>
        </oval-def:criteria>
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-accounts_passwords_pam_faillock_unlock_time:def:1" version="6" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Set Lockout Time for Failed Password Attempts</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="accounts_passwords_pam_faillock_unlock_time" source="ssg" />
        <oval-def:description>The unlock time after number of failed logins should be set correctly.</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria comment="Check the proper configuration of pam_faillock.so" operator="AND">
        <oval-def:criteria comment="Check if pam_faillock.so is properly enabled" operator="AND">
          <oval-def:criteria comment="Count occurrences of pam_unix.so in system-auth and password-auth" operator="AND">
            <oval-def:criterion comment="pam_unix.so appears only once in auth section of system-auth" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_system_pam_unix_auth:tst:1" />
            <oval-def:criterion comment="pam_unix.so appears only once in auth section of password-auth" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_password_pam_unix_auth:tst:1" />
          </oval-def:criteria>
          <oval-def:criteria comment="Check common definition of pam_faillock.so" operator="AND">
            <oval-def:criterion comment="pam_faillock.so is properly defined in auth section of system-auth" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_system_pam_faillock_auth:tst:1" />
            <oval-def:criterion comment="pam_faillock.so is properly defined in account section of system-auth" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_system_pam_faillock_account:tst:1" />
            <oval-def:criterion comment="pam_faillock.so is properly defined in auth section of password-auth" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_password_pam_faillock_auth:tst:1" />
            <oval-def:criterion comment="pam_faillock.so is properly defined in account section of password-auth" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_password_pam_faillock_account:tst:1" />
          </oval-def:criteria>
        </oval-def:criteria>
        <oval-def:criteria comment="Check expected value for pam_faillock.so unlock_time parameter" operator="OR">
          <oval-def:criteria comment="Check expected pam_faillock.so unlock_time parameter in pam files" operator="AND">
            <oval-def:criterion comment="Check the unlock_time parameter in auth section of system-auth file" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_parameter_pamd_system:tst:1" />
            <oval-def:criterion comment="Check the unlock_time parameter in auth section of password-auth file" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_parameter_pamd_password:tst:1" />
            <oval-def:criterion comment="Ensure the unlock_time parameter is not present in /etc/security/faillock.conf" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_parameter_no_faillock_conf:tst:1" />
          </oval-def:criteria>
          <oval-def:criteria comment="Check expected pam_faillock.so unlock_time parameter in /etc/security/faillock.conf" operator="AND">
            <oval-def:criterion comment="Check the unlock_time parameter is not present system-auth file" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_parameter_no_pamd_system:tst:1" />
            <oval-def:criterion comment="Check the unlock_time parameter is not present password-auth file" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_parameter_no_pamd_password:tst:1" />
            <oval-def:criterion comment="Ensure the unlock_time parameter is present in /etc/security/faillock.conf" test_ref="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_parameter_faillock_conf:tst:1" />
          </oval-def:criteria>
        </oval-def:criteria>
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-aide_disable_silentreports:def:1" version="1" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Configure AIDE To Notify Personnel if Baseline Configurations Are Altered</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="aide_disable_silentreports" source="ssg" />
        <oval-def:description>Ensure 'SILENTREPORTS' is configured with value 'no' in /etc/default/aide</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria comment="The respective application or service is configured correctly and configuration file exists" operator="AND">
        <oval-def:criteria comment="The respective application or service is configured correctly" operator="OR">
          <oval-def:criterion comment="Check the SILENTREPORTS in /etc/default/aide" test_ref="oval:ssg-test_aide_disable_silentreports:tst:1" />
        </oval-def:criteria>
        <oval-def:criterion comment="test if configuration file /etc/default/aide exists for aide_disable_silentreports" test_ref="oval:ssg-test_aide_disable_silentreports_config_file_exists:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-apparmor_configured:def:1" version="1" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Ensure AppArmor is Active and Configured</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="apparmor_configured" source="ssg" />
        <oval-def:description>The apparmor service should be enabled if possible.</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria comment="package apparmor-parser installed and service apparmor is configured to start" operator="AND">
        <oval-def:criterion comment="apparmor-parser installed" test_ref="oval:ssg-test_service_apparmor_package_apparmor-parser_installed:tst:1" />
        <oval-def:criteria comment="service apparmor is configured to start and is running" operator="AND">
          <oval-def:criterion comment="apparmor is running" test_ref="oval:ssg-test_service_running_apparmor:tst:1" />
          <oval-def:criteria comment="service apparmor is configured to start" operator="OR">
            <oval-def:criterion comment="multi-user.target wants apparmor" test_ref="oval:ssg-test_multi_user_wants_apparmor:tst:1" />
            <oval-def:criterion comment="multi-user.target wants apparmor socket" test_ref="oval:ssg-test_multi_user_wants_apparmor_socket:tst:1" />
          </oval-def:criteria>
        </oval-def:criteria>
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-chronyd_sync_clock:def:1" version="1" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Synchronize internal information system clocks</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="chronyd_sync_clock" source="ssg" />
        <oval-def:description>Ensure 'makestep' is configured with value '1 -1' in /etc/chrony/chrony.conf</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria comment="The respective application or service is configured correctly and configuration file exists" operator="AND">
        <oval-def:criteria comment="The respective application or service is configured correctly" operator="OR">
          <oval-def:criterion comment="Check the makestep in /etc/chrony/chrony.conf" test_ref="oval:ssg-test_chronyd_sync_clock:tst:1" />
        </oval-def:criteria>
        <oval-def:criterion comment="test if configuration file /etc/chrony/chrony.conf exists for chronyd_sync_clock" test_ref="oval:ssg-test_chronyd_sync_clock_config_file_exists:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-dir_group_ownership_library_dirs:def:1" version="1" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Verify that Shared Library Directories Have Root Group Ownership</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="dir_group_ownership_library_dirs" source="ssg" />
        <oval-def:description>This test makes sure that /lib/, /lib64/, /usr/lib/, /usr/lib64/ is group owned by 0.</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="AND">
        <oval-def:criterion comment="Check file group ownership of /lib/" test_ref="oval:ssg-test_file_groupownerdir_group_ownership_library_dirs_0:tst:1" />
        <oval-def:criterion comment="Check file group ownership of /lib64/" test_ref="oval:ssg-test_file_groupownerdir_group_ownership_library_dirs_1:tst:1" />
        <oval-def:criterion comment="Check file group ownership of /usr/lib/" test_ref="oval:ssg-test_file_groupownerdir_group_ownership_library_dirs_2:tst:1" />
        <oval-def:criterion comment="Check file group ownership of /usr/lib64/" test_ref="oval:ssg-test_file_groupownerdir_group_ownership_library_dirs_3:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-dir_groupowner_system_journal:def:1" version="1" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Verify group-owner of system journal directories</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="dir_groupowner_system_journal" source="ssg" />
        <oval-def:description>This test makes sure that /run/log/journal/, /var/log/journal/ is group owned by systemd-journal.</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="AND">
        <oval-def:criterion comment="Check file group ownership of /run/log/journal/" test_ref="oval:ssg-test_file_groupownerdir_groupowner_system_journal_0:tst:1" />
        <oval-def:criterion comment="Check file group ownership of /var/log/journal/" test_ref="oval:ssg-test_file_groupownerdir_groupowner_system_journal_1:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-dir_groupownership_binary_dirs:def:1" version="1" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Verify that system commands directories are group owned by root</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="dir_groupownership_binary_dirs" source="ssg" />
        <oval-def:description>This test makes sure that /bin/, /sbin/, /usr/bin/, /usr/sbin/, /usr/local/bin/, /usr/local/sbin/ is group owned by 0.</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="AND">
        <oval-def:criterion comment="Check file group ownership of /bin/" test_ref="oval:ssg-test_file_groupownerdir_groupownership_binary_dirs_0:tst:1" />
        <oval-def:criterion comment="Check file group ownership of /sbin/" test_ref="oval:ssg-test_file_groupownerdir_groupownership_binary_dirs_1:tst:1" />
        <oval-def:criterion comment="Check file group ownership of /usr/bin/" test_ref="oval:ssg-test_file_groupownerdir_groupownership_binary_dirs_2:tst:1" />
        <oval-def:criterion comment="Check file group ownership of /usr/sbin/" test_ref="oval:ssg-test_file_groupownerdir_groupownership_binary_dirs_3:tst:1" />
        <oval-def:criterion comment="Check file group ownership of /usr/local/bin/" test_ref="oval:ssg-test_file_groupownerdir_groupownership_binary_dirs_4:tst:1" />
        <oval-def:criterion comment="Check file group ownership of /usr/local/sbin/" test_ref="oval:ssg-test_file_groupownerdir_groupownership_binary_dirs_5:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-dir_owner_system_journal:def:1" version="1" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Verify owner of system journal directories</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="dir_owner_system_journal" source="ssg" />
        <oval-def:description>This test makes sure that /run/log/journal/, /var/log/journal/ is owned by 0.</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="AND">
        <oval-def:criterion comment="Check file ownership of /run/log/journal/" test_ref="oval:ssg-test_file_ownerdir_owner_system_journal_0:tst:1" />
        <oval-def:criterion comment="Check file ownership of /var/log/journal/" test_ref="oval:ssg-test_file_ownerdir_owner_system_journal_1:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-dir_ownership_binary_dirs:def:1" version="1" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Verify that System Executable Have Root Ownership</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="dir_ownership_binary_dirs" source="ssg" />
        <oval-def:description>This test makes sure that /bin/, /sbin/, /usr/bin/, /usr/sbin/, /usr/local/bin/, /usr/local/sbin/ is owned by 0.</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="AND">
        <oval-def:criterion comment="Check file ownership of /bin/" test_ref="oval:ssg-test_file_ownerdir_ownership_binary_dirs_0:tst:1" />
        <oval-def:criterion comment="Check file ownership of /sbin/" test_ref="oval:ssg-test_file_ownerdir_ownership_binary_dirs_1:tst:1" />
        <oval-def:criterion comment="Check file ownership of /usr/bin/" test_ref="oval:ssg-test_file_ownerdir_ownership_binary_dirs_2:tst:1" />
        <oval-def:criterion comment="Check file ownership of /usr/sbin/" test_ref="oval:ssg-test_file_ownerdir_ownership_binary_dirs_3:tst:1" />
        <oval-def:criterion comment="Check file ownership of /usr/local/bin/" test_ref="oval:ssg-test_file_ownerdir_ownership_binary_dirs_4:tst:1" />
        <oval-def:criterion comment="Check file ownership of /usr/local/sbin/" test_ref="oval:ssg-test_file_ownerdir_ownership_binary_dirs_5:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-dir_ownership_library_dirs:def:1" version="1" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Verify that Shared Library Directories Have Root Ownership</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="dir_ownership_library_dirs" source="ssg" />
        <oval-def:description>This test makes sure that /lib/, /lib64/, /usr/lib/, /usr/lib64/ is owned by 0.</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="AND">
        <oval-def:criterion comment="Check file ownership of /lib/" test_ref="oval:ssg-test_file_ownerdir_ownership_library_dirs_0:tst:1" />
        <oval-def:criterion comment="Check file ownership of /lib64/" test_ref="oval:ssg-test_file_ownerdir_ownership_library_dirs_1:tst:1" />
        <oval-def:criterion comment="Check file ownership of /usr/lib/" test_ref="oval:ssg-test_file_ownerdir_ownership_library_dirs_2:tst:1" />
        <oval-def:criterion comment="Check file ownership of /usr/lib64/" test_ref="oval:ssg-test_file_ownerdir_ownership_library_dirs_3:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-dir_permissions_binary_dirs:def:1" version="1" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Verify that System Executable Directories Have Restrictive Permissions</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="dir_permissions_binary_dirs" source="ssg" />
        <oval-def:description>This test makes sure that /bin/, /sbin/, /usr/bin/, /usr/sbin/, /usr/local/bin/, /usr/local/sbin/ has mode 0755.
      If the target file or directory has an extended ACL, then it will fail the mode check.
      </oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="AND">
        <oval-def:criterion comment="Check file mode of /bin/" test_ref="oval:ssg-test_file_permissionsdir_permissions_binary_dirs_0:tst:1" />
        <oval-def:criterion comment="Check file mode of /sbin/" test_ref="oval:ssg-test_file_permissionsdir_permissions_binary_dirs_1:tst:1" />
        <oval-def:criterion comment="Check file mode of /usr/bin/" test_ref="oval:ssg-test_file_permissionsdir_permissions_binary_dirs_2:tst:1" />
        <oval-def:criterion comment="Check file mode of /usr/sbin/" test_ref="oval:ssg-test_file_permissionsdir_permissions_binary_dirs_3:tst:1" />
        <oval-def:criterion comment="Check file mode of /usr/local/bin/" test_ref="oval:ssg-test_file_permissionsdir_permissions_binary_dirs_4:tst:1" />
        <oval-def:criterion comment="Check file mode of /usr/local/sbin/" test_ref="oval:ssg-test_file_permissionsdir_permissions_binary_dirs_5:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-dir_permissions_system_journal:def:1" version="1" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Verify Permissions on the system journal directories</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="dir_permissions_system_journal" source="ssg" />
        <oval-def:description>This test makes sure that /run/log/journal/, /var/log/journal/ has mode 2750.
      If the target file or directory has an extended ACL, then it will fail the mode check.
      </oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="AND">
        <oval-def:criterion comment="Check file mode of /run/log/journal/" test_ref="oval:ssg-test_file_permissionsdir_permissions_system_journal_0:tst:1" />
        <oval-def:criterion comment="Check file mode of /var/log/journal/" test_ref="oval:ssg-test_file_permissionsdir_permissions_system_journal_1:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-file_groupowner_journalctl:def:1" version="1" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Verify Groupowner on the journalctl command</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="file_groupowner_journalctl" source="ssg" />
        <oval-def:description>This test makes sure that /usr/bin/journalctl is group owned by 0.</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="AND">
        <oval-def:criterion comment="Check file group ownership of /usr/bin/journalctl" test_ref="oval:ssg-test_file_groupowner_journalctl_0:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-file_groupowner_system_journal:def:1" version="1" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Verify Group Who Owns the system journal</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="file_groupowner_system_journal" source="ssg" />
        <oval-def:description>This test makes sure that ^/var/log/journal/.*/system.journal$ is group owned by systemd-journal.</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="AND">
        <oval-def:criterion comment="Check file group ownership of ^/var/log/journal/.*/system.journal$" test_ref="oval:ssg-test_file_groupowner_system_journal_0:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-file_groupowner_var_log:def:1" version="1" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Verify Group Who Owns /var/log Directory</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="file_groupowner_var_log" source="ssg" />
        <oval-def:description>This test makes sure that /var/log/ is group owned by 0.</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="AND">
        <oval-def:criterion comment="Check file group ownership of /var/log/" test_ref="oval:ssg-test_file_groupowner_var_log_0:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-file_groupowner_var_log_syslog:def:1" version="1" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Verify Group Who Owns /var/log/syslog File</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="file_groupowner_var_log_syslog" source="ssg" />
        <oval-def:description>This test makes sure that /var/log/syslog is group owned by 4.</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="AND">
        <oval-def:criterion comment="Check file group ownership of /var/log/syslog" test_ref="oval:ssg-test_file_groupowner_var_log_syslog_0:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-file_groupownership_audit_configuration:def:1" version="1" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Audit Configuration Files Must Be Owned By Group root</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="file_groupownership_audit_configuration" source="ssg" />
        <oval-def:description>This test makes sure that /etc/audit/, /etc/audit/rules.d/ is group owned by 0.</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="AND">
        <oval-def:criterion comment="Check file group ownership of /etc/audit/" test_ref="oval:ssg-test_file_groupownership_audit_configuration_0:tst:1" />
        <oval-def:criterion comment="Check file group ownership of /etc/audit/rules.d/" test_ref="oval:ssg-test_file_groupownership_audit_configuration_1:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-file_owner_journalctl:def:1" version="1" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Verify Owner on the journalctl Command</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="file_owner_journalctl" source="ssg" />
        <oval-def:description>This test makes sure that /usr/bin/journalctl is owned by 0.</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="AND">
        <oval-def:criterion comment="Check file ownership of /usr/bin/journalctl" test_ref="oval:ssg-test_file_owner_journalctl_0:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-file_owner_system_journal:def:1" version="1" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Verify Owner on the system journal</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="file_owner_system_journal" source="ssg" />
        <oval-def:description>This test makes sure that ^/var/log/journal/.*/system.journal$ is owned by 0.</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="AND">
        <oval-def:criterion comment="Check file ownership of ^/var/log/journal/.*/system.journal$" test_ref="oval:ssg-test_file_owner_system_journal_0:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-file_owner_var_log:def:1" version="1" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Verify User Who Owns /var/log Directory</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="file_owner_var_log" source="ssg" />
        <oval-def:description>This test makes sure that /var/log/ is owned by 0.</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="AND">
        <oval-def:criterion comment="Check file ownership of /var/log/" test_ref="oval:ssg-test_file_owner_var_log_0:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-file_owner_var_log_syslog:def:1" version="1" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Verify User Who Owns /var/log/syslog File</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="file_owner_var_log_syslog" source="ssg" />
        <oval-def:description>This test makes sure that /var/log/syslog is owned by syslog.</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="AND">
        <oval-def:criterion comment="Check file ownership of /var/log/syslog" test_ref="oval:ssg-test_file_owner_var_log_syslog_0:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-file_ownership_audit_binaries:def:1" version="1" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Verify that audit tools are owned by root</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="file_ownership_audit_binaries" source="ssg" />
        <oval-def:description>This test makes sure that /sbin/auditctl, /sbin/aureport, /sbin/ausearch, /sbin/autrace, /sbin/auditd, /sbin/audispd, /sbin/augenrules is owned by 0.</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="AND">
        <oval-def:criterion comment="Check file ownership of /sbin/auditctl" test_ref="oval:ssg-test_file_ownership_audit_binaries_0:tst:1" />
        <oval-def:criterion comment="Check file ownership of /sbin/aureport" test_ref="oval:ssg-test_file_ownership_audit_binaries_1:tst:1" />
        <oval-def:criterion comment="Check file ownership of /sbin/ausearch" test_ref="oval:ssg-test_file_ownership_audit_binaries_2:tst:1" />
        <oval-def:criterion comment="Check file ownership of /sbin/autrace" test_ref="oval:ssg-test_file_ownership_audit_binaries_3:tst:1" />
        <oval-def:criterion comment="Check file ownership of /sbin/auditd" test_ref="oval:ssg-test_file_ownership_audit_binaries_4:tst:1" />
        <oval-def:criterion comment="Check file ownership of /sbin/audispd" test_ref="oval:ssg-test_file_ownership_audit_binaries_5:tst:1" />
        <oval-def:criterion comment="Check file ownership of /sbin/augenrules" test_ref="oval:ssg-test_file_ownership_audit_binaries_6:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-file_ownership_audit_configuration:def:1" version="1" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Audit Configuration Files Must Be Owned By Root</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="file_ownership_audit_configuration" source="ssg" />
        <oval-def:description>This test makes sure that /etc/audit/, /etc/audit/rules.d/ is owned by 0.</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="AND">
        <oval-def:criterion comment="Check file ownership of /etc/audit/" test_ref="oval:ssg-test_file_ownership_audit_configuration_0:tst:1" />
        <oval-def:criterion comment="Check file ownership of /etc/audit/rules.d/" test_ref="oval:ssg-test_file_ownership_audit_configuration_1:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-file_ownership_library_dirs:def:1" version="1" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Verify that Shared Library Files Have Root Ownership</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="file_ownership_library_dirs" source="ssg" />
        <oval-def:description>This test makes sure that /lib/, /lib64/, /usr/lib/, /usr/lib64/ is owned by 0.</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="AND">
        <oval-def:criterion comment="Check file ownership of /lib/" test_ref="oval:ssg-test_file_ownership_library_dirs_0:tst:1" />
        <oval-def:criterion comment="Check file ownership of /lib64/" test_ref="oval:ssg-test_file_ownership_library_dirs_1:tst:1" />
        <oval-def:criterion comment="Check file ownership of /usr/lib/" test_ref="oval:ssg-test_file_ownership_library_dirs_2:tst:1" />
        <oval-def:criterion comment="Check file ownership of /usr/lib64/" test_ref="oval:ssg-test_file_ownership_library_dirs_3:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-file_permissions_audit_binaries:def:1" version="1" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Verify that audit tools Have Mode 0755 or less</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="file_permissions_audit_binaries" source="ssg" />
        <oval-def:description>This test makes sure that /sbin/auditctl, /sbin/aureport, /sbin/ausearch, /sbin/autrace, /sbin/auditd, /sbin/audispd, /sbin/augenrules has mode 0755.
      If the target file or directory has an extended ACL, then it will fail the mode check.
      </oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="AND">
        <oval-def:criterion comment="Check file mode of /sbin/auditctl" test_ref="oval:ssg-test_file_permissions_audit_binaries_0:tst:1" />
        <oval-def:criterion comment="Check file mode of /sbin/aureport" test_ref="oval:ssg-test_file_permissions_audit_binaries_1:tst:1" />
        <oval-def:criterion comment="Check file mode of /sbin/ausearch" test_ref="oval:ssg-test_file_permissions_audit_binaries_2:tst:1" />
        <oval-def:criterion comment="Check file mode of /sbin/autrace" test_ref="oval:ssg-test_file_permissions_audit_binaries_3:tst:1" />
        <oval-def:criterion comment="Check file mode of /sbin/auditd" test_ref="oval:ssg-test_file_permissions_audit_binaries_4:tst:1" />
        <oval-def:criterion comment="Check file mode of /sbin/audispd" test_ref="oval:ssg-test_file_permissions_audit_binaries_5:tst:1" />
        <oval-def:criterion comment="Check file mode of /sbin/augenrules" test_ref="oval:ssg-test_file_permissions_audit_binaries_6:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-file_permissions_etc_audit_auditd:def:1" version="1" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Verify Permissions on /etc/audit/auditd.conf</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="file_permissions_etc_audit_auditd" source="ssg" />
        <oval-def:description>This test makes sure that /etc/audit/auditd.conf has mode 0640.
      If the target file or directory has an extended ACL, then it will fail the mode check.
      </oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="AND">
        <oval-def:criterion comment="Check file mode of /etc/audit/auditd.conf" test_ref="oval:ssg-test_file_permissions_etc_audit_auditd_0:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-file_permissions_etc_audit_rules:def:1" version="1" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Verify Permissions on /etc/audit/audit.rules</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="file_permissions_etc_audit_rules" source="ssg" />
        <oval-def:description>This test makes sure that /etc/audit/audit.rules has mode 0640.
      If the target file or directory has an extended ACL, then it will fail the mode check.
      </oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="AND">
        <oval-def:criterion comment="Check file mode of /etc/audit/audit.rules" test_ref="oval:ssg-test_file_permissions_etc_audit_rules_0:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-file_permissions_etc_audit_rulesd:def:1" version="1" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Verify Permissions on /etc/audit/rules.d/*.rules</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="file_permissions_etc_audit_rulesd" source="ssg" />
        <oval-def:description>This test makes sure that /etc/audit/rules.d/ has mode 0600.
      If the target file or directory has an extended ACL, then it will fail the mode check.
      </oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="AND">
        <oval-def:criterion comment="Check file mode of /etc/audit/rules.d/" test_ref="oval:ssg-test_file_permissions_etc_audit_rulesd_0:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-file_permissions_journalctl:def:1" version="1" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Verify Permissions on the journal command</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="file_permissions_journalctl" source="ssg" />
        <oval-def:description>This test makes sure that /usr/bin/journalctl has mode 0740.
      If the target file or directory has an extended ACL, then it will fail the mode check.
      </oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="AND">
        <oval-def:criterion comment="Check file mode of /usr/bin/journalctl" test_ref="oval:ssg-test_file_permissions_journalctl_0:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-file_permissions_library_dirs:def:1" version="1" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Verify that Shared Library Files Have Restrictive Permissions</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="file_permissions_library_dirs" source="ssg" />
        <oval-def:description>This test makes sure that /lib/, /lib64/, /usr/lib/, /usr/lib64/ has mode 7755.
      If the target file or directory has an extended ACL, then it will fail the mode check.
      </oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="AND">
        <oval-def:criterion comment="Check file mode of /lib/" test_ref="oval:ssg-test_file_permissions_library_dirs_0:tst:1" />
        <oval-def:criterion comment="Check file mode of /lib64/" test_ref="oval:ssg-test_file_permissions_library_dirs_1:tst:1" />
        <oval-def:criterion comment="Check file mode of /usr/lib/" test_ref="oval:ssg-test_file_permissions_library_dirs_2:tst:1" />
        <oval-def:criterion comment="Check file mode of /usr/lib64/" test_ref="oval:ssg-test_file_permissions_library_dirs_3:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-file_permissions_system_journal:def:1" version="1" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Verify Permissions on the system journal</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="file_permissions_system_journal" source="ssg" />
        <oval-def:description>This test makes sure that ^/var/log/journal/.*/system.journal$ has mode 0640.
      If the target file or directory has an extended ACL, then it will fail the mode check.
      </oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="AND">
        <oval-def:criterion comment="Check file mode of ^/var/log/journal/.*/system.journal$" test_ref="oval:ssg-test_file_permissions_system_journal_0:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-file_permissions_var_log:def:1" version="1" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Verify Permissions on /var/log Directory</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="file_permissions_var_log" source="ssg" />
        <oval-def:description>This test makes sure that /var/log/ has mode 0755.
      If the target file or directory has an extended ACL, then it will fail the mode check.
      </oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="AND">
        <oval-def:criterion comment="Check file mode of /var/log/" test_ref="oval:ssg-test_file_permissions_var_log_0:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-file_permissions_var_log_syslog:def:1" version="1" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Verify Permissions on /var/log/syslog File</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="file_permissions_var_log_syslog" source="ssg" />
        <oval-def:description>This test makes sure that /var/log/syslog has mode 0640.
      If the target file or directory has an extended ACL, then it will fail the mode check.
      </oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="AND">
        <oval-def:criterion comment="Check file mode of /var/log/syslog" test_ref="oval:ssg-test_file_permissions_var_log_syslog_0:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-kernel_module_usb-storage_disabled:def:1" version="1" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Disable Modprobe Loading of USB Storage Driver</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="kernel_module_usb-storage_disabled" source="ssg" />
        <oval-def:description>The kernel module usb-storage should be disabled.</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="OR">
        <oval-def:criterion comment="kernel module usb-storage disabled in modprobe.d" test_ref="oval:ssg-test_kernmod_usb-storage_disabled:tst:1" />
        <oval-def:criterion comment="kernel module usb-storage disabled in /etc/modprobe.conf" test_ref="oval:ssg-test_kernmod_usb-storage_modprobeconf:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-permissions_local_var_log:def:1" version="1" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Verify permissions of log files</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="permissions_local_var_log" source="ssg" />
        <oval-def:description>This test makes sure that /var/log/ has mode 0640.
      If the target file or directory has an extended ACL, then it will fail the mode check.
      </oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="AND">
        <oval-def:criterion comment="Check file mode of /var/log/" test_ref="oval:ssg-test_file_permissionspermissions_local_var_log_0:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-root_permissions_syslibrary_files:def:1" version="1" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Verify the system-wide library files in directories
"/lib", "/lib64", "/usr/lib/" and "/usr/lib64" are group-owned by root.</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="root_permissions_syslibrary_files" source="ssg" />
        <oval-def:description>This test makes sure that /lib/, /lib64/, /usr/lib/, /usr/lib64/ is group owned by 0.</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="AND">
        <oval-def:criterion comment="Check file group ownership of /lib/" test_ref="oval:ssg-test_file_groupownerroot_permissions_syslibrary_files_0:tst:1" />
        <oval-def:criterion comment="Check file group ownership of /lib64/" test_ref="oval:ssg-test_file_groupownerroot_permissions_syslibrary_files_1:tst:1" />
        <oval-def:criterion comment="Check file group ownership of /usr/lib/" test_ref="oval:ssg-test_file_groupownerroot_permissions_syslibrary_files_2:tst:1" />
        <oval-def:criterion comment="Check file group ownership of /usr/lib64/" test_ref="oval:ssg-test_file_groupownerroot_permissions_syslibrary_files_3:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-service_auditd_enabled:def:1" version="1" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Enable auditd Service</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="service_auditd_enabled" source="ssg" />
        <oval-def:description>The auditd service should be enabled if possible.</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria comment="package audit installed and service auditd is configured to start" operator="AND">
        <oval-def:criterion comment="audit installed" test_ref="oval:ssg-test_service_auditd_package_audit_installed:tst:1" />
        <oval-def:criteria comment="service auditd is configured to start and is running" operator="AND">
          <oval-def:criterion comment="auditd is running" test_ref="oval:ssg-test_service_running_auditd:tst:1" />
          <oval-def:criteria comment="service auditd is configured to start" operator="OR">
            <oval-def:criterion comment="multi-user.target wants auditd" test_ref="oval:ssg-test_multi_user_wants_auditd:tst:1" />
            <oval-def:criterion comment="multi-user.target wants auditd socket" test_ref="oval:ssg-test_multi_user_wants_auditd_socket:tst:1" />
          </oval-def:criteria>
        </oval-def:criteria>
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-service_rsyslog_enabled:def:1" version="1" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Enable rsyslog Service</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="service_rsyslog_enabled" source="ssg" />
        <oval-def:description>The rsyslog service should be enabled if possible.</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria comment="package rsyslog installed and service rsyslog is configured to start" operator="AND">
        <oval-def:criterion comment="rsyslog installed" test_ref="oval:ssg-test_service_rsyslog_package_rsyslog_installed:tst:1" />
        <oval-def:criteria comment="service rsyslog is configured to start and is running" operator="AND">
          <oval-def:criterion comment="rsyslog is running" test_ref="oval:ssg-test_service_running_rsyslog:tst:1" />
          <oval-def:criteria comment="service rsyslog is configured to start" operator="OR">
            <oval-def:criterion comment="multi-user.target wants rsyslog" test_ref="oval:ssg-test_multi_user_wants_rsyslog:tst:1" />
            <oval-def:criterion comment="multi-user.target wants rsyslog socket" test_ref="oval:ssg-test_multi_user_wants_rsyslog_socket:tst:1" />
          </oval-def:criteria>
        </oval-def:criteria>
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-service_sshd_enabled:def:1" version="1" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Enable the OpenSSH Service</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="service_sshd_enabled" source="ssg" />
        <oval-def:description>The sshd service should be enabled if possible.</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria comment="package openssh-server installed and service sshd is configured to start" operator="AND">
        <oval-def:criterion comment="openssh-server installed" test_ref="oval:ssg-test_service_sshd_package_openssh-server_installed:tst:1" />
        <oval-def:criteria comment="service sshd is configured to start and is running" operator="AND">
          <oval-def:criterion comment="sshd is running" test_ref="oval:ssg-test_service_running_sshd:tst:1" />
          <oval-def:criteria comment="service sshd is configured to start" operator="OR">
            <oval-def:criterion comment="multi-user.target wants sshd" test_ref="oval:ssg-test_multi_user_wants_sshd:tst:1" />
            <oval-def:criterion comment="multi-user.target wants sshd socket" test_ref="oval:ssg-test_multi_user_wants_sshd_socket:tst:1" />
          </oval-def:criteria>
        </oval-def:criteria>
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-service_sssd_enabled:def:1" version="1" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Enable the SSSD Service</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="service_sssd_enabled" source="ssg" />
        <oval-def:description>The sssd service should be enabled if possible.</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria comment="package sssd-common installed and service sssd is configured to start" operator="AND">
        <oval-def:criterion comment="sssd-common installed" test_ref="oval:ssg-test_service_sssd_package_sssd-common_installed:tst:1" />
        <oval-def:criteria comment="service sssd is configured to start and is running" operator="AND">
          <oval-def:criterion comment="sssd is running" test_ref="oval:ssg-test_service_running_sssd:tst:1" />
          <oval-def:criteria comment="service sssd is configured to start" operator="OR">
            <oval-def:criterion comment="multi-user.target wants sssd" test_ref="oval:ssg-test_multi_user_wants_sssd:tst:1" />
            <oval-def:criterion comment="multi-user.target wants sssd socket" test_ref="oval:ssg-test_multi_user_wants_sssd_socket:tst:1" />
          </oval-def:criteria>
        </oval-def:criteria>
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-service_ufw_enabled:def:1" version="1" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Verify ufw Enabled</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="service_ufw_enabled" source="ssg" />
        <oval-def:description>The ufw service should be enabled if possible.</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria comment="package ufw installed and service ufw is configured to start" operator="AND">
        <oval-def:criterion comment="ufw installed" test_ref="oval:ssg-test_service_ufw_package_ufw_installed:tst:1" />
        <oval-def:criteria comment="service ufw is configured to start and is running" operator="AND">
          <oval-def:criterion comment="ufw is running" test_ref="oval:ssg-test_service_running_ufw:tst:1" />
          <oval-def:criteria comment="service ufw is configured to start" operator="OR">
            <oval-def:criterion comment="multi-user.target wants ufw" test_ref="oval:ssg-test_multi_user_wants_ufw:tst:1" />
            <oval-def:criterion comment="multi-user.target wants ufw socket" test_ref="oval:ssg-test_multi_user_wants_ufw_socket:tst:1" />
          </oval-def:criteria>
        </oval-def:criteria>
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-sysctl_kernel_dmesg_restrict:def:1" version="3" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Restrict Access to Kernel Message Buffer</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="sysctl_kernel_dmesg_restrict" source="ssg" />
        <oval-def:description>The 'kernel.dmesg_restrict' kernel parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="AND">
        <oval-def:extend_definition comment="kernel.dmesg_restrict configuration setting check" definition_ref="oval:ssg-sysctl_kernel_dmesg_restrict_static:def:1" />
        <oval-def:extend_definition comment="kernel.dmesg_restrict runtime setting check" definition_ref="oval:ssg-sysctl_kernel_dmesg_restrict_runtime:def:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-sysctl_kernel_dmesg_restrict_runtime:def:1" version="3" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Restrict Access to Kernel Message Buffer</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="sysctl_kernel_dmesg_restrict_runtime" source="ssg" />
        <oval-def:description>The kernel 'kernel.dmesg_restrict' parameter should be set to 1 in the system runtime.</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="AND">
        <oval-def:criterion comment="kernel runtime parameter kernel.dmesg_restrict set to 1" test_ref="oval:ssg-test_sysctl_kernel_dmesg_restrict_runtime:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-sysctl_kernel_dmesg_restrict_static:def:1" version="3" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Restrict Access to Kernel Message Buffer</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="sysctl_kernel_dmesg_restrict_static" source="ssg" />
        <oval-def:description>The kernel 'kernel.dmesg_restrict' parameter should be set to 1 in the system configuration.</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="OR">
        <oval-def:criterion comment="kernel static parameter kernel.dmesg_restrict set to 1 in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_kernel_dmesg_restrict_static_user:tst:1" />
        <oval-def:criteria operator="AND">
          <oval-def:criterion comment="kernel static parameter kernel.dmesg_restrict missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_kernel_dmesg_restrict_static_user_missing:tst:1" />
          <oval-def:criterion comment="kernel static parameter kernel.dmesg_restrict set to 1 in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_kernel_dmesg_restrict_static_pkg_correct:tst:1" />
        </oval-def:criteria>
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-sysctl_kernel_randomize_va_space:def:1" version="3" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Enable Randomized Layout of Virtual Address Space</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="sysctl_kernel_randomize_va_space" source="ssg" />
        <oval-def:description>The 'kernel.randomize_va_space' kernel parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="AND">
        <oval-def:extend_definition comment="kernel.randomize_va_space configuration setting check" definition_ref="oval:ssg-sysctl_kernel_randomize_va_space_static:def:1" />
        <oval-def:extend_definition comment="kernel.randomize_va_space runtime setting check" definition_ref="oval:ssg-sysctl_kernel_randomize_va_space_runtime:def:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-sysctl_kernel_randomize_va_space_runtime:def:1" version="3" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Enable Randomized Layout of Virtual Address Space</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="sysctl_kernel_randomize_va_space_runtime" source="ssg" />
        <oval-def:description>The kernel 'kernel.randomize_va_space' parameter should be set to 2 in the system runtime.</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="AND">
        <oval-def:criterion comment="kernel runtime parameter kernel.randomize_va_space set to 2" test_ref="oval:ssg-test_sysctl_kernel_randomize_va_space_runtime:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-sysctl_kernel_randomize_va_space_static:def:1" version="3" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Enable Randomized Layout of Virtual Address Space</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="sysctl_kernel_randomize_va_space_static" source="ssg" />
        <oval-def:description>The kernel 'kernel.randomize_va_space' parameter should be set to 2 in the system configuration.</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="OR">
        <oval-def:criterion comment="kernel static parameter kernel.randomize_va_space set to 2 in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_kernel_randomize_va_space_static_user:tst:1" />
        <oval-def:criteria operator="AND">
          <oval-def:criterion comment="kernel static parameter kernel.randomize_va_space missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_kernel_randomize_va_space_static_user_missing:tst:1" />
          <oval-def:criterion comment="kernel static parameter kernel.randomize_va_space set to 2 in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_kernel_randomize_va_space_static_pkg_correct:tst:1" />
        </oval-def:criteria>
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-sysctl_net_ipv4_tcp_syncookies:def:1" version="3" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Enable Kernel Parameter to Use TCP Syncookies on Network Interfaces</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="sysctl_net_ipv4_tcp_syncookies" source="ssg" />
        <oval-def:description>The 'net.ipv4.tcp_syncookies' kernel parameter should be set to the appropriate value in system configuration and system runtime.</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="AND">
        <oval-def:extend_definition comment="net.ipv4.tcp_syncookies configuration setting check" definition_ref="oval:ssg-sysctl_net_ipv4_tcp_syncookies_static:def:1" />
        <oval-def:extend_definition comment="net.ipv4.tcp_syncookies runtime setting check" definition_ref="oval:ssg-sysctl_net_ipv4_tcp_syncookies_runtime:def:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-sysctl_net_ipv4_tcp_syncookies_runtime:def:1" version="3" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Enable Kernel Parameter to Use TCP Syncookies on Network Interfaces</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="sysctl_net_ipv4_tcp_syncookies_runtime" source="ssg" />
        <oval-def:description>The kernel 'net.ipv4.tcp_syncookies' parameter should be set to the appropriate value in the system runtime.</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="AND">
        <oval-def:criterion comment="kernel runtime parameter net.ipv4.tcp_syncookies set to the appropriate value" test_ref="oval:ssg-test_sysctl_net_ipv4_tcp_syncookies_runtime:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-sysctl_net_ipv4_tcp_syncookies_static:def:1" version="3" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Enable Kernel Parameter to Use TCP Syncookies on Network Interfaces</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="sysctl_net_ipv4_tcp_syncookies_static" source="ssg" />
        <oval-def:description>The kernel 'net.ipv4.tcp_syncookies' parameter should be set to the appropriate value in the system configuration.</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria operator="OR">
        <oval-def:criterion comment="kernel static parameter net.ipv4.tcp_syncookies set to the appropriate value in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_tcp_syncookies_static_user:tst:1" />
        <oval-def:criteria operator="AND">
          <oval-def:criterion comment="kernel static parameter net.ipv4.tcp_syncookies missing in sysctl files not managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_tcp_syncookies_static_user_missing:tst:1" />
          <oval-def:criterion comment="kernel static parameter net.ipv4.tcp_syncookies set to the appropriate value in sysctl files managed by packages" test_ref="oval:ssg-test_sysctl_net_ipv4_tcp_syncookies_static_pkg_correct:tst:1" />
        </oval-def:criteria>
      </oval-def:criteria>
    </oval-def:definition>
    <oval-def:definition id="oval:ssg-verify_use_mappers:def:1" version="1" class="compliance">
      <oval-def:metadata>
        <oval-def:title>Verify that 'use_mappers' is set to 'pwent' in PAM</oval-def:title>
        <oval-def:affected family="unix">
          <oval-def:platform>Claroty CTD 5.x</oval-def:platform>
        </oval-def:affected>
        <oval-def:reference ref_id="verify_use_mappers" source="ssg" />
        <oval-def:description>Check presence of use_mappers = pwent in /etc/pam_pkcs11/pam_pkcs11.conf</oval-def:description>
      </oval-def:metadata>
      <oval-def:criteria comment="Test conditions - presence of the file plus 0 extra definitions." operator="AND">
        <oval-def:criterion comment="Check that /etc/pam_pkcs11/pam_pkcs11.conf contains a line with certain text" test_ref="oval:ssg-test_verify_use_mappers:tst:1" />
      </oval-def:criteria>
    </oval-def:definition>
  </oval-def:definitions>
  <oval-def:tests>
    <ind:textfilecontent54_test id="oval:ssg-test_auditd_audispd_configure_remote_server:tst:1" version="1" check="all" comment="remote server to send audit records" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_auditd_audispd_configure_remote_server:obj:1" />
      <ind:state state_ref="oval:ssg-state_auditd_audispd_configure_remote_server:ste:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_auditd_data_disk_full_action:tst:1" version="1" check="all" comment="disk error action" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_auditd_data_disk_full_action:obj:1" />
      <ind:state state_ref="oval:ssg-state_auditd_data_disk_full_action:ste:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_auditd_data_retention_action_mail_acct:tst:1" version="1" check="all" comment="email account for actions" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_auditd_data_retention_action_mail_acct:obj:1" />
      <ind:state state_ref="oval:ssg-state_auditd_data_retention_action_mail_acct:ste:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_auditd_data_retention_space_left_action:tst:1" version="2" check="all" comment="space left action" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_auditd_data_retention_space_left_action:obj:1" />
      <ind:state state_ref="oval:ssg-state_auditd_data_retention_space_left_action:ste:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_auditd_data_retention_space_left_percentage:tst:1" version="1" check="all" comment="admin space left action " state_operator="AND">
      <ind:object object_ref="oval:ssg-object_auditd_data_retention_space_left_percentage:obj:1" />
      <ind:state state_ref="oval:ssg-state_auditd_data_retention_space_left_percentage:ste:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_etc_cron_weekly_audit_offload_exists:tst:1" version="1" check="all" comment="/etc/cron.weekly/audit-offload exists" check_existence="all_exist" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_etc_cron_weekly_audit_offload_exists:obj:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_apt_conf_disallow_unauthenticated:tst:1" version="1" check="all" comment="Checks allow-unauthenticated in apt configs" check_existence="any_exist" state_operator="AND">
      <ind:object object_ref="oval:ssg-obj_apt_conf_disallow_unauthenticated:obj:1" />
      <ind:state state_ref="oval:ssg-state_apt_conf_disallow_unauthenticated:ste:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_ntp_set_maxpoll:tst:1" version="1" check="all" comment="check if maxpoll is set in /etc/ntp.conf" check_existence="all_exist" state_operator="AND">
      <ind:object object_ref="oval:ssg-obj_ntp_set_maxpoll:obj:1" />
      <ind:state state_ref="oval:ssg-state_time_service_set_maxpoll:ste:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_chrony_set_maxpoll:tst:1" version="1" check="all" comment="check if maxpoll is set in /etc/chrony/chrony.conf or /etc/chrony/conf.d/" check_existence="all_exist" state_operator="AND">
      <ind:object object_ref="oval:ssg-obj_chrony_set_maxpoll:obj:1" />
      <ind:state state_ref="oval:ssg-state_time_service_set_maxpoll:ste:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_ntp_all_server_has_maxpoll:tst:1" version="1" check="all" comment="check if all server entries have maxpoll set in /etc/ntp.conf" check_existence="all_exist" state_operator="AND">
      <ind:object object_ref="oval:ssg-obj_ntp_all_server_has_maxpoll:obj:1" />
      <ind:state state_ref="oval:ssg-state_server_has_maxpoll:ste:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_chrony_all_server_has_maxpoll:tst:1" version="1" check="all" comment="check if all server entries have maxpoll set in /etc/chrony/chrony.conf or /etc/chrony/conf.d/" check_existence="all_exist" state_operator="AND">
      <ind:object object_ref="oval:ssg-obj_chrony_all_server_has_maxpoll:obj:1" />
      <ind:state state_ref="oval:ssg-state_server_has_maxpoll:ste:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_sssd_certification_path_trust_anchor:tst:1" version="1" check="all" comment="test the value of         certificate_verification in sssd configuration" check_existence="all_exist" state_operator="AND">
      <ind:object object_ref="oval:ssg-obj_sssd_certification_path_trust_anchor:obj:1" />
      <ind:state state_ref="oval:ssg-state_sssd_certification_path_trust_anchor:ste:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_sssd_enable_pam_services:tst:1" version="1" check="all" comment="check if pam is configured in the services setting of the sssd section" check_existence="all_exist" state_operator="AND">
      <ind:object object_ref="oval:ssg-obj_sssd_enable_pam_services:obj:1" />
      <ind:state state_ref="oval:ssg-state_sssd_enable_pam_services:ste:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_sssd_enable_smartcards:tst:1" version="1" check="all" comment="tests the value of pam_cert_auth setting in the /etc/sssd/sssd.conf file" check_existence="all_exist" state_operator="AND">
      <ind:object object_ref="oval:ssg-obj_sssd_enable_smartcards:obj:1" />
      <ind:state state_ref="oval:ssg-state_sssd_enable_smartcards:ste:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_sssd_enable_user_cert:tst:1" version="1" check="all" comment="test the value of         ldap_user_certificate in sssd configuration" check_existence="all_exist" state_operator="AND">
      <ind:object object_ref="oval:ssg-obj_sssd_enable_user_cert:obj:1" />
      <ind:state state_ref="oval:ssg-state_sssd_enable_user_cert:ste:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_sssd_offline_cred_expiration:tst:1" version="1" check="all" comment="tests the value of offline_credentials_expiration setting in the /etc/sssd/sssd.conf file" check_existence="all_exist" state_operator="AND">
      <ind:object object_ref="oval:ssg-obj_sssd_offline_cred_expiration:obj:1" />
      <ind:state state_ref="oval:ssg-state_sssd_offline_cred_expiration:ste:1" />
    </ind:textfilecontent54_test>
    <unix:symlink_test id="oval:ssg-test_pam_fingerprint_symlinked_to_authselect:tst:1" version="1" check="all" comment="The 'fingerprint-auth' PAM config is a symlink to its authselect counterpart" check_existence="all_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_pam_fingerprint_symlinked_to_authselect:obj:1" />
      <unix:state state_ref="oval:ssg-state_pam_fingerprint_symlinked_to_authselect:ste:1" />
    </unix:symlink_test>
    <unix:symlink_test id="oval:ssg-test_pam_password_symlinked_to_authselect:tst:1" version="1" check="all" comment="The 'password-auth' PAM config is a symlink to its authselect counterpart" check_existence="all_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_pam_password_symlinked_to_authselect:obj:1" />
      <unix:state state_ref="oval:ssg-state_pam_password_symlinked_to_authselect:ste:1" />
    </unix:symlink_test>
    <unix:symlink_test id="oval:ssg-test_pam_postlogin_symlinked_to_authselect:tst:1" version="1" check="all" comment="The 'postlogin' PAM config is a symlink to its authselect counterpart" check_existence="all_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_pam_postlogin_symlinked_to_authselect:obj:1" />
      <unix:state state_ref="oval:ssg-state_pam_postlogin_symlinked_to_authselect:ste:1" />
    </unix:symlink_test>
    <unix:symlink_test id="oval:ssg-test_pam_smartcard_symlinked_to_authselect:tst:1" version="1" check="all" comment="The 'smartcard-auth' PAM config is a symlink to its authselect counterpart" check_existence="all_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_pam_smartcard_symlinked_to_authselect:obj:1" />
      <unix:state state_ref="oval:ssg-state_pam_smartcard_symlinked_to_authselect:ste:1" />
    </unix:symlink_test>
    <unix:symlink_test id="oval:ssg-test_pam_system_symlinked_to_authselect:tst:1" version="1" check="all" comment="The 'system-auth' PAM config is a symlink to its authselect counterpart" check_existence="all_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_pam_system_symlinked_to_authselect:obj:1" />
      <unix:state state_ref="oval:ssg-state_pam_system_symlinked_to_authselect:ste:1" />
    </unix:symlink_test>
    <ind:textfilecontent54_test id="oval:ssg-test_banner_etc_issue_net:tst:1" version="1" check="at least one" comment="correct banner in /etc/issue.net" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_banner_etc_issue_net:obj:1" />
      <ind:state state_ref="oval:ssg-state_banner_etc_issue_net:ste:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_pam_faillock_audit_parameter_system_auth:tst:1" version="1" check="all" comment="Check the presence of audit parameter in system-auth" state_operator="AND">
      <ind:object object_ref="oval:ssg-obj_all_pam_faillock_audit_parameter_system_auth:obj:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_pam_faillock_audit_parameter_no_pamd_system:tst:1" version="1" check="all" comment="Check the absence of audit parameter in system-auth" check_existence="none_exist" state_operator="AND">
      <ind:object object_ref="oval:ssg-obj_all_pam_faillock_audit_parameter_system_auth:obj:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_pam_faillock_audit_parameter_password_auth:tst:1" version="1" check="all" comment="Check the presence of audit parameter in password-auth" state_operator="AND">
      <ind:object object_ref="oval:ssg-obj_all_pam_faillock_audit_parameter_password_auth:obj:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_pam_faillock_audit_parameter_no_pamd_password:tst:1" version="1" check="all" comment="Check the absence of audit parameter in password-auth" check_existence="none_exist" state_operator="AND">
      <ind:object object_ref="oval:ssg-obj_all_pam_faillock_audit_parameter_password_auth:obj:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_pam_faillock_audit_parameter_faillock_conf:tst:1" version="1" check="all" comment="Check the expected audit value in in /etc/security/faillock.conf" check_existence="all_exist" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_pam_faillock_audit_parameter_faillock_conf:obj:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_pam_faillock_audit_parameter_no_faillock_conf:tst:1" version="1" check="all" comment="Check the absence of audit parameter in /etc/security/faillock.conf" check_existence="none_exist" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_pam_faillock_audit_parameter_faillock_conf:obj:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_pam_faillock_silent_parameter_system_auth:tst:1" version="1" check="all" comment="Check the presence of silent parameter in system-auth" state_operator="AND">
      <ind:object object_ref="oval:ssg-obj_all_pam_faillock_silent_parameter_system_auth:obj:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_pam_faillock_silent_parameter_no_pamd_system:tst:1" version="1" check="all" comment="Check the absence of silent parameter in system-auth" check_existence="none_exist" state_operator="AND">
      <ind:object object_ref="oval:ssg-obj_all_pam_faillock_silent_parameter_system_auth:obj:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_pam_faillock_silent_parameter_password_auth:tst:1" version="1" check="all" comment="Check the presence of silent parameter in password-auth" state_operator="AND">
      <ind:object object_ref="oval:ssg-obj_all_pam_faillock_silent_parameter_password_auth:obj:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_pam_faillock_silent_parameter_no_pamd_password:tst:1" version="1" check="all" comment="Check the absence of silent parameter in password-auth" check_existence="none_exist" state_operator="AND">
      <ind:object object_ref="oval:ssg-obj_all_pam_faillock_silent_parameter_password_auth:obj:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_pam_faillock_silent_parameter_faillock_conf:tst:1" version="1" check="all" comment="Check the expected silent value in in /etc/security/faillock.conf" check_existence="all_exist" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_pam_faillock_silent_parameter_faillock_conf:obj:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_pam_faillock_silent_parameter_no_faillock_conf:tst:1" version="1" check="all" comment="Check the absence of silent parameter in /etc/security/faillock.conf" check_existence="none_exist" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_pam_faillock_silent_parameter_faillock_conf:obj:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_password_pam_pwquality_retry_system_auth:tst:1" version="1" check="all" comment="check the configuration of /etc/pam.d/system-auth" state_operator="AND">
      <ind:object object_ref="oval:ssg-obj_password_pam_pwquality_retry_system_auth:obj:1" />
      <ind:state state_ref="oval:ssg-state_password_pam_retry_upper_bound:ste:1" />
      <ind:state state_ref="oval:ssg-state_password_pam_retry_lower_bound:ste:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_password_pam_pwquality_retry_system_auth_not_set:tst:1" version="1" check="all" comment="check the configuration of /etc/pam.d/system-auth" check_existence="none_exist" state_operator="AND">
      <ind:object object_ref="oval:ssg-obj_password_pam_pwquality_retry_system_auth:obj:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_password_pam_pwquality_retry_pwquality_conf:tst:1" version="1" check="all" comment="check the configuration of /etc/security/pwquality.conf" state_operator="AND">
      <ind:object object_ref="oval:ssg-obj_password_pam_pwquality_retry_pwquality_conf:obj:1" />
      <ind:state state_ref="oval:ssg-state_password_pam_retry_upper_bound:ste:1" />
      <ind:state state_ref="oval:ssg-state_password_pam_retry_lower_bound:ste:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_pam_unix_hashing_algorithm_commonauth:tst:1" version="2" check="all" comment="check if pam_unix.so hashing algorithm option is correct and specified only once in /etc/pam.d/common-password" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_pam_unix_hashing_algorithm_commonauth:obj:1" />
      <ind:state state_ref="oval:ssg-state_pam_unix_hashing_algorithm_commonauth:ste:1" />
    </ind:textfilecontent54_test>
    <ind:variable_test id="oval:ssg-test_set_password_hashing_algorithm_logindefs:tst:1" version="1" check="all" comment="The value of ENCRYPT_METHOD should be set appropriately in /etc/login.defs" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_set_password_hashing_algorithm_logindefs:obj:1" />
      <ind:state state_ref="oval:ssg-state_set_password_hashing_algorithm_logindefs:ste:1" />
    </ind:variable_test>
    <unix:symlink_test id="oval:ssg-test_disable_ctrlaltdel_exists:tst:1" version="1" check="all" comment="Disable Ctrl-Alt-Del key sequence override exists" check_existence="all_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_disable_ctrlaltdel_exists:obj:1" />
      <unix:state state_ref="oval:ssg-state_disable_ctrlaltdel_exists:ste:1" />
    </unix:symlink_test>
    <ind:textfilecontent54_test id="oval:ssg-test_etc_default_useradd_inactive:tst:1" version="1" check="all" comment="the value INACTIVE parameter should be set appropriately in /etc/default/useradd" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_etc_default_useradd_inactive:obj:1" />
      <ind:state state_ref="oval:ssg-state_etc_default_useradd_inactive:ste:1" />
      <ind:state state_ref="oval:ssg-state_etc_default_useradd_inactive_nonnegative:ste:1" />
    </ind:textfilecontent54_test>
    <ind:variable_test id="oval:ssg-test_pass_max_days:tst:1" version="1" check="all" comment="The value of PASS_MAX_DAYS should be set appropriately in /etc/login.defs" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_last_pass_max_days_instance_value:obj:1" />
      <ind:state state_ref="oval:ssg-state_last_pass_max_days_instance_value:ste:1" />
    </ind:variable_test>
    <ind:variable_test id="oval:ssg-test_pass_min_days:tst:1" version="1" check="all" comment="The value of PASS_MIN_DAYS should be set appropriately in /etc/login.defs" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_last_pass_min_days_instance_value:obj:1" />
      <ind:state state_ref="oval:ssg-state_last_pass_min_days_instance_value:ste:1" />
    </ind:variable_test>
    <ind:textfilecontent54_test id="oval:ssg-test_password_auth_pam_unix_rounds_is_set:tst:1" version="1" check="all" comment="Test if rounds attribute of pam_unix.so is set correctly in /etc/pam.d/password-auth " check_existence="all_exist" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_password_auth_pam_unix_rounds:obj:1" />
      <ind:state state_ref="oval:ssg-state_password_auth_pam_unix_rounds:ste:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_no_empty_passwords:tst:1" version="1" check="all" comment="make sure nullok is not used in /etc/pam.d/system-auth" check_existence="none_exist" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_no_empty_passwords:obj:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_no_empty_passwords_etc_shadow:tst:1" version="1" check="all" comment="make sure there aren't blank or null passwords in /etc/shadow" check_existence="none_exist" state_operator="AND">
      <ind:object object_ref="oval:ssg-obj_no_empty_passwords_etc_shadow:obj:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_root_access_locked_etc_shadow:tst:1" version="1" check="all" comment="make sure root account is locked in /etc/shadow" check_existence="only_one_exists" state_operator="AND">
      <ind:object object_ref="oval:ssg-obj_root_access_locked_etc_shadow:obj:1" />
      <ind:state state_ref="oval:ssg-state_oot_access_locked_etc_shadow:ste:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_maxlogins:tst:1" version="1" check="all" comment="the value maxlogins should be set appropriately in /etc/security/limits.conf" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_etc_security_limits_conf_maxlogins:obj:1" />
      <ind:state state_ref="oval:ssg-state_maxlogins:ste:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_limitsd_maxlogins:tst:1" version="1" check="all" comment="the value maxlogins should be set appropriately in /etc/security/limits.d/*.conf" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_etc_security_limitsd_conf_maxlogins:obj:1" />
      <ind:state state_ref="oval:ssg-state_maxlogins:ste:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_limitsd_maxlogins_exists:tst:1" version="1" check="all" comment="the value maxlogins should be set appropriately in /etc/security/limits.d/*.conf" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_etc_security_limitsd_conf_maxlogins_exists:obj:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_etc_profile_tmout:tst:1" version="2" check="all" comment="TMOUT in /etc/profile" check_existence="any_exist" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_etc_profile_tmout:obj:1" />
      <ind:state state_ref="oval:ssg-state_etc_profile_tmout:ste:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_etc_profiled_tmout:tst:1" version="2" check="all" comment="TMOUT in /etc/profile.d/*.sh" check_existence="any_exist" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_etc_profiled_tmout:obj:1" />
      <ind:state state_ref="oval:ssg-state_etc_profile_tmout:ste:1" />
    </ind:textfilecontent54_test>
    <ind:variable_test id="oval:ssg-test_accounts_tmout_defined:tst:1" version="1" check="all" comment="Check that at least one TMOUT is defined" check_existence="all_exist" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_accounts_tmout_defined:obj:1" />
      <ind:state state_ref="oval:ssg-state_accounts_tmout_defined:ste:1" />
    </ind:variable_test>
    <ind:textfilecontent54_test id="oval:ssg-test_accounts_tmout_lower_bound:tst:1" version="1" check="all" comment="All TMOUT values must be greater than or equal to 1" check_existence="any_exist" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_accounts_tmout_all_tmout_instances:obj:1" />
      <ind:state state_ref="oval:ssg-state_etc_profile_tmout_lower_bound:ste:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_bootloader_superuser:tst:1" version="2" check="all" comment="superuser is defined in /boot/grub/grub.cfg files." check_existence="all_exist" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_bootloader_superuser:obj:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_grub2_password_usercfg:tst:1" version="1" check="all" comment="make sure a password is defined in /boot/grub/user.cfg" check_existence="all_exist" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_grub2_password_usercfg:obj:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_grub2_password_grubcfg:tst:1" version="1" check="all" comment="make sure a password is defined in /boot/grub/grub.cfg" check_existence="all_exist" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_grub2_password_grubcfg:obj:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_grub2_uefi_password_usercfg:tst:1" version="1" check="all" comment="make sure a password is defined in /boot/efi/EFI/ubuntu/user.cfg" check_existence="all_exist" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_grub2_uefi_password_usercfg:obj:1" />
    </ind:textfilecontent54_test>
    <unix:symlink_test id="oval:ssg-test_ensure_rtc_utc_configuration:tst:1" version="1" check="all" comment="Ensure softlink exist for localtime with UTC pattern" check_existence="all_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_ensure_rtc_utc_configuration:obj:1" />
      <unix:state state_ref="oval:ssg-object_ensure_symlink_utc_configuration:ste:1" />
    </unix:symlink_test>
    <ind:textfilecontent54_test id="oval:ssg-test_remote_method_monitoring_auth:tst:1" version="1" check="all" comment="remote method auth monitoring configured in rsyslog'" state_operator="AND">
      <ind:object object_ref="oval:ssg-obj_remote_method_monitoring_auth:obj:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_remote_method_monitoring_authpriv:tst:1" version="1" check="all" comment="remote method authpriv monitoring configured in rsyslog'" state_operator="AND">
      <ind:object object_ref="oval:ssg-obj_remote_method_monitoring_authpriv:obj:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_remote_method_monitoring_daemon:tst:1" version="1" check="all" comment="remote method daemon monitoring configured in rsyslog'" state_operator="AND">
      <ind:object object_ref="oval:ssg-obj_remote_method_monitoring_daemon:obj:1" />
    </ind:textfilecontent54_test>
    <unix:interface_test id="oval:ssg-test_wireless_disable_interfaces:tst:1" version="1" check="all" comment="check if UP flag is present on wifi interfaces" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_active_wifi_interfaces:obj:1" />
      <unix:state state_ref="oval:ssg-state_wifi_up:ste:1" />
    </unix:interface_test>
    <unix:file_test id="oval:ssg-test_dir_perms_world_writable_sticky_bits:tst:1" version="2" check="all" comment="Check the existence of world-writable directories without sticky bits" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_dir_perms_world_writable_sticky_bits:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_groupownership_system_commands_dirs:tst:1" version="1" check="all" comment="system commands are owned by root or a system account" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_groupownership_system_commands_dirs:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_ownership_binary_directories:tst:1" version="1" check="all" comment="binary directories uid root" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_ownership_binary_directories:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_ownership_binary_files:tst:1" version="1" check="all" comment="binary files uid root" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_ownership_binary_files:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_perms_binary_files:tst:1" version="1" check="all" comment="binary files go-w" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_permissions_binary_files:obj:1" />
    </unix:file_test>
    <ind:textfilecontent54_test id="oval:ssg-test_NX_cpu_support:tst:1" version="1" check="all" comment="CPUs support for NX bit" check_existence="all_exist" state_operator="AND">
      <ind:object object_ref="oval:ssg-obj_NX_cpu_support:obj:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_noexec_cmd_line:tst:1" version="1" check="all" comment="NX is not disabled in the kernel command line" check_existence="none_exist" state_operator="AND">
      <ind:object object_ref="oval:ssg-obj_noexec_cmd_line:obj:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-is_fips_mode_enabled_test_whole_file_contents_fips_equal_to_one:tst:1" version="1" check="all" comment="Tests if contents of /proc/sys/crypto/fips_enabled is exactly what is defined in rule description" check_existence="all_exist" state_operator="AND">
      <ind:object object_ref="oval:ssg-is_fips_mode_enabled_object_whole_file_contents_fips_equal_to_one:obj:1" />
      <ind:state state_ref="oval:ssg-is_fips_mode_enabled_state_whole_file_contents_fips_equal_to_one:ste:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_no_authenticate_etc_sudoers:tst:1" version="1" check="all" comment="!authenticate does not exist in /etc/sudoers" check_existence="none_exist" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_no_authenticate_etc_sudoers:obj:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_no_authenticate_etc_sudoers_d:tst:1" version="1" check="all" comment="!authenticate does not exist in /etc/sudoers.d" check_existence="none_exist" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_no_authenticate_etc_sudoers_d:obj:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_nopasswd_etc_sudoers:tst:1" version="1" check="all" comment="NOPASSWD does not exist /etc/sudoers" check_existence="none_exist" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_nopasswd_etc_sudoers:obj:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_nopasswd_etc_sudoers_d:tst:1" version="1" check="all" comment="NOPASSWD does not exist in /etc/sudoers.d" check_existence="none_exist" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_nopasswd_etc_sudoers_d:obj:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_not_all_users_can_sudo_to_users:tst:1" version="1" check="all" comment="Make sure that sudoers has restrictions on which users can run sudo" check_existence="none_exist" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_sudoers_cfg_spec_all_users:obj:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_not_all_users_can_sudo_to_group:tst:1" version="1" check="all" comment="Make sure that sudoers has restrictions on which users can run sudo" check_existence="none_exist" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_sudoers_cfg_spec_all_group:obj:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_yum_clean_components_post_updating:tst:1" version="1" check="all" comment="check value of clean_requirements_on_remove in /etc/apt/apt.conf" check_existence="all_exist" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_yum_clean_components_post_updating:obj:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_accounts_password_pam_enforcing:tst:1" version="1" check="all" comment="tests the presence of 'enforcing = 1' setting in the /etc/security/pwquality.conf file" state_operator="AND">
      <ind:object object_ref="oval:ssg-obj_accounts_password_pam_enforcing:obj:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_pam_auth_pam_faildelay_delay:tst:1" version="1" check="all" comment="Verify delay configuation of pam_faildelay.so" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_pam_auth_pam_faildelay_delay:obj:1" />
      <ind:state state_ref="oval:ssg-state_pam_auth_pam_faildelay_delay:ste:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_accounts_passwords_pam_faillock_deny_system_pam_unix_auth:tst:1" version="2" check="all" comment="no more that one pam_unix.so is expected in auth section of system-auth" check_existence="none_exist" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_deny_system_pam_unix_auth:obj:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_accounts_passwords_pam_faillock_deny_system_pam_faillock_auth:tst:1" version="2" check="all" comment="One and only one occurrence is expected in auth section of system-auth" check_existence="only_one_exists" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_deny_system_pam_faillock_auth:obj:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_accounts_passwords_pam_faillock_deny_password_pam_unix_auth:tst:1" version="2" check="all" comment="no more that one pam_unix.so is expected in auth section of password-auth" check_existence="none_exist" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_deny_password_pam_unix_auth:obj:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_accounts_passwords_pam_faillock_deny_password_pam_faillock_auth:tst:1" version="2" check="all" comment="One and only one occurrence is expected in auth section of password-auth" check_existence="only_one_exists" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_deny_password_pam_faillock_auth:obj:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_accounts_passwords_pam_faillock_deny_system_pam_faillock_account:tst:1" version="2" check="all" comment="One and only one occurrence is expected in system-auth" check_existence="only_one_exists" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_deny_system_pam_faillock_account:obj:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_accounts_passwords_pam_faillock_deny_password_pam_faillock_account:tst:1" version="2" check="all" comment="One and only one occurrence is expected in password-auth" check_existence="only_one_exists" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_deny_password_pam_faillock_account:obj:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_accounts_passwords_pam_faillock_deny_parameter_no_pamd_system:tst:1" version="2" check="all" comment="Check the absence of deny parameter in system-auth" check_existence="none_exist" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_deny_parameter_pamd_system:obj:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_accounts_passwords_pam_faillock_deny_parameter_pamd_system:tst:1" version="2" check="all" comment="Check the expected deny value in system-auth" check_existence="all_exist" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_deny_parameter_pamd_system:obj:1" />
      <ind:state state_ref="oval:ssg-state_accounts_passwords_pam_faillock_deny_parameter_upper_bound:ste:1" />
      <ind:state state_ref="oval:ssg-state_accounts_passwords_pam_faillock_deny_parameter_lower_bound:ste:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_accounts_passwords_pam_faillock_deny_parameter_no_pamd_password:tst:1" version="2" check="all" comment="Check the absence of deny parameter in password-auth" check_existence="none_exist" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_deny_parameter_pamd_password:obj:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_accounts_passwords_pam_faillock_deny_parameter_pamd_password:tst:1" version="2" check="all" comment="Check the expected deny value in password-auth" check_existence="all_exist" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_deny_parameter_pamd_password:obj:1" />
      <ind:state state_ref="oval:ssg-state_accounts_passwords_pam_faillock_deny_parameter_upper_bound:ste:1" />
      <ind:state state_ref="oval:ssg-state_accounts_passwords_pam_faillock_deny_parameter_lower_bound:ste:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_accounts_passwords_pam_faillock_deny_parameter_faillock_conf:tst:1" version="1" check="all" comment="Check the expected deny value in /etc/security/faillock.conf" check_existence="all_exist" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_deny_parameter_faillock_conf:obj:1" />
      <ind:state state_ref="oval:ssg-state_accounts_passwords_pam_faillock_deny_parameter_upper_bound:ste:1" />
      <ind:state state_ref="oval:ssg-state_accounts_passwords_pam_faillock_deny_parameter_lower_bound:ste:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_accounts_passwords_pam_faillock_deny_parameter_no_faillock_conf:tst:1" version="1" check="all" comment="Check the absence of deny parameter in /etc/security/faillock.conf" check_existence="none_exist" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_deny_parameter_faillock_conf:obj:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_accounts_passwords_pam_faillock_fail_interval_system_pam_unix_auth:tst:1" version="2" check="all" comment="no more that one pam_unix.so is expected in auth section of system-auth" check_existence="none_exist" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_fail_interval_system_pam_unix_auth:obj:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_accounts_passwords_pam_faillock_fail_interval_system_pam_faillock_auth:tst:1" version="2" check="all" comment="One and only one occurrence is expected in auth section of system-auth" check_existence="only_one_exists" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_fail_interval_system_pam_faillock_auth:obj:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_accounts_passwords_pam_faillock_fail_interval_password_pam_unix_auth:tst:1" version="2" check="all" comment="no more that one pam_unix.so is expected in auth section of password-auth" check_existence="none_exist" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_fail_interval_password_pam_unix_auth:obj:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_accounts_passwords_pam_faillock_fail_interval_password_pam_faillock_auth:tst:1" version="2" check="all" comment="One and only one occurrence is expected in auth section of password-auth" check_existence="only_one_exists" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_fail_interval_password_pam_faillock_auth:obj:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_accounts_passwords_pam_faillock_fail_interval_system_pam_faillock_account:tst:1" version="2" check="all" comment="One and only one occurrence is expected in system-auth" check_existence="only_one_exists" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_fail_interval_system_pam_faillock_account:obj:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_accounts_passwords_pam_faillock_fail_interval_password_pam_faillock_account:tst:1" version="2" check="all" comment="One and only one occurrence is expected in password-auth" check_existence="only_one_exists" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_fail_interval_password_pam_faillock_account:obj:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_accounts_passwords_pam_faillock_fail_interval_parameter_no_pamd_system:tst:1" version="2" check="all" comment="Check the absence of fail_interval parameter in system-auth" check_existence="none_exist" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_fail_interval_parameter_pamd_system:obj:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_accounts_passwords_pam_faillock_fail_interval_parameter_pamd_system:tst:1" version="2" check="all" comment="Check the expected fail_interval value in system-auth" check_existence="all_exist" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_fail_interval_parameter_pamd_system:obj:1" />
      <ind:state state_ref="oval:ssg-state_accounts_passwords_pam_faillock_fail_interval_parameter_lower_bound:ste:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_accounts_passwords_pam_faillock_fail_interval_parameter_no_pamd_password:tst:1" version="2" check="all" comment="Check the absence of fail_interval parameter in password-auth" check_existence="none_exist" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_fail_interval_parameter_pamd_password:obj:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_accounts_passwords_pam_faillock_fail_interval_parameter_pamd_password:tst:1" version="2" check="all" comment="Check the expected fail_interval value in password-auth" check_existence="all_exist" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_fail_interval_parameter_pamd_password:obj:1" />
      <ind:state state_ref="oval:ssg-state_accounts_passwords_pam_faillock_fail_interval_parameter_lower_bound:ste:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_accounts_passwords_pam_faillock_fail_interval_parameter_faillock_conf:tst:1" version="1" check="all" comment="Check the expected fail_interval value in /etc/security/faillock.conf" check_existence="all_exist" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_fail_interval_parameter_faillock_conf:obj:1" />
      <ind:state state_ref="oval:ssg-state_accounts_passwords_pam_faillock_fail_interval_parameter_lower_bound:ste:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_accounts_passwords_pam_faillock_fail_interval_parameter_no_faillock_conf:tst:1" version="1" check="all" comment="Check the absence of fail_interval parameter in /etc/security/faillock.conf" check_existence="none_exist" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_fail_interval_parameter_faillock_conf:obj:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_system_pam_unix_auth:tst:1" version="2" check="all" comment="no more that one pam_unix.so is expected in auth section of system-auth" check_existence="none_exist" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_unlock_time_system_pam_unix_auth:obj:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_system_pam_faillock_auth:tst:1" version="2" check="all" comment="One and only one occurrence is expected in auth section of system-auth" check_existence="only_one_exists" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_unlock_time_system_pam_faillock_auth:obj:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_password_pam_unix_auth:tst:1" version="2" check="all" comment="no more that one pam_unix.so is expected in auth section of password-auth" check_existence="none_exist" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_unlock_time_password_pam_unix_auth:obj:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_password_pam_faillock_auth:tst:1" version="2" check="all" comment="One and only one occurrence is expected in auth section of password-auth" check_existence="only_one_exists" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_unlock_time_password_pam_faillock_auth:obj:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_system_pam_faillock_account:tst:1" version="2" check="all" comment="One and only one occurrence is expected in system-auth" check_existence="only_one_exists" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_unlock_time_system_pam_faillock_account:obj:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_password_pam_faillock_account:tst:1" version="2" check="all" comment="One and only one occurrence is expected in password-auth" check_existence="only_one_exists" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_unlock_time_password_pam_faillock_account:obj:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_parameter_no_pamd_system:tst:1" version="2" check="all" comment="Check the absence of unlock_time parameter in system-auth" check_existence="none_exist" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_unlock_time_parameter_pamd_system:obj:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_parameter_pamd_system:tst:1" version="2" check="all" comment="Check the expected unlock_time value in system-auth" check_existence="all_exist" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_unlock_time_parameter_pamd_system:obj:1" />
      <ind:state state_ref="oval:ssg-state_accounts_passwords_pam_faillock_unlock_time_parameter_lower_bound:ste:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_parameter_no_pamd_password:tst:1" version="2" check="all" comment="Check the absence of unlock_time parameter in password-auth" check_existence="none_exist" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_unlock_time_parameter_pamd_password:obj:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_parameter_pamd_password:tst:1" version="2" check="all" comment="Check the expected unlock_time value in password-auth" check_existence="all_exist" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_unlock_time_parameter_pamd_password:obj:1" />
      <ind:state state_ref="oval:ssg-state_accounts_passwords_pam_faillock_unlock_time_parameter_lower_bound:ste:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_parameter_faillock_conf:tst:1" version="1" check="all" comment="Check the expected unlock_time value in /etc/security/faillock.conf" check_existence="all_exist" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_unlock_time_parameter_faillock_conf:obj:1" />
      <ind:state state_ref="oval:ssg-state_accounts_passwords_pam_faillock_unlock_time_parameter_lower_bound:ste:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_accounts_passwords_pam_faillock_unlock_time_parameter_no_faillock_conf:tst:1" version="1" check="all" comment="Check the absence of unlock_time parameter in /etc/security/faillock.conf" check_existence="none_exist" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_accounts_passwords_pam_faillock_unlock_time_parameter_faillock_conf:obj:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_aide_disable_silentreports:tst:1" version="1" check="all" comment="tests the value of SILENTREPORTS setting in the /etc/default/aide file" check_existence="all_exist" state_operator="AND">
      <ind:object object_ref="oval:ssg-obj_aide_disable_silentreports:obj:1" />
      <ind:state state_ref="oval:ssg-state_aide_disable_silentreports:ste:1" />
    </ind:textfilecontent54_test>
    <unix:file_test id="oval:ssg-test_aide_disable_silentreports_config_file_exists:tst:1" version="1" check="all" comment="The configuration file /etc/default/aide exists for aide_disable_silentreports" check_existence="all_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-obj_aide_disable_silentreports_config_file:obj:1" />
    </unix:file_test>
    <linux:systemdunitdependency_test id="oval:ssg-test_multi_user_wants_apparmor:tst:1" version="1" check="all" comment="systemd test" check_existence="any_exist" state_operator="AND">
      <linux:object object_ref="oval:ssg-object_multi_user_target_for_apparmor_enabled:obj:1" />
      <linux:state state_ref="oval:ssg-state_systemd_apparmor_on:ste:1" />
    </linux:systemdunitdependency_test>
    <linux:systemdunitdependency_test id="oval:ssg-test_multi_user_wants_apparmor_socket:tst:1" version="1" check="all" comment="systemd test" check_existence="any_exist" state_operator="AND">
      <linux:object object_ref="oval:ssg-object_multi_user_target_for_apparmor_socket_enabled:obj:1" />
      <linux:state state_ref="oval:ssg-state_systemd_apparmor_socket_on:ste:1" />
    </linux:systemdunitdependency_test>
    <linux:systemdunitproperty_test id="oval:ssg-test_service_running_apparmor:tst:1" version="1" check="at least one" comment="Test that the apparmor service is running" state_operator="AND">
      <linux:object object_ref="oval:ssg-obj_service_running_apparmor:obj:1" />
      <linux:state state_ref="oval:ssg-state_service_running_apparmor:ste:1" />
    </linux:systemdunitproperty_test>
    <linux:dpkginfo_test id="oval:ssg-test_service_apparmor_package_apparmor-parser_installed:tst:1" version="1" check="all" comment="package apparmor-parser is installed" check_existence="all_exist" state_operator="AND">
      <linux:object object_ref="oval:ssg-obj_test_service_apparmor_package_apparmor-parser_installed:obj:1" />
    </linux:dpkginfo_test>
    <ind:textfilecontent54_test id="oval:ssg-test_chronyd_sync_clock:tst:1" version="1" check="all" comment="tests the value of makestep setting in the /etc/chrony/chrony.conf file" check_existence="all_exist" state_operator="AND">
      <ind:object object_ref="oval:ssg-obj_chronyd_sync_clock:obj:1" />
      <ind:state state_ref="oval:ssg-state_chronyd_sync_clock:ste:1" />
    </ind:textfilecontent54_test>
    <unix:file_test id="oval:ssg-test_chronyd_sync_clock_config_file_exists:tst:1" version="1" check="all" comment="The configuration file /etc/chrony/chrony.conf exists for chronyd_sync_clock" check_existence="all_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-obj_chronyd_sync_clock_config_file:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_groupownerdir_group_ownership_library_dirs_0:tst:1" version="1" check="all" comment="Testing group ownership of /lib/" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_groupownerdir_group_ownership_library_dirs_0:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_groupownerdir_group_ownership_library_dirs_1:tst:1" version="1" check="all" comment="Testing group ownership of /lib64/" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_groupownerdir_group_ownership_library_dirs_1:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_groupownerdir_group_ownership_library_dirs_2:tst:1" version="1" check="all" comment="Testing group ownership of /usr/lib/" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_groupownerdir_group_ownership_library_dirs_2:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_groupownerdir_group_ownership_library_dirs_3:tst:1" version="1" check="all" comment="Testing group ownership of /usr/lib64/" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_groupownerdir_group_ownership_library_dirs_3:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_groupownerdir_groupowner_system_journal_0:tst:1" version="1" check="all" comment="Testing group ownership of /run/log/journal/" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_groupownerdir_groupowner_system_journal_0:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_groupownerdir_groupowner_system_journal_1:tst:1" version="1" check="all" comment="Testing group ownership of /var/log/journal/" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_groupownerdir_groupowner_system_journal_1:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_groupownerdir_groupownership_binary_dirs_0:tst:1" version="1" check="all" comment="Testing group ownership of /bin/" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_groupownerdir_groupownership_binary_dirs_0:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_groupownerdir_groupownership_binary_dirs_1:tst:1" version="1" check="all" comment="Testing group ownership of /sbin/" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_groupownerdir_groupownership_binary_dirs_1:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_groupownerdir_groupownership_binary_dirs_2:tst:1" version="1" check="all" comment="Testing group ownership of /usr/bin/" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_groupownerdir_groupownership_binary_dirs_2:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_groupownerdir_groupownership_binary_dirs_3:tst:1" version="1" check="all" comment="Testing group ownership of /usr/sbin/" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_groupownerdir_groupownership_binary_dirs_3:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_groupownerdir_groupownership_binary_dirs_4:tst:1" version="1" check="all" comment="Testing group ownership of /usr/local/bin/" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_groupownerdir_groupownership_binary_dirs_4:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_groupownerdir_groupownership_binary_dirs_5:tst:1" version="1" check="all" comment="Testing group ownership of /usr/local/sbin/" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_groupownerdir_groupownership_binary_dirs_5:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_ownerdir_owner_system_journal_0:tst:1" version="1" check="all" comment="Testing user ownership of /run/log/journal/" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_ownerdir_owner_system_journal_0:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_ownerdir_owner_system_journal_1:tst:1" version="1" check="all" comment="Testing user ownership of /var/log/journal/" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_ownerdir_owner_system_journal_1:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_ownerdir_ownership_binary_dirs_0:tst:1" version="1" check="all" comment="Testing user ownership of /bin/" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_ownerdir_ownership_binary_dirs_0:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_ownerdir_ownership_binary_dirs_1:tst:1" version="1" check="all" comment="Testing user ownership of /sbin/" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_ownerdir_ownership_binary_dirs_1:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_ownerdir_ownership_binary_dirs_2:tst:1" version="1" check="all" comment="Testing user ownership of /usr/bin/" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_ownerdir_ownership_binary_dirs_2:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_ownerdir_ownership_binary_dirs_3:tst:1" version="1" check="all" comment="Testing user ownership of /usr/sbin/" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_ownerdir_ownership_binary_dirs_3:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_ownerdir_ownership_binary_dirs_4:tst:1" version="1" check="all" comment="Testing user ownership of /usr/local/bin/" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_ownerdir_ownership_binary_dirs_4:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_ownerdir_ownership_binary_dirs_5:tst:1" version="1" check="all" comment="Testing user ownership of /usr/local/sbin/" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_ownerdir_ownership_binary_dirs_5:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_ownerdir_ownership_library_dirs_0:tst:1" version="1" check="all" comment="Testing user ownership of /lib/" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_ownerdir_ownership_library_dirs_0:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_ownerdir_ownership_library_dirs_1:tst:1" version="1" check="all" comment="Testing user ownership of /lib64/" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_ownerdir_ownership_library_dirs_1:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_ownerdir_ownership_library_dirs_2:tst:1" version="1" check="all" comment="Testing user ownership of /usr/lib/" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_ownerdir_ownership_library_dirs_2:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_ownerdir_ownership_library_dirs_3:tst:1" version="1" check="all" comment="Testing user ownership of /usr/lib64/" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_ownerdir_ownership_library_dirs_3:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_permissionsdir_permissions_binary_dirs_0:tst:1" version="3" check="all" comment="Testing mode of /bin/" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_permissionsdir_permissions_binary_dirs_0:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_permissionsdir_permissions_binary_dirs_1:tst:1" version="3" check="all" comment="Testing mode of /sbin/" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_permissionsdir_permissions_binary_dirs_1:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_permissionsdir_permissions_binary_dirs_2:tst:1" version="3" check="all" comment="Testing mode of /usr/bin/" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_permissionsdir_permissions_binary_dirs_2:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_permissionsdir_permissions_binary_dirs_3:tst:1" version="3" check="all" comment="Testing mode of /usr/sbin/" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_permissionsdir_permissions_binary_dirs_3:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_permissionsdir_permissions_binary_dirs_4:tst:1" version="3" check="all" comment="Testing mode of /usr/local/bin/" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_permissionsdir_permissions_binary_dirs_4:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_permissionsdir_permissions_binary_dirs_5:tst:1" version="3" check="all" comment="Testing mode of /usr/local/sbin/" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_permissionsdir_permissions_binary_dirs_5:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_permissionsdir_permissions_system_journal_0:tst:1" version="3" check="all" comment="Testing mode of /run/log/journal/" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_permissionsdir_permissions_system_journal_0:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_permissionsdir_permissions_system_journal_1:tst:1" version="3" check="all" comment="Testing mode of /var/log/journal/" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_permissionsdir_permissions_system_journal_1:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_groupowner_journalctl_0:tst:1" version="1" check="all" comment="Testing group ownership of /usr/bin/journalctl" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_groupowner_journalctl_0:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_groupowner_system_journal_0:tst:1" version="1" check="all" comment="Testing group ownership of ^/var/log/journal/.*/system.journal$" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_groupowner_system_journal_0:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_groupowner_var_log_0:tst:1" version="1" check="all" comment="Testing group ownership of /var/log/" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_groupowner_var_log_0:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_groupowner_var_log_syslog_0:tst:1" version="1" check="all" comment="Testing group ownership of /var/log/syslog" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_groupowner_var_log_syslog_0:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_groupownership_audit_configuration_0:tst:1" version="1" check="all" comment="Testing group ownership of /etc/audit/" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_groupownership_audit_configuration_0:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_groupownership_audit_configuration_1:tst:1" version="1" check="all" comment="Testing group ownership of /etc/audit/rules.d/" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_groupownership_audit_configuration_1:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_owner_journalctl_0:tst:1" version="1" check="all" comment="Testing user ownership of /usr/bin/journalctl" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_owner_journalctl_0:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_owner_system_journal_0:tst:1" version="1" check="all" comment="Testing user ownership of ^/var/log/journal/.*/system.journal$" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_owner_system_journal_0:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_owner_var_log_0:tst:1" version="1" check="all" comment="Testing user ownership of /var/log/" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_owner_var_log_0:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_owner_var_log_syslog_0:tst:1" version="1" check="all" comment="Testing user ownership of /var/log/syslog" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_owner_var_log_syslog_0:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_ownership_audit_binaries_0:tst:1" version="1" check="all" comment="Testing user ownership of /sbin/auditctl" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_ownership_audit_binaries_0:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_ownership_audit_binaries_1:tst:1" version="1" check="all" comment="Testing user ownership of /sbin/aureport" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_ownership_audit_binaries_1:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_ownership_audit_binaries_2:tst:1" version="1" check="all" comment="Testing user ownership of /sbin/ausearch" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_ownership_audit_binaries_2:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_ownership_audit_binaries_3:tst:1" version="1" check="all" comment="Testing user ownership of /sbin/autrace" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_ownership_audit_binaries_3:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_ownership_audit_binaries_4:tst:1" version="1" check="all" comment="Testing user ownership of /sbin/auditd" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_ownership_audit_binaries_4:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_ownership_audit_binaries_5:tst:1" version="1" check="all" comment="Testing user ownership of /sbin/audispd" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_ownership_audit_binaries_5:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_ownership_audit_binaries_6:tst:1" version="1" check="all" comment="Testing user ownership of /sbin/augenrules" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_ownership_audit_binaries_6:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_ownership_audit_configuration_0:tst:1" version="1" check="all" comment="Testing user ownership of /etc/audit/" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_ownership_audit_configuration_0:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_ownership_audit_configuration_1:tst:1" version="1" check="all" comment="Testing user ownership of /etc/audit/rules.d/" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_ownership_audit_configuration_1:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_ownership_library_dirs_0:tst:1" version="1" check="all" comment="Testing user ownership of /lib/" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_ownership_library_dirs_0:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_ownership_library_dirs_1:tst:1" version="1" check="all" comment="Testing user ownership of /lib64/" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_ownership_library_dirs_1:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_ownership_library_dirs_2:tst:1" version="1" check="all" comment="Testing user ownership of /usr/lib/" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_ownership_library_dirs_2:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_ownership_library_dirs_3:tst:1" version="1" check="all" comment="Testing user ownership of /usr/lib64/" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_ownership_library_dirs_3:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_permissions_audit_binaries_0:tst:1" version="3" check="all" comment="Testing mode of /sbin/auditctl" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_permissions_audit_binaries_0:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_permissions_audit_binaries_1:tst:1" version="3" check="all" comment="Testing mode of /sbin/aureport" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_permissions_audit_binaries_1:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_permissions_audit_binaries_2:tst:1" version="3" check="all" comment="Testing mode of /sbin/ausearch" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_permissions_audit_binaries_2:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_permissions_audit_binaries_3:tst:1" version="3" check="all" comment="Testing mode of /sbin/autrace" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_permissions_audit_binaries_3:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_permissions_audit_binaries_4:tst:1" version="3" check="all" comment="Testing mode of /sbin/auditd" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_permissions_audit_binaries_4:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_permissions_audit_binaries_5:tst:1" version="3" check="all" comment="Testing mode of /sbin/audispd" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_permissions_audit_binaries_5:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_permissions_audit_binaries_6:tst:1" version="3" check="all" comment="Testing mode of /sbin/augenrules" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_permissions_audit_binaries_6:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_permissions_etc_audit_auditd_0:tst:1" version="3" check="all" comment="Testing mode of /etc/audit/auditd.conf" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_permissions_etc_audit_auditd_0:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_permissions_etc_audit_rules_0:tst:1" version="3" check="all" comment="Testing mode of /etc/audit/audit.rules" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_permissions_etc_audit_rules_0:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_permissions_etc_audit_rulesd_0:tst:1" version="3" check="all" comment="Testing mode of /etc/audit/rules.d/" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_permissions_etc_audit_rulesd_0:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_permissions_journalctl_0:tst:1" version="3" check="all" comment="Testing mode of /usr/bin/journalctl" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_permissions_journalctl_0:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_permissions_library_dirs_0:tst:1" version="3" check="all" comment="Testing mode of /lib/" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_permissions_library_dirs_0:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_permissions_library_dirs_1:tst:1" version="3" check="all" comment="Testing mode of /lib64/" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_permissions_library_dirs_1:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_permissions_library_dirs_2:tst:1" version="3" check="all" comment="Testing mode of /usr/lib/" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_permissions_library_dirs_2:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_permissions_library_dirs_3:tst:1" version="3" check="all" comment="Testing mode of /usr/lib64/" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_permissions_library_dirs_3:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_permissions_system_journal_0:tst:1" version="3" check="all" comment="Testing mode of ^/var/log/journal/.*/system.journal$" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_permissions_system_journal_0:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_permissions_var_log_0:tst:1" version="3" check="all" comment="Testing mode of /var/log/" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_permissions_var_log_0:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_permissions_var_log_syslog_0:tst:1" version="3" check="all" comment="Testing mode of /var/log/syslog" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_permissions_var_log_syslog_0:obj:1" />
    </unix:file_test>
    <ind:textfilecontent54_test id="oval:ssg-test_kernmod_usb-storage_disabled:tst:1" version="1" check="all" comment="kernel module usb-storage disabled" state_operator="AND">
      <ind:object object_ref="oval:ssg-obj_kernmod_usb-storage_disabled:obj:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_kernmod_usb-storage_modprobeconf:tst:1" version="1" check="all" comment="kernel module usb-storage disabled in /etc/modprobe.conf" state_operator="AND">
      <ind:object object_ref="oval:ssg-obj_kernmod_usb-storage_modprobeconf:obj:1" />
    </ind:textfilecontent54_test>
    <unix:file_test id="oval:ssg-test_file_permissionspermissions_local_var_log_0:tst:1" version="3" check="all" comment="Testing mode of /var/log/" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_permissionspermissions_local_var_log_0:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_groupownerroot_permissions_syslibrary_files_0:tst:1" version="1" check="all" comment="Testing group ownership of /lib/" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_groupownerroot_permissions_syslibrary_files_0:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_groupownerroot_permissions_syslibrary_files_1:tst:1" version="1" check="all" comment="Testing group ownership of /lib64/" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_groupownerroot_permissions_syslibrary_files_1:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_groupownerroot_permissions_syslibrary_files_2:tst:1" version="1" check="all" comment="Testing group ownership of /usr/lib/" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_groupownerroot_permissions_syslibrary_files_2:obj:1" />
    </unix:file_test>
    <unix:file_test id="oval:ssg-test_file_groupownerroot_permissions_syslibrary_files_3:tst:1" version="1" check="all" comment="Testing group ownership of /usr/lib64/" check_existence="none_exist" state_operator="AND">
      <unix:object object_ref="oval:ssg-object_file_groupownerroot_permissions_syslibrary_files_3:obj:1" />
    </unix:file_test>
    <linux:systemdunitdependency_test id="oval:ssg-test_multi_user_wants_auditd:tst:1" version="1" check="all" comment="systemd test" check_existence="any_exist" state_operator="AND">
      <linux:object object_ref="oval:ssg-object_multi_user_target_for_auditd_enabled:obj:1" />
      <linux:state state_ref="oval:ssg-state_systemd_auditd_on:ste:1" />
    </linux:systemdunitdependency_test>
    <linux:systemdunitdependency_test id="oval:ssg-test_multi_user_wants_auditd_socket:tst:1" version="1" check="all" comment="systemd test" check_existence="any_exist" state_operator="AND">
      <linux:object object_ref="oval:ssg-object_multi_user_target_for_auditd_socket_enabled:obj:1" />
      <linux:state state_ref="oval:ssg-state_systemd_auditd_socket_on:ste:1" />
    </linux:systemdunitdependency_test>
    <linux:systemdunitproperty_test id="oval:ssg-test_service_running_auditd:tst:1" version="1" check="at least one" comment="Test that the auditd service is running" state_operator="AND">
      <linux:object object_ref="oval:ssg-obj_service_running_auditd:obj:1" />
      <linux:state state_ref="oval:ssg-state_service_running_auditd:ste:1" />
    </linux:systemdunitproperty_test>
    <linux:dpkginfo_test id="oval:ssg-test_service_auditd_package_audit_installed:tst:1" version="1" check="all" comment="package audit is installed" check_existence="all_exist" state_operator="AND">
      <linux:object object_ref="oval:ssg-obj_test_service_auditd_package_audit_installed:obj:1" />
    </linux:dpkginfo_test>
    <linux:systemdunitdependency_test id="oval:ssg-test_multi_user_wants_rsyslog:tst:1" version="1" check="all" comment="systemd test" check_existence="any_exist" state_operator="AND">
      <linux:object object_ref="oval:ssg-object_multi_user_target_for_rsyslog_enabled:obj:1" />
      <linux:state state_ref="oval:ssg-state_systemd_rsyslog_on:ste:1" />
    </linux:systemdunitdependency_test>
    <linux:systemdunitdependency_test id="oval:ssg-test_multi_user_wants_rsyslog_socket:tst:1" version="1" check="all" comment="systemd test" check_existence="any_exist" state_operator="AND">
      <linux:object object_ref="oval:ssg-object_multi_user_target_for_rsyslog_socket_enabled:obj:1" />
      <linux:state state_ref="oval:ssg-state_systemd_rsyslog_socket_on:ste:1" />
    </linux:systemdunitdependency_test>
    <linux:systemdunitproperty_test id="oval:ssg-test_service_running_rsyslog:tst:1" version="1" check="at least one" comment="Test that the rsyslog service is running" state_operator="AND">
      <linux:object object_ref="oval:ssg-obj_service_running_rsyslog:obj:1" />
      <linux:state state_ref="oval:ssg-state_service_running_rsyslog:ste:1" />
    </linux:systemdunitproperty_test>
    <linux:dpkginfo_test id="oval:ssg-test_service_rsyslog_package_rsyslog_installed:tst:1" version="1" check="all" comment="package rsyslog is installed" check_existence="all_exist" state_operator="AND">
      <linux:object object_ref="oval:ssg-obj_test_service_rsyslog_package_rsyslog_installed:obj:1" />
    </linux:dpkginfo_test>
    <linux:systemdunitdependency_test id="oval:ssg-test_multi_user_wants_sshd:tst:1" version="1" check="all" comment="systemd test" check_existence="any_exist" state_operator="AND">
      <linux:object object_ref="oval:ssg-object_multi_user_target_for_sshd_enabled:obj:1" />
      <linux:state state_ref="oval:ssg-state_systemd_sshd_on:ste:1" />
    </linux:systemdunitdependency_test>
    <linux:systemdunitdependency_test id="oval:ssg-test_multi_user_wants_sshd_socket:tst:1" version="1" check="all" comment="systemd test" check_existence="any_exist" state_operator="AND">
      <linux:object object_ref="oval:ssg-object_multi_user_target_for_sshd_socket_enabled:obj:1" />
      <linux:state state_ref="oval:ssg-state_systemd_sshd_socket_on:ste:1" />
    </linux:systemdunitdependency_test>
    <linux:systemdunitproperty_test id="oval:ssg-test_service_running_sshd:tst:1" version="1" check="at least one" comment="Test that the sshd service is running" state_operator="AND">
      <linux:object object_ref="oval:ssg-obj_service_running_sshd:obj:1" />
      <linux:state state_ref="oval:ssg-state_service_running_sshd:ste:1" />
    </linux:systemdunitproperty_test>
    <linux:dpkginfo_test id="oval:ssg-test_service_sshd_package_openssh-server_installed:tst:1" version="1" check="all" comment="package openssh-server is installed" check_existence="all_exist" state_operator="AND">
      <linux:object object_ref="oval:ssg-obj_test_service_sshd_package_openssh-server_installed:obj:1" />
    </linux:dpkginfo_test>
    <linux:systemdunitdependency_test id="oval:ssg-test_multi_user_wants_sssd:tst:1" version="1" check="all" comment="systemd test" check_existence="any_exist" state_operator="AND">
      <linux:object object_ref="oval:ssg-object_multi_user_target_for_sssd_enabled:obj:1" />
      <linux:state state_ref="oval:ssg-state_systemd_sssd_on:ste:1" />
    </linux:systemdunitdependency_test>
    <linux:systemdunitdependency_test id="oval:ssg-test_multi_user_wants_sssd_socket:tst:1" version="1" check="all" comment="systemd test" check_existence="any_exist" state_operator="AND">
      <linux:object object_ref="oval:ssg-object_multi_user_target_for_sssd_socket_enabled:obj:1" />
      <linux:state state_ref="oval:ssg-state_systemd_sssd_socket_on:ste:1" />
    </linux:systemdunitdependency_test>
    <linux:systemdunitproperty_test id="oval:ssg-test_service_running_sssd:tst:1" version="1" check="at least one" comment="Test that the sssd service is running" state_operator="AND">
      <linux:object object_ref="oval:ssg-obj_service_running_sssd:obj:1" />
      <linux:state state_ref="oval:ssg-state_service_running_sssd:ste:1" />
    </linux:systemdunitproperty_test>
    <linux:dpkginfo_test id="oval:ssg-test_service_sssd_package_sssd-common_installed:tst:1" version="1" check="all" comment="package sssd-common is installed" check_existence="all_exist" state_operator="AND">
      <linux:object object_ref="oval:ssg-obj_test_service_sssd_package_sssd-common_installed:obj:1" />
    </linux:dpkginfo_test>
    <linux:systemdunitdependency_test id="oval:ssg-test_multi_user_wants_ufw:tst:1" version="1" check="all" comment="systemd test" check_existence="any_exist" state_operator="AND">
      <linux:object object_ref="oval:ssg-object_multi_user_target_for_ufw_enabled:obj:1" />
      <linux:state state_ref="oval:ssg-state_systemd_ufw_on:ste:1" />
    </linux:systemdunitdependency_test>
    <linux:systemdunitdependency_test id="oval:ssg-test_multi_user_wants_ufw_socket:tst:1" version="1" check="all" comment="systemd test" check_existence="any_exist" state_operator="AND">
      <linux:object object_ref="oval:ssg-object_multi_user_target_for_ufw_socket_enabled:obj:1" />
      <linux:state state_ref="oval:ssg-state_systemd_ufw_socket_on:ste:1" />
    </linux:systemdunitdependency_test>
    <linux:systemdunitproperty_test id="oval:ssg-test_service_running_ufw:tst:1" version="1" check="at least one" comment="Test that the ufw service is running" state_operator="AND">
      <linux:object object_ref="oval:ssg-obj_service_running_ufw:obj:1" />
      <linux:state state_ref="oval:ssg-state_service_running_ufw:ste:1" />
    </linux:systemdunitproperty_test>
    <linux:dpkginfo_test id="oval:ssg-test_service_ufw_package_ufw_installed:tst:1" version="1" check="all" comment="package ufw is installed" check_existence="all_exist" state_operator="AND">
      <linux:object object_ref="oval:ssg-obj_test_service_ufw_package_ufw_installed:obj:1" />
    </linux:dpkginfo_test>
    <unix:sysctl_test id="oval:ssg-test_sysctl_kernel_dmesg_restrict_runtime:tst:1" version="1" check="all" comment="kernel runtime parameter kernel.dmesg_restrict set to 1" check_existence="all_exist" state_operator="OR">
      <unix:object object_ref="oval:ssg-object_sysctl_kernel_dmesg_restrict_runtime:obj:1" />
      <unix:state state_ref="oval:ssg-state_sysctl_kernel_dmesg_restrict_runtime:ste:1" />
    </unix:sysctl_test>
    <ind:textfilecontent54_test id="oval:ssg-test_sysctl_kernel_dmesg_restrict_static_user_missing:tst:1" version="1" check="all" comment="kernel.dmesg_restrict static configuration" check_existence="none_exist" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_static_user_sysctl_kernel_dmesg_restrict:obj:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_sysctl_kernel_dmesg_restrict_static_user:tst:1" version="1" check="all" comment="kernel.dmesg_restrict static configuration" check_existence="all_exist" state_operator="OR">
      <ind:object object_ref="oval:ssg-object_static_user_sysctl_kernel_dmesg_restrict:obj:1" />
      <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_kernel_dmesg_restrict:ste:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_sysctl_kernel_dmesg_restrict_static_pkg_correct:tst:1" version="2" check="all" comment="kernel.dmesg_restrict static configuration in /usr/lib/sysctl.d/*.conf" check_existence="all_exist" state_operator="OR">
      <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_kernel_dmesg_restrict:obj:1" />
      <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_kernel_dmesg_restrict:ste:1" />
    </ind:textfilecontent54_test>
    <unix:sysctl_test id="oval:ssg-test_sysctl_kernel_randomize_va_space_runtime:tst:1" version="1" check="all" comment="kernel runtime parameter kernel.randomize_va_space set to 2" check_existence="all_exist" state_operator="OR">
      <unix:object object_ref="oval:ssg-object_sysctl_kernel_randomize_va_space_runtime:obj:1" />
      <unix:state state_ref="oval:ssg-state_sysctl_kernel_randomize_va_space_runtime:ste:1" />
    </unix:sysctl_test>
    <ind:textfilecontent54_test id="oval:ssg-test_sysctl_kernel_randomize_va_space_static_user_missing:tst:1" version="1" check="all" comment="kernel.randomize_va_space static configuration" check_existence="none_exist" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_static_user_sysctl_kernel_randomize_va_space:obj:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_sysctl_kernel_randomize_va_space_static_user:tst:1" version="1" check="all" comment="kernel.randomize_va_space static configuration" check_existence="all_exist" state_operator="OR">
      <ind:object object_ref="oval:ssg-object_static_user_sysctl_kernel_randomize_va_space:obj:1" />
      <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_kernel_randomize_va_space:ste:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_sysctl_kernel_randomize_va_space_static_pkg_correct:tst:1" version="2" check="all" comment="kernel.randomize_va_space static configuration in /usr/lib/sysctl.d/*.conf" check_existence="all_exist" state_operator="OR">
      <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_kernel_randomize_va_space:obj:1" />
      <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_kernel_randomize_va_space:ste:1" />
    </ind:textfilecontent54_test>
    <unix:sysctl_test id="oval:ssg-test_sysctl_net_ipv4_tcp_syncookies_runtime:tst:1" version="1" check="all" comment="kernel runtime parameter net.ipv4.tcp_syncookies set to the appropriate value" check_existence="all_exist" state_operator="OR">
      <unix:object object_ref="oval:ssg-object_sysctl_net_ipv4_tcp_syncookies_runtime:obj:1" />
      <unix:state state_ref="oval:ssg-state_sysctl_net_ipv4_tcp_syncookies_runtime:ste:1" />
    </unix:sysctl_test>
    <ind:textfilecontent54_test id="oval:ssg-test_sysctl_net_ipv4_tcp_syncookies_static_user_missing:tst:1" version="1" check="all" comment="net.ipv4.tcp_syncookies static configuration" check_existence="none_exist" state_operator="AND">
      <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv4_tcp_syncookies:obj:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_sysctl_net_ipv4_tcp_syncookies_static_user:tst:1" version="1" check="all" comment="net.ipv4.tcp_syncookies static configuration" check_existence="all_exist" state_operator="OR">
      <ind:object object_ref="oval:ssg-object_static_user_sysctl_net_ipv4_tcp_syncookies:obj:1" />
      <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv4_tcp_syncookies:ste:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_sysctl_net_ipv4_tcp_syncookies_static_pkg_correct:tst:1" version="2" check="all" comment="net.ipv4.tcp_syncookies static configuration in /usr/lib/sysctl.d/*.conf" check_existence="all_exist" state_operator="OR">
      <ind:object object_ref="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv4_tcp_syncookies:obj:1" />
      <ind:state state_ref="oval:ssg-state_static_sysctld_sysctl_net_ipv4_tcp_syncookies:ste:1" />
    </ind:textfilecontent54_test>
    <ind:textfilecontent54_test id="oval:ssg-test_verify_use_mappers:tst:1" version="1" check="all" comment="tests the presence of 'use_mappers = pwent' setting in the /etc/pam_pkcs11/pam_pkcs11.conf file" state_operator="AND">
      <ind:object object_ref="oval:ssg-obj_verify_use_mappers:obj:1" />
    </ind:textfilecontent54_test>
  </oval-def:tests>
  <oval-def:objects>
    <ind:textfilecontent54_object id="oval:ssg-object_auditd_audispd_configure_remote_server:obj:1" version="1">
      <ind:filepath>/etc/audit/audisp-remote.conf</ind:filepath>
      <ind:pattern operation="pattern match">^[ ]*(?i)remote_server(?-i)[ ]+=[ ]+(\S+)[ ]*$</ind:pattern>
      <ind:instance datatype="int">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_auditd_data_disk_full_action:obj:1" version="3">
      <ind:filepath>/etc/audit/auditd.conf</ind:filepath>
      <ind:pattern operation="pattern match">^[ ]*disk_full_action[ ]+=[ ]+(\S+)[ ]*$</ind:pattern>
      <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_auditd_data_retention_action_mail_acct:obj:1" version="2">
      <ind:filepath>/etc/audit/auditd.conf</ind:filepath>
      <ind:pattern operation="pattern match">^[ ]*action_mail_acct[ ]+=[ ]+(\S+)[ ]*$</ind:pattern>
      <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_auditd_data_retention_space_left_action:obj:1" version="2">
      <ind:filepath>/etc/audit/auditd.conf</ind:filepath>
      <ind:pattern operation="pattern match">^[ ]*space_left_action[ ]+=[ ]+(\S+)[ ]*$</ind:pattern>
      <ind:instance datatype="int">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_auditd_data_retention_space_left_percentage:obj:1" version="2">
      <ind:filepath>/etc/audit/auditd.conf</ind:filepath>
      <ind:pattern operation="pattern match">^[\s]*space_left[\s]+=[\s]+(\d+)%[\s]*$</ind:pattern>
      <ind:instance datatype="int">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_etc_cron_weekly_audit_offload_exists:obj:1" version="1" comment="/etc/cron.weekly/audit-offload file exists">
      <ind:filepath>/etc/cron.weekly/audit-offload</ind:filepath>
      <ind:pattern operation="pattern match">^.*$</ind:pattern>
      <ind:instance datatype="int">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-obj_apt_conf_disallow_unauthenticated:obj:1" version="1">
      <ind:filepath operation="pattern match">/etc/apt/apt.conf(\.d/.*)?$</ind:filepath>
      <ind:pattern operation="pattern match">^[^#]*(?i)AllowUnauthenticated(?-i)(.*)$</ind:pattern>
      <ind:instance datatype="int">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-obj_ntp_set_maxpoll:obj:1" version="1">
      <ind:filepath>/etc/ntp.conf</ind:filepath>
      <ind:pattern operation="pattern match">^server[\s]+[\S]+.*maxpoll[\s]+(\d+)</ind:pattern>
      <ind:instance operation="greater than or equal" datatype="int">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-obj_chrony_set_maxpoll:obj:1" version="1">
      <ind:filepath operation="pattern match">^(/etc/chrony/chrony\.conf|/etc/chrony/conf\.d/.+\.conf)$</ind:filepath>
      <ind:pattern operation="pattern match">^(?:server|pool|peer)[\s]+[\S]+.*maxpoll[\s]+(\d+)</ind:pattern>
      <ind:instance operation="greater than or equal" datatype="int">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-obj_ntp_all_server_has_maxpoll:obj:1" version="1">
      <ind:filepath>/etc/ntp.conf</ind:filepath>
      <ind:pattern operation="pattern match">^server[\s]+[\S]+[\s]+(.*)</ind:pattern>
      <ind:instance operation="greater than or equal" datatype="int">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-obj_chrony_all_server_has_maxpoll:obj:1" version="1">
      <ind:filepath operation="pattern match">^(/etc/chrony/chrony\.conf|/etc/chrony/conf\.d/.+\.conf)$</ind:filepath>
      <ind:pattern operation="pattern match">^(?:server|pool|peer)[\s]+[\S]+[\s]+(.*)</ind:pattern>
      <ind:instance operation="greater than or equal" datatype="int">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-obj_sssd_certification_path_trust_anchor:obj:1" version="1">
      <ind:filepath operation="pattern match">^/etc/sssd/sssd.conf$</ind:filepath>
      <ind:pattern operation="pattern match">^[\s]*\[domain\/.*](?:[^\n\[]*\n+)+?[\s]*certificate_verification\s*=\s*([\w,]+)$</ind:pattern>
      <ind:instance operation="greater than or equal" datatype="int">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-obj_sssd_enable_pam_services:obj:1" version="1">
      <ind:filepath operation="pattern match">^/etc/sssd/(sssd|conf\.d/.*)\.conf$</ind:filepath>
      <ind:pattern operation="pattern match">^\s*\[sssd\].*(?:\n\s*[^[\s].*)*\n\s*services[ \t]*=[ \t]*(.*)$</ind:pattern>
      <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-obj_sssd_enable_smartcards:obj:1" version="2">
      <ind:filepath operation="pattern match">/etc/sssd/(sssd\.conf|conf.d/[^/]+\.conf)</ind:filepath>
      <ind:pattern operation="pattern match">^[\s]*\[pam](?:[^\n\[]*\n+)+?[\s]*pam_cert_auth[\s]*=[\s]*(\w+)\s*$</ind:pattern>
      <ind:instance datatype="int">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-obj_sssd_enable_user_cert:obj:1" version="1">
      <ind:filepath>/etc/sssd/sssd.conf</ind:filepath>
      <ind:pattern operation="pattern match">^[\s]*\[[^\n\[\]]+\](?:[^\n\[]*\n+)+?[\s]*ldap_user_certificate\s*=\s*([\w;]+)$</ind:pattern>
      <ind:instance operation="greater than or equal" datatype="int">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-obj_sssd_offline_cred_expiration:obj:1" version="1">
      <ind:filepath operation="pattern match">^\/etc\/sssd\/(sssd.conf|conf\.d\/.+\.conf)$</ind:filepath>
      <ind:pattern operation="pattern match">^[\s]*\[pam](?:[^\n\[]*\n+)+?[\s]*offline_credentials_expiration[\s]*=[\s]*(\d+)\s*(?:#.*)?$</ind:pattern>
      <ind:instance datatype="int">1</ind:instance>
    </ind:textfilecontent54_object>
    <unix:symlink_object id="oval:ssg-object_pam_fingerprint_symlinked_to_authselect:obj:1" version="1" comment="see the test comment">
      <unix:filepath>/etc/pam.d/fingerprint-auth</unix:filepath>
    </unix:symlink_object>
    <unix:symlink_object id="oval:ssg-object_pam_password_symlinked_to_authselect:obj:1" version="1" comment="see the test comment">
      <unix:filepath>/etc/pam.d/password-auth</unix:filepath>
    </unix:symlink_object>
    <unix:symlink_object id="oval:ssg-object_pam_postlogin_symlinked_to_authselect:obj:1" version="1" comment="see the test comment">
      <unix:filepath>/etc/pam.d/postlogin</unix:filepath>
    </unix:symlink_object>
    <unix:symlink_object id="oval:ssg-object_pam_smartcard_symlinked_to_authselect:obj:1" version="1" comment="see the test comment">
      <unix:filepath>/etc/pam.d/smartcard-auth</unix:filepath>
    </unix:symlink_object>
    <unix:symlink_object id="oval:ssg-object_pam_system_symlinked_to_authselect:obj:1" version="1" comment="see the test comment">
      <unix:filepath>/etc/pam.d/system-auth</unix:filepath>
    </unix:symlink_object>
    <ind:textfilecontent54_object id="oval:ssg-object_banner_etc_issue_net:obj:1" version="1">
      <ind:behaviors singleline="true" multiline="false" />
      <ind:filepath operation="pattern match">^/etc/issue\.net$</ind:filepath>
      <ind:pattern operation="pattern match">^(.*)$</ind:pattern>
      <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-obj_all_pam_faillock_audit_parameter_system_auth:obj:1" version="1" comment="Get the pam_faillock.so preauth audit parameter from system-auth file">
      <ind:filepath>/etc/pam.d/system-auth</ind:filepath>
      <ind:pattern operation="pattern match" var_ref="oval:ssg-var_pam_faillock_audit_parameter_regex:var:1" />
      <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-obj_all_pam_faillock_audit_parameter_password_auth:obj:1" version="1" comment="Get the pam_faillock.so preauth audit parameter from system-auth file">
      <ind:filepath>/etc/pam.d/password-auth</ind:filepath>
      <ind:pattern operation="pattern match" var_ref="oval:ssg-var_pam_faillock_audit_parameter_regex:var:1" />
      <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_pam_faillock_audit_parameter_faillock_conf:obj:1" version="1" comment="Check the expected pam_faillock.so audit parameter in /etc/security/faillock.conf">
      <ind:filepath>/etc/security/faillock.conf</ind:filepath>
      <ind:pattern operation="pattern match">^\s*audit</ind:pattern>
      <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-obj_all_pam_faillock_silent_parameter_system_auth:obj:1" version="1" comment="Get the pam_faillock.so preauth silent parameter from system-auth file">
      <ind:filepath>/etc/pam.d/system-auth</ind:filepath>
      <ind:pattern operation="pattern match" var_ref="oval:ssg-var_pam_faillock_silent_parameter_regex:var:1" />
      <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-obj_all_pam_faillock_silent_parameter_password_auth:obj:1" version="1" comment="Get the pam_faillock.so preauth silent parameter from system-auth file">
      <ind:filepath>/etc/pam.d/password-auth</ind:filepath>
      <ind:pattern operation="pattern match" var_ref="oval:ssg-var_pam_faillock_silent_parameter_regex:var:1" />
      <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_pam_faillock_silent_parameter_faillock_conf:obj:1" version="1" comment="Check the expected pam_faillock.so silent parameter in /etc/security/faillock.conf">
      <ind:filepath>/etc/security/faillock.conf</ind:filepath>
      <ind:pattern operation="pattern match">^\s*silent</ind:pattern>
      <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-obj_password_pam_pwquality_retry_system_auth:obj:1" version="1">
      <ind:filepath>/etc/pam.d/system-auth</ind:filepath>
      <ind:pattern operation="pattern match">^\s*password\s+(?:(?:required)|(?:requisite))\s+pam_pwquality\.so.*retry=([0-9]*).*$</ind:pattern>
      <ind:instance datatype="int">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-obj_password_pam_pwquality_retry_pwquality_conf:obj:1" version="1">
      <ind:filepath>/etc/security/pwquality.conf</ind:filepath>
      <ind:pattern operation="pattern match">^[\s]*retry[\s]*=[\s]*(\d+)(?:[\s]|$)</ind:pattern>
      <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_pam_unix_hashing_algorithm_commonauth:obj:1" version="1" comment="only one hashing algorithm option for pam_unix.so is found in /etc/pam.d/common-password">
      <ind:filepath>/etc/pam.d/common-password</ind:filepath>
      <ind:pattern operation="pattern match">^[\s]*password[\s]+(?:\[success=\d+\s+default=ignore\])[\s]+pam_unix\.so[\s]+(?!.*\b(sha512|yescrypt|gost_yescrypt|blowfish|sha256|md5|bigcrypt)\b[^#]*\b(sha512|yescrypt|gost_yescrypt|blowfish|sha256|md5|bigcrypt)\b)[^#]*\b(sha512|yescrypt|gost_yescrypt|blowfish|sha256|md5|bigcrypt)\b.*$</ind:pattern>
      <ind:instance datatype="int">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_last_encrypt_method_from_etc_login_defs:obj:1" version="1">
      <ind:behaviors singleline="true" />
      <ind:filepath>/etc/login.defs</ind:filepath>
      <ind:pattern operation="pattern match">.*\n[^#]*(ENCRYPT_METHOD\s+\w+)\s*\n</ind:pattern>
      <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:variable_object id="oval:ssg-object_set_password_hashing_algorithm_logindefs:obj:1" version="1">
      <ind:var_ref>oval:ssg-variable_last_encrypt_method_instance_value:var:1</ind:var_ref>
    </ind:variable_object>
    <unix:symlink_object id="oval:ssg-object_disable_ctrlaltdel_exists:obj:1" version="1" comment="Disable Ctrl-Alt-Del key sequence override exists">
      <unix:filepath>/etc/systemd/system/ctrl-alt-del.target</unix:filepath>
    </unix:symlink_object>
    <ind:textfilecontent54_object id="oval:ssg-object_etc_default_useradd_inactive:obj:1" version="1">
      <ind:filepath>/etc/default/useradd</ind:filepath>
      <ind:pattern operation="pattern match">^\s*INACTIVE\s*=\s*(\d+)\s*$</ind:pattern>
      <ind:instance datatype="int">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_last_pass_max_days_from_etc_login_defs:obj:1" version="1">
      <ind:filepath>/etc/login.defs</ind:filepath>
      <ind:pattern operation="pattern match">^(?:.*\n)*\s*[^#]*(PASS_MAX_DAYS\s+\d+)\s*\n</ind:pattern>
      <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:variable_object id="oval:ssg-object_last_pass_max_days_instance_value:obj:1" version="1">
      <ind:var_ref>oval:ssg-variable_last_pass_max_days_instance_value:var:1</ind:var_ref>
    </ind:variable_object>
    <ind:textfilecontent54_object id="oval:ssg-object_last_pass_min_days_from_etc_login_defs:obj:1" version="1">
      <ind:behaviors singleline="true" />
      <ind:filepath>/etc/login.defs</ind:filepath>
      <ind:pattern operation="pattern match">.*\n[^#]*(PASS_MIN_DAYS\s+\d+)\s*\n</ind:pattern>
      <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:variable_object id="oval:ssg-object_last_pass_min_days_instance_value:obj:1" version="1">
      <ind:var_ref>oval:ssg-variable_last_pass_min_days_instance_value:var:1</ind:var_ref>
    </ind:variable_object>
    <ind:textfilecontent54_object id="oval:ssg-object_password_auth_pam_unix_rounds:obj:1" version="1">
      <ind:filepath operation="pattern match">^/etc/pam.d/password-auth$</ind:filepath>
      <ind:pattern operation="pattern match">^\s*password\s+(?:(?:sufficient)|(?:required))\s+pam_unix\.so[^#]*rounds=([0-9]*).*$</ind:pattern>
      <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_no_empty_passwords:obj:1" version="1">
      <ind:filepath operation="pattern match">^/etc/pam.d/(system|password)-auth$</ind:filepath>
      <ind:pattern operation="pattern match">^[^#]*\bnullok\b.*$</ind:pattern>
      <ind:instance datatype="int">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-obj_no_empty_passwords_etc_shadow:obj:1" version="1">
      <ind:filepath>/etc/shadow</ind:filepath>
      <ind:pattern operation="pattern match">^[^:]+::.*$</ind:pattern>
      <ind:instance datatype="int">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-obj_root_access_locked_etc_shadow:obj:1" version="1">
      <ind:filepath>/etc/shadow</ind:filepath>
      <ind:pattern operation="pattern match">^root:([^:]*):(?:[^:]*:){6}(?:[^:]*)$</ind:pattern>
      <ind:instance datatype="int">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_etc_security_limits_conf_maxlogins:obj:1" version="1">
      <ind:filepath>/etc/security/limits.conf</ind:filepath>
      <ind:pattern operation="pattern match">^[\s]*\*[\s]+(?:(?:hard)|(?:-))[\s]+maxlogins[\s]+(\d+)\s*$</ind:pattern>
      <ind:instance datatype="int">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_etc_security_limitsd_conf_maxlogins:obj:1" version="1">
      <ind:path>/etc/security/limits.d</ind:path>
      <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
      <ind:pattern operation="pattern match">^[\s]*\*[\s]+(?:(?:hard)|(?:-))[\s]+maxlogins[\s]+(\d+)\s*$</ind:pattern>
      <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_etc_security_limitsd_conf_maxlogins_exists:obj:1" version="1">
      <ind:path>/etc/security/limits.d</ind:path>
      <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
      <ind:pattern operation="pattern match">^[\s]*\*[\s]+(?:(?:hard)|(?:-))[\s]+maxlogins</ind:pattern>
      <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_etc_profile_tmout:obj:1" version="3">
      <ind:filepath>/etc/profile</ind:filepath>
      <ind:pattern operation="pattern match">^[\s]*(?:typeset|declare)[\s]+-xr[\s]+TMOUT=([\w$]+).*$</ind:pattern>
      <ind:instance operation="greater than or equal" datatype="int">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_etc_profiled_tmout:obj:1" version="3">
      <ind:path>/etc/profile.d</ind:path>
      <ind:filename operation="pattern match">^.*\.sh$</ind:filename>
      <ind:pattern operation="pattern match">^[\s]*(?:typeset|declare)[\s]+-xr[\s]+TMOUT=([\w$]+).*$</ind:pattern>
      <ind:instance operation="greater than or equal" datatype="int">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_accounts_tmout_all_tmout_instances:obj:1" version="1">
      <oval-def:set>
        <oval-def:object_reference>oval:ssg-object_etc_profile_tmout:obj:1</oval-def:object_reference>
        <oval-def:object_reference>oval:ssg-object_etc_profiled_tmout:obj:1</oval-def:object_reference>
      </oval-def:set>
    </ind:textfilecontent54_object>
    <ind:variable_object id="oval:ssg-object_accounts_tmout_defined:obj:1" version="1">
      <ind:var_ref>oval:ssg-variable_count_of_tmout_instances:var:1</ind:var_ref>
    </ind:variable_object>
    <ind:textfilecontent54_object id="oval:ssg-object_bootloader_superuser:obj:1" version="2">
      <ind:filepath>/boot/grub/grub.cfg</ind:filepath>
      <ind:pattern operation="pattern match">^[\s]*set[\s]+superusers=("?)[a-zA-Z_]+\1$</ind:pattern>
      <ind:instance datatype="int">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_grub2_password_usercfg:obj:1" version="1">
      <ind:filepath>/boot/grub/user.cfg</ind:filepath>
      <ind:pattern operation="pattern match">^[\s]*GRUB2_PASSWORD=grub\.pbkdf2\.sha512.*$</ind:pattern>
      <ind:instance datatype="int">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_grub2_password_grubcfg:obj:1" version="1">
      <ind:filepath>/boot/grub/grub.cfg</ind:filepath>
      <ind:pattern operation="pattern match">^[\s]*password_pbkdf2[\s]+.*[\s]+grub\.pbkdf2\.sha512.*$</ind:pattern>
      <ind:instance datatype="int">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_grub2_uefi_password_usercfg:obj:1" version="1">
      <ind:filepath>/boot/efi/EFI/ubuntu/user.cfg</ind:filepath>
      <ind:pattern operation="pattern match">^[\s]*GRUB2_PASSWORD=grub\.pbkdf2\.sha512.*$</ind:pattern>
      <ind:instance datatype="int">1</ind:instance>
    </ind:textfilecontent54_object>
    <unix:symlink_object id="oval:ssg-object_ensure_rtc_utc_configuration:obj:1" version="1" comment="object_ensure_rtc_utc_configuration">
      <unix:filepath>/etc/localtime</unix:filepath>
    </unix:symlink_object>
    <ind:textfilecontent54_object id="oval:ssg-obj_remote_method_monitoring_auth:obj:1" version="1">
      <ind:filepath operation="pattern match">^/etc/rsyslog\.(conf|d/.+\.conf)$</ind:filepath>
      <ind:pattern operation="pattern match">^[ \t]*(?:(?:\w+,)*auth(?:,\w+)*\.\*|\S+;auth\.\*|auth\.\*;\S+|\S+;auth\.\*;\S+)[ \t]+(?:(?!action\()\S+|action\([^)]*file\s*=\s*["'][^"']+["'][^)]*\))\s*$</ind:pattern>
      <ind:instance datatype="int">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-obj_remote_method_monitoring_authpriv:obj:1" version="1">
      <ind:filepath operation="pattern match">^/etc/rsyslog\.(conf|d/.+\.conf)$</ind:filepath>
      <ind:pattern operation="pattern match">^[ \t]*(?:(?:\w+,)*authpriv(?:,\w+)*\.\*|\S+;authpriv\.\*|authpriv\.\*;\S+|\S+;authpriv\.\*;\S+)[ \t]+(?:(?!action\()\S+|action\([^)]*file\s*=\s*["'][^"']+["'][^)]*\))\s*$</ind:pattern>
      <ind:instance datatype="int">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-obj_remote_method_monitoring_daemon:obj:1" version="1">
      <ind:filepath operation="pattern match">^/etc/rsyslog\.(conf|d/.+\.conf)$</ind:filepath>
      <ind:pattern operation="pattern match">^[ \t]*(?:(?:\w+,)*daemon(?:,\w+)*\.\*|\S+;daemon\.\*|daemon\.\*;\S+|\S+;daemon\.\*;\S+)[ \t]+(?:(?!action\()\S+|action\([^)]*file\s*=\s*["'][^"']+["'][^)]*\))\s*$</ind:pattern>
      <ind:instance datatype="int">1</ind:instance>
    </ind:textfilecontent54_object>
    <unix:interface_object id="oval:ssg-object_active_wifi_interfaces:obj:1" version="1">
      <unix:name operation="pattern match">^wl.*$</unix:name>
    </unix:interface_object>
    <linux:partition_object id="oval:ssg-object_dir_perms_world_writable_sticky_bits_local_partitions:obj:1" version="1">
      <linux:mount_point operation="pattern match">.*</linux:mount_point>
      <oval-def:filter action="include">oval:ssg-state_dir_perms_world_writable_sticky_bits_dev_partitons:ste:1</oval-def:filter>
    </linux:partition_object>
    <unix:file_object id="oval:ssg-object_dir_perms_world_writable_sticky_bits:obj:1" version="1" comment="All world-writable directories without sticky bits">
      <unix:behaviors recurse="directories" recurse_direction="down" max_depth="-1" recurse_file_system="defined" />
      <unix:path operation="equals" var_check="at least one" var_ref="oval:ssg-var_dir_perms_world_writable_sticky_bits_local_mountpoints:var:1" />
      <unix:filename xsi:nil="true" />
      <oval-def:filter action="include">oval:ssg-state_dir_perms_world_writable_sticky_bits:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_groupownership_system_commands_dirs:obj:1" version="1" comment="system commands files">
      <unix:path operation="pattern match">^\/s?bin|^\/usr\/s?bin|^\/usr\/local\/s?bin</unix:path>
      <unix:filename operation="pattern match">^.*$</unix:filename>
      <oval-def:filter action="include">oval:ssg-state_groupowner_system_commands_dirs_not_root_or_system_account:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_groupowner_system_commands_dirs_symlink:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_ownership_binary_directories:obj:1" version="1" comment="binary directories">
      <unix:path operation="pattern match">^\/(|s)bin|^\/usr\/(|local\/)(|s)bin|^\/usr\/libexec</unix:path>
      <unix:filename xsi:nil="true" />
      <oval-def:filter action="include">oval:ssg-state_owner_binaries_not_root:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_ownership_binary_files:obj:1" version="1" comment="binary files">
      <unix:path operation="pattern match">^\/(|s)bin|^\/usr\/(|local\/)(|s)bin|^\/usr\/libexec</unix:path>
      <unix:filename operation="pattern match">^.*$</unix:filename>
      <oval-def:filter action="include">oval:ssg-state_owner_binaries_not_root:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_permissions_binary_files:obj:1" version="1" comment="binary files">
      <unix:path operation="pattern match">^\/(|s)bin|^\/usr\/(|local\/)(|s)bin|^\/usr\/libexec</unix:path>
      <unix:filename operation="pattern match">^.*$</unix:filename>
      <oval-def:filter action="include">oval:ssg-state_perms_binary_files_nogroupwrite_noworldwrite:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_perms_binary_files_symlink:ste:1</oval-def:filter>
    </unix:file_object>
    <ind:textfilecontent54_object id="oval:ssg-obj_NX_cpu_support:obj:1" version="1">
      <ind:filepath>/proc/cpuinfo</ind:filepath>
      <ind:pattern operation="pattern match">^flags[\s]+:.*[\s]+nx[\s]+.*$</ind:pattern>
      <ind:instance datatype="int">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-obj_noexec_cmd_line:obj:1" version="1">
      <ind:filepath>/proc/cmdline</ind:filepath>
      <ind:pattern operation="pattern match">.+noexec[0-9]*=off.+</ind:pattern>
      <ind:instance datatype="int">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-is_fips_mode_enabled_object_whole_file_contents_fips_equal_to_one:obj:1" version="1">
      <ind:behaviors singleline="true" multiline="false" />
      <ind:filepath>/proc/sys/crypto/fips_enabled</ind:filepath>
      <ind:pattern operation="pattern match">^.*$</ind:pattern>
      <ind:instance datatype="int">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_no_authenticate_etc_sudoers:obj:1" version="1">
      <ind:filepath>/etc/sudoers</ind:filepath>
      <ind:pattern operation="pattern match">^(?!#).*[\s]+\!authenticate.*$</ind:pattern>
      <ind:instance datatype="int">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_no_authenticate_etc_sudoers_d:obj:1" version="1">
      <ind:path>/etc/sudoers.d</ind:path>
      <ind:filename operation="pattern match">^.*$</ind:filename>
      <ind:pattern operation="pattern match">^(?!#).*[\s]+\!authenticate.*$</ind:pattern>
      <ind:instance datatype="int">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_nopasswd_etc_sudoers:obj:1" version="1">
      <ind:filepath>/etc/sudoers</ind:filepath>
      <ind:pattern operation="pattern match">^(?!#).*[\s]+NOPASSWD[\s]*\:.*$</ind:pattern>
      <ind:instance datatype="int">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_nopasswd_etc_sudoers_d:obj:1" version="1">
      <ind:path>/etc/sudoers.d</ind:path>
      <ind:filename operation="pattern match">^.*$</ind:filename>
      <ind:pattern operation="pattern match">^(?!#).*[\s]+NOPASSWD[\s]*\:.*$</ind:pattern>
      <ind:instance datatype="int">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_sudoers_cfg_spec_all_users:obj:1" version="1">
      <ind:filepath operation="pattern match">^/etc/sudoers(\.d/.*)?$</ind:filepath>
      <ind:pattern operation="pattern match">^\s*ALL\s+ALL\=\(ALL\)\s+ALL\s*$</ind:pattern>
      <ind:instance datatype="int">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_sudoers_cfg_spec_all_group:obj:1" version="1">
      <ind:filepath operation="pattern match">^/etc/sudoers(\.d/.*)?$</ind:filepath>
      <ind:pattern operation="pattern match">^\s*ALL\s+ALL\=\(ALL\:ALL\)\s+ALL\s*</ind:pattern>
      <ind:instance datatype="int">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_yum_clean_components_post_updating:obj:1" version="1" comment="clean_requirements_on_remove set in /etc/apt/apt.conf">
      <ind:filepath>/etc/apt/apt.conf</ind:filepath>
      <ind:pattern operation="pattern match">^\s*clean_requirements_on_remove\s*=\s*(1|True|yes)\s*$</ind:pattern>
      <ind:instance datatype="int" operation="equals">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-obj_accounts_password_pam_enforcing:obj:1" version="1">
      <ind:filepath>/etc/security/pwquality.conf</ind:filepath>
      <ind:pattern operation="pattern match">^[\s]*enforcing = 1[\s]*$</ind:pattern>
      <ind:instance operation="greater than or equal" datatype="int">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_pam_auth_pam_faildelay_delay:obj:1" version="1" comment="Check delay configuration of PAM pam_faildelay.so module">
      <ind:filepath>/etc/pam.d/common-auth</ind:filepath>
      <ind:pattern operation="pattern match">^\s*auth\s+required\s+pam_faildelay.so.*\sdelay=(-?[a-zA-Z0-9]+)(?:\s+.*)?</ind:pattern>
      <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_accounts_passwords_pam_faillock_deny_system_pam_unix_auth:obj:1" version="2" comment="Get the second and subsequent occurrences of pam_unix.so in auth section of system-auth">
      <ind:filepath>/etc/pam.d/system-auth</ind:filepath>
      <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_deny_pam_unix_regex:var:1" />
      <ind:instance datatype="int" operation="greater than">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_accounts_passwords_pam_faillock_deny_system_pam_faillock_auth:obj:1" version="2" comment="Check common definition of pam_faillock.so in auth section of common-auth">
      <ind:filepath>/etc/pam.d/system-auth</ind:filepath>
      <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_deny_pam_faillock_auth_regex:var:1" />
      <ind:instance datatype="int" operation="equals">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_accounts_passwords_pam_faillock_deny_password_pam_unix_auth:obj:1" version="2" comment="Get the second and subsequent occurrences of pam_unix.so in auth section of password-auth">
      <ind:filepath>/etc/pam.d/password-auth</ind:filepath>
      <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_deny_pam_unix_regex:var:1" />
      <ind:instance datatype="int" operation="greater than">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_accounts_passwords_pam_faillock_deny_password_pam_faillock_auth:obj:1" version="2" comment="Check common definition of pam_faillock.so in auth section of common-auth">
      <ind:filepath>/etc/pam.d/password-auth</ind:filepath>
      <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_deny_pam_faillock_auth_regex:var:1" />
      <ind:instance datatype="int" operation="equals">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_accounts_passwords_pam_faillock_deny_system_pam_faillock_account:obj:1" version="2" comment="Check common definition of pam_faillock.so in account section of system-auth">
      <ind:filepath>/etc/pam.d/system-auth</ind:filepath>
      <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_deny_pam_faillock_account_regex:var:1" />
      <ind:instance datatype="int" operation="equals">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_accounts_passwords_pam_faillock_deny_password_pam_faillock_account:obj:1" version="2" comment="Check common definition of pam_faillock.so in account section of password-auth">
      <ind:filepath>/etc/pam.d/password-auth</ind:filepath>
      <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_deny_pam_faillock_account_regex:var:1" />
      <ind:instance datatype="int" operation="equals">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_accounts_passwords_pam_faillock_deny_parameter_pamd_system:obj:1" version="2" comment="Get the pam_faillock.so deny parameter from system-auth file">
      <ind:filepath>/etc/pam.d/system-auth</ind:filepath>
      <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_deny_pam_faillock_deny_parameter_regex:var:1" />
      <ind:instance datatype="int" operation="equals">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_accounts_passwords_pam_faillock_deny_parameter_pamd_password:obj:1" version="2" comment="Get the pam_faillock.so deny parameter from password-auth file">
      <ind:filepath>/etc/pam.d/password-auth</ind:filepath>
      <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_deny_pam_faillock_deny_parameter_regex:var:1" />
      <ind:instance datatype="int" operation="equals">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_accounts_passwords_pam_faillock_deny_parameter_faillock_conf:obj:1" version="1" comment="Check the expected pam_faillock.so deny parameter in /etc/security/faillock.conf">
      <ind:filepath>/etc/security/faillock.conf</ind:filepath>
      <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_deny_faillock_conf_deny_parameter_regex:var:1" />
      <ind:instance datatype="int" operation="equals">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_accounts_passwords_pam_faillock_fail_interval_system_pam_unix_auth:obj:1" version="2" comment="Get the second and subsequent occurrences of pam_unix.so in auth section of system-auth">
      <ind:filepath>/etc/pam.d/system-auth</ind:filepath>
      <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_fail_interval_pam_unix_regex:var:1" />
      <ind:instance datatype="int" operation="greater than">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_accounts_passwords_pam_faillock_fail_interval_system_pam_faillock_auth:obj:1" version="2" comment="Check common definition of pam_faillock.so in auth section of common-auth">
      <ind:filepath>/etc/pam.d/system-auth</ind:filepath>
      <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_fail_interval_pam_faillock_auth_regex:var:1" />
      <ind:instance datatype="int" operation="equals">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_accounts_passwords_pam_faillock_fail_interval_password_pam_unix_auth:obj:1" version="2" comment="Get the second and subsequent occurrences of pam_unix.so in auth section of password-auth">
      <ind:filepath>/etc/pam.d/password-auth</ind:filepath>
      <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_fail_interval_pam_unix_regex:var:1" />
      <ind:instance datatype="int" operation="greater than">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_accounts_passwords_pam_faillock_fail_interval_password_pam_faillock_auth:obj:1" version="2" comment="Check common definition of pam_faillock.so in auth section of common-auth">
      <ind:filepath>/etc/pam.d/password-auth</ind:filepath>
      <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_fail_interval_pam_faillock_auth_regex:var:1" />
      <ind:instance datatype="int" operation="equals">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_accounts_passwords_pam_faillock_fail_interval_system_pam_faillock_account:obj:1" version="2" comment="Check common definition of pam_faillock.so in account section of system-auth">
      <ind:filepath>/etc/pam.d/system-auth</ind:filepath>
      <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_fail_interval_pam_faillock_account_regex:var:1" />
      <ind:instance datatype="int" operation="equals">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_accounts_passwords_pam_faillock_fail_interval_password_pam_faillock_account:obj:1" version="2" comment="Check common definition of pam_faillock.so in account section of password-auth">
      <ind:filepath>/etc/pam.d/password-auth</ind:filepath>
      <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_fail_interval_pam_faillock_account_regex:var:1" />
      <ind:instance datatype="int" operation="equals">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_accounts_passwords_pam_faillock_fail_interval_parameter_pamd_system:obj:1" version="2" comment="Get the pam_faillock.so fail_interval parameter from system-auth file">
      <ind:filepath>/etc/pam.d/system-auth</ind:filepath>
      <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_fail_interval_pam_faillock_fail_interval_parameter_regex:var:1" />
      <ind:instance datatype="int" operation="equals">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_accounts_passwords_pam_faillock_fail_interval_parameter_pamd_password:obj:1" version="2" comment="Get the pam_faillock.so fail_interval parameter from password-auth file">
      <ind:filepath>/etc/pam.d/password-auth</ind:filepath>
      <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_fail_interval_pam_faillock_fail_interval_parameter_regex:var:1" />
      <ind:instance datatype="int" operation="equals">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_accounts_passwords_pam_faillock_fail_interval_parameter_faillock_conf:obj:1" version="1" comment="Check the expected pam_faillock.so fail_interval parameter in /etc/security/faillock.conf">
      <ind:filepath>/etc/security/faillock.conf</ind:filepath>
      <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_fail_interval_faillock_conf_fail_interval_parameter_regex:var:1" />
      <ind:instance datatype="int" operation="equals">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_accounts_passwords_pam_faillock_unlock_time_system_pam_unix_auth:obj:1" version="2" comment="Get the second and subsequent occurrences of pam_unix.so in auth section of system-auth">
      <ind:filepath>/etc/pam.d/system-auth</ind:filepath>
      <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_unlock_time_pam_unix_regex:var:1" />
      <ind:instance datatype="int" operation="greater than">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_accounts_passwords_pam_faillock_unlock_time_system_pam_faillock_auth:obj:1" version="2" comment="Check common definition of pam_faillock.so in auth section of common-auth">
      <ind:filepath>/etc/pam.d/system-auth</ind:filepath>
      <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_unlock_time_pam_faillock_auth_regex:var:1" />
      <ind:instance datatype="int" operation="equals">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_accounts_passwords_pam_faillock_unlock_time_password_pam_unix_auth:obj:1" version="2" comment="Get the second and subsequent occurrences of pam_unix.so in auth section of password-auth">
      <ind:filepath>/etc/pam.d/password-auth</ind:filepath>
      <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_unlock_time_pam_unix_regex:var:1" />
      <ind:instance datatype="int" operation="greater than">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_accounts_passwords_pam_faillock_unlock_time_password_pam_faillock_auth:obj:1" version="2" comment="Check common definition of pam_faillock.so in auth section of common-auth">
      <ind:filepath>/etc/pam.d/password-auth</ind:filepath>
      <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_unlock_time_pam_faillock_auth_regex:var:1" />
      <ind:instance datatype="int" operation="equals">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_accounts_passwords_pam_faillock_unlock_time_system_pam_faillock_account:obj:1" version="2" comment="Check common definition of pam_faillock.so in account section of system-auth">
      <ind:filepath>/etc/pam.d/system-auth</ind:filepath>
      <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_unlock_time_pam_faillock_account_regex:var:1" />
      <ind:instance datatype="int" operation="equals">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_accounts_passwords_pam_faillock_unlock_time_password_pam_faillock_account:obj:1" version="2" comment="Check common definition of pam_faillock.so in account section of password-auth">
      <ind:filepath>/etc/pam.d/password-auth</ind:filepath>
      <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_unlock_time_pam_faillock_account_regex:var:1" />
      <ind:instance datatype="int" operation="equals">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_accounts_passwords_pam_faillock_unlock_time_parameter_pamd_system:obj:1" version="2" comment="Get the pam_faillock.so unlock_time parameter from system-auth file">
      <ind:filepath>/etc/pam.d/system-auth</ind:filepath>
      <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_unlock_time_pam_faillock_unlock_time_parameter_regex:var:1" />
      <ind:instance datatype="int" operation="equals">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_accounts_passwords_pam_faillock_unlock_time_parameter_pamd_password:obj:1" version="2" comment="Get the pam_faillock.so unlock_time parameter from password-auth file">
      <ind:filepath>/etc/pam.d/password-auth</ind:filepath>
      <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_unlock_time_pam_faillock_unlock_time_parameter_regex:var:1" />
      <ind:instance datatype="int" operation="equals">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_accounts_passwords_pam_faillock_unlock_time_parameter_faillock_conf:obj:1" version="1" comment="Check the expected pam_faillock.so unlock_time parameter in /etc/security/faillock.conf">
      <ind:filepath>/etc/security/faillock.conf</ind:filepath>
      <ind:pattern operation="pattern match" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_unlock_time_faillock_conf_unlock_time_parameter_regex:var:1" />
      <ind:instance datatype="int" operation="equals">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-obj_aide_disable_silentreports:obj:1" version="1">
      <ind:filepath>/etc/default/aide</ind:filepath>
      <ind:pattern operation="pattern match">^\s*SILENTREPORTS=(.+?)[ \t]*(?:$|#)</ind:pattern>
      <ind:instance operation="greater than or equal" datatype="int">1</ind:instance>
    </ind:textfilecontent54_object>
    <unix:file_object id="oval:ssg-obj_aide_disable_silentreports_config_file:obj:1" version="1" comment="The configuration file /etc/default/aide for aide_disable_silentreports">
      <unix:filepath operation="pattern match">^/etc/default/aide</unix:filepath>
    </unix:file_object>
    <linux:systemdunitdependency_object id="oval:ssg-object_multi_user_target_for_apparmor_enabled:obj:1" version="1" comment="list of dependencies of multi-user.target">
      <linux:unit>multi-user.target</linux:unit>
    </linux:systemdunitdependency_object>
    <linux:systemdunitdependency_object id="oval:ssg-object_multi_user_target_for_apparmor_socket_enabled:obj:1" version="1" comment="list of dependencies of multi-user.target">
      <linux:unit>multi-user.target</linux:unit>
    </linux:systemdunitdependency_object>
    <linux:systemdunitproperty_object id="oval:ssg-obj_service_running_apparmor:obj:1" version="1" comment="Retrieve the ActiveState property of apparmor">
      <linux:unit operation="pattern match">^apparmor\.(socket|service)$</linux:unit>
      <linux:property>ActiveState</linux:property>
    </linux:systemdunitproperty_object>
    <linux:dpkginfo_object id="oval:ssg-obj_test_service_apparmor_package_apparmor-parser_installed:obj:1" version="1">
      <linux:name>apparmor-parser</linux:name>
    </linux:dpkginfo_object>
    <ind:textfilecontent54_object id="oval:ssg-obj_chronyd_sync_clock:obj:1" version="1">
      <ind:filepath>/etc/chrony/chrony.conf</ind:filepath>
      <ind:pattern operation="pattern match">^\s*makestep (.+?)[ \t]*(?:$|#)</ind:pattern>
      <ind:instance operation="greater than or equal" datatype="int">1</ind:instance>
    </ind:textfilecontent54_object>
    <unix:file_object id="oval:ssg-obj_chronyd_sync_clock_config_file:obj:1" version="1" comment="The configuration file /etc/chrony/chrony.conf for chronyd_sync_clock">
      <unix:filepath operation="pattern match">^/etc/chrony/chrony.conf</unix:filepath>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_groupownerdir_group_ownership_library_dirs_0:obj:1" version="1" comment="/lib/">
      <unix:behaviors recurse="directories" recurse_direction="down" max_depth="-1" recurse_file_system="local" />
      <unix:path>/lib</unix:path>
      <unix:filename xsi:nil="true" />
      <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_groupownerdir_group_ownership_library_dirs_0_0:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_groupownerdir_group_ownership_library_dirs_1:obj:1" version="1" comment="/lib64/">
      <unix:behaviors recurse="directories" recurse_direction="down" max_depth="-1" recurse_file_system="local" />
      <unix:path>/lib64</unix:path>
      <unix:filename xsi:nil="true" />
      <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_groupownerdir_group_ownership_library_dirs_0_0:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_groupownerdir_group_ownership_library_dirs_2:obj:1" version="1" comment="/usr/lib/">
      <unix:behaviors recurse="directories" recurse_direction="down" max_depth="-1" recurse_file_system="local" />
      <unix:path>/usr/lib</unix:path>
      <unix:filename xsi:nil="true" />
      <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_groupownerdir_group_ownership_library_dirs_0_0:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_groupownerdir_group_ownership_library_dirs_3:obj:1" version="1" comment="/usr/lib64/">
      <unix:behaviors recurse="directories" recurse_direction="down" max_depth="-1" recurse_file_system="local" />
      <unix:path>/usr/lib64</unix:path>
      <unix:filename xsi:nil="true" />
      <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_groupownerdir_group_ownership_library_dirs_0_0:ste:1</oval-def:filter>
    </unix:file_object>
    <ind:textfilecontent54_object id="oval:ssg-object_file_groupownerdir_groupowner_system_journal_systemd-journal_gid_etc:obj:1" version="1" comment="gid of the systemd-journal group (from /etc/group)">
      <ind:filepath>/etc/group</ind:filepath>
      <ind:pattern operation="pattern match">^systemd-journal:\w+:(\w+):.*</ind:pattern>
      <ind:instance datatype="int" operation="equals">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_file_groupownerdir_groupowner_system_journal_systemd-journal_gid_usr:obj:1" version="1" comment="gid of the systemd-journal group (from /usr/lib/group)">
      <ind:filepath>/usr/lib/group</ind:filepath>
      <ind:pattern operation="pattern match">^systemd-journal:\w+:(\w+):.*</ind:pattern>
      <ind:instance datatype="int" operation="equals">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_file_groupownerdir_groupowner_system_journal_systemd-journal_gid:obj:1" version="1" comment="gid of the systemd-journal group (from /etc/group or /usr/lib/group)">
      <oval-def:set>
        <oval-def:object_reference>oval:ssg-object_file_groupownerdir_groupowner_system_journal_systemd-journal_gid_etc:obj:1</oval-def:object_reference>
        <oval-def:object_reference>oval:ssg-object_file_groupownerdir_groupowner_system_journal_systemd-journal_gid_usr:obj:1</oval-def:object_reference>
      </oval-def:set>
    </ind:textfilecontent54_object>
    <unix:file_object id="oval:ssg-object_file_groupownerdir_groupowner_system_journal_0:obj:1" version="1" comment="/run/log/journal/">
      <unix:behaviors recurse="directories" recurse_direction="down" max_depth="-1" recurse_file_system="local" />
      <unix:path>/run/log/journal</unix:path>
      <unix:filename xsi:nil="true" />
      <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_groupownerdir_groupowner_system_journal_0_systemd-journal:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_groupownerdir_groupowner_system_journal_1:obj:1" version="1" comment="/var/log/journal/">
      <unix:behaviors recurse="directories" recurse_direction="down" max_depth="-1" recurse_file_system="local" />
      <unix:path>/var/log/journal</unix:path>
      <unix:filename xsi:nil="true" />
      <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_groupownerdir_groupowner_system_journal_0_systemd-journal:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_groupownerdir_groupownership_binary_dirs_0:obj:1" version="1" comment="/bin/">
      <unix:behaviors recurse="directories" recurse_direction="down" max_depth="-1" recurse_file_system="local" />
      <unix:path>/bin</unix:path>
      <unix:filename xsi:nil="true" />
      <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_groupownerdir_groupownership_binary_dirs_0_0:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_groupownerdir_groupownership_binary_dirs_1:obj:1" version="1" comment="/sbin/">
      <unix:behaviors recurse="directories" recurse_direction="down" max_depth="-1" recurse_file_system="local" />
      <unix:path>/sbin</unix:path>
      <unix:filename xsi:nil="true" />
      <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_groupownerdir_groupownership_binary_dirs_0_0:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_groupownerdir_groupownership_binary_dirs_2:obj:1" version="1" comment="/usr/bin/">
      <unix:behaviors recurse="directories" recurse_direction="down" max_depth="-1" recurse_file_system="local" />
      <unix:path>/usr/bin</unix:path>
      <unix:filename xsi:nil="true" />
      <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_groupownerdir_groupownership_binary_dirs_0_0:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_groupownerdir_groupownership_binary_dirs_3:obj:1" version="1" comment="/usr/sbin/">
      <unix:behaviors recurse="directories" recurse_direction="down" max_depth="-1" recurse_file_system="local" />
      <unix:path>/usr/sbin</unix:path>
      <unix:filename xsi:nil="true" />
      <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_groupownerdir_groupownership_binary_dirs_0_0:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_groupownerdir_groupownership_binary_dirs_4:obj:1" version="1" comment="/usr/local/bin/">
      <unix:behaviors recurse="directories" recurse_direction="down" max_depth="-1" recurse_file_system="local" />
      <unix:path>/usr/local/bin</unix:path>
      <unix:filename xsi:nil="true" />
      <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_groupownerdir_groupownership_binary_dirs_0_0:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_groupownerdir_groupownership_binary_dirs_5:obj:1" version="1" comment="/usr/local/sbin/">
      <unix:behaviors recurse="directories" recurse_direction="down" max_depth="-1" recurse_file_system="local" />
      <unix:path>/usr/local/sbin</unix:path>
      <unix:filename xsi:nil="true" />
      <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_groupownerdir_groupownership_binary_dirs_0_0:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_ownerdir_owner_system_journal_0:obj:1" version="1" comment="/run/log/journal/">
      <unix:behaviors recurse="directories" recurse_direction="down" max_depth="-1" recurse_file_system="local" />
      <unix:path>/run/log/journal</unix:path>
      <unix:filename xsi:nil="true" />
      <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_ownerdir_owner_system_journal_0_0:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_ownerdir_owner_system_journal_1:obj:1" version="1" comment="/var/log/journal/">
      <unix:behaviors recurse="directories" recurse_direction="down" max_depth="-1" recurse_file_system="local" />
      <unix:path>/var/log/journal</unix:path>
      <unix:filename xsi:nil="true" />
      <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_ownerdir_owner_system_journal_0_0:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_ownerdir_ownership_binary_dirs_0:obj:1" version="1" comment="/bin/">
      <unix:behaviors recurse="directories" recurse_direction="down" max_depth="-1" recurse_file_system="local" />
      <unix:path>/bin</unix:path>
      <unix:filename xsi:nil="true" />
      <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_ownerdir_ownership_binary_dirs_0_0:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_ownerdir_ownership_binary_dirs_1:obj:1" version="1" comment="/sbin/">
      <unix:behaviors recurse="directories" recurse_direction="down" max_depth="-1" recurse_file_system="local" />
      <unix:path>/sbin</unix:path>
      <unix:filename xsi:nil="true" />
      <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_ownerdir_ownership_binary_dirs_0_0:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_ownerdir_ownership_binary_dirs_2:obj:1" version="1" comment="/usr/bin/">
      <unix:behaviors recurse="directories" recurse_direction="down" max_depth="-1" recurse_file_system="local" />
      <unix:path>/usr/bin</unix:path>
      <unix:filename xsi:nil="true" />
      <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_ownerdir_ownership_binary_dirs_0_0:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_ownerdir_ownership_binary_dirs_3:obj:1" version="1" comment="/usr/sbin/">
      <unix:behaviors recurse="directories" recurse_direction="down" max_depth="-1" recurse_file_system="local" />
      <unix:path>/usr/sbin</unix:path>
      <unix:filename xsi:nil="true" />
      <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_ownerdir_ownership_binary_dirs_0_0:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_ownerdir_ownership_binary_dirs_4:obj:1" version="1" comment="/usr/local/bin/">
      <unix:behaviors recurse="directories" recurse_direction="down" max_depth="-1" recurse_file_system="local" />
      <unix:path>/usr/local/bin</unix:path>
      <unix:filename xsi:nil="true" />
      <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_ownerdir_ownership_binary_dirs_0_0:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_ownerdir_ownership_binary_dirs_5:obj:1" version="1" comment="/usr/local/sbin/">
      <unix:behaviors recurse="directories" recurse_direction="down" max_depth="-1" recurse_file_system="local" />
      <unix:path>/usr/local/sbin</unix:path>
      <unix:filename xsi:nil="true" />
      <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_ownerdir_ownership_binary_dirs_0_0:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_ownerdir_ownership_library_dirs_0:obj:1" version="1" comment="/lib/">
      <unix:behaviors recurse="directories" recurse_direction="down" max_depth="-1" recurse_file_system="local" />
      <unix:path>/lib</unix:path>
      <unix:filename xsi:nil="true" />
      <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_ownerdir_ownership_library_dirs_0_0:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_ownerdir_ownership_library_dirs_1:obj:1" version="1" comment="/lib64/">
      <unix:behaviors recurse="directories" recurse_direction="down" max_depth="-1" recurse_file_system="local" />
      <unix:path>/lib64</unix:path>
      <unix:filename xsi:nil="true" />
      <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_ownerdir_ownership_library_dirs_0_0:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_ownerdir_ownership_library_dirs_2:obj:1" version="1" comment="/usr/lib/">
      <unix:behaviors recurse="directories" recurse_direction="down" max_depth="-1" recurse_file_system="local" />
      <unix:path>/usr/lib</unix:path>
      <unix:filename xsi:nil="true" />
      <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_ownerdir_ownership_library_dirs_0_0:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_ownerdir_ownership_library_dirs_3:obj:1" version="1" comment="/usr/lib64/">
      <unix:behaviors recurse="directories" recurse_direction="down" max_depth="-1" recurse_file_system="local" />
      <unix:path>/usr/lib64</unix:path>
      <unix:filename xsi:nil="true" />
      <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_ownerdir_ownership_library_dirs_0_0:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_permissionsdir_permissions_binary_dirs_0:obj:1" version="1" comment="/bin/">
      <unix:behaviors recurse="directories" recurse_direction="down" max_depth="-1" recurse_file_system="local" />
      <unix:path>/bin</unix:path>
      <unix:filename xsi:nil="true" />
      <oval-def:filter action="exclude">oval:ssg-exclude_symlinks_dir_permissions_binary_dirs:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_permissionsdir_permissions_binary_dirs_0_mode_0755or_stricter_:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_permissionsdir_permissions_binary_dirs_1:obj:1" version="1" comment="/sbin/">
      <unix:behaviors recurse="directories" recurse_direction="down" max_depth="-1" recurse_file_system="local" />
      <unix:path>/sbin</unix:path>
      <unix:filename xsi:nil="true" />
      <oval-def:filter action="exclude">oval:ssg-exclude_symlinks_dir_permissions_binary_dirs:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_permissionsdir_permissions_binary_dirs_1_mode_0755or_stricter_:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_permissionsdir_permissions_binary_dirs_2:obj:1" version="1" comment="/usr/bin/">
      <unix:behaviors recurse="directories" recurse_direction="down" max_depth="-1" recurse_file_system="local" />
      <unix:path>/usr/bin</unix:path>
      <unix:filename xsi:nil="true" />
      <oval-def:filter action="exclude">oval:ssg-exclude_symlinks_dir_permissions_binary_dirs:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_permissionsdir_permissions_binary_dirs_2_mode_0755or_stricter_:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_permissionsdir_permissions_binary_dirs_3:obj:1" version="1" comment="/usr/sbin/">
      <unix:behaviors recurse="directories" recurse_direction="down" max_depth="-1" recurse_file_system="local" />
      <unix:path>/usr/sbin</unix:path>
      <unix:filename xsi:nil="true" />
      <oval-def:filter action="exclude">oval:ssg-exclude_symlinks_dir_permissions_binary_dirs:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_permissionsdir_permissions_binary_dirs_3_mode_0755or_stricter_:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_permissionsdir_permissions_binary_dirs_4:obj:1" version="1" comment="/usr/local/bin/">
      <unix:behaviors recurse="directories" recurse_direction="down" max_depth="-1" recurse_file_system="local" />
      <unix:path>/usr/local/bin</unix:path>
      <unix:filename xsi:nil="true" />
      <oval-def:filter action="exclude">oval:ssg-exclude_symlinks_dir_permissions_binary_dirs:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_permissionsdir_permissions_binary_dirs_4_mode_0755or_stricter_:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_permissionsdir_permissions_binary_dirs_5:obj:1" version="1" comment="/usr/local/sbin/">
      <unix:behaviors recurse="directories" recurse_direction="down" max_depth="-1" recurse_file_system="local" />
      <unix:path>/usr/local/sbin</unix:path>
      <unix:filename xsi:nil="true" />
      <oval-def:filter action="exclude">oval:ssg-exclude_symlinks_dir_permissions_binary_dirs:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_permissionsdir_permissions_binary_dirs_5_mode_0755or_stricter_:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_permissionsdir_permissions_system_journal_0:obj:1" version="1" comment="/run/log/journal/">
      <unix:behaviors recurse="directories" recurse_direction="down" max_depth="-1" recurse_file_system="local" />
      <unix:path>/run/log/journal</unix:path>
      <unix:filename xsi:nil="true" />
      <oval-def:filter action="exclude">oval:ssg-exclude_symlinks_dir_permissions_system_journal:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_permissionsdir_permissions_system_journal_0_mode_2750or_stricter_:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_permissionsdir_permissions_system_journal_1:obj:1" version="1" comment="/var/log/journal/">
      <unix:behaviors recurse="directories" recurse_direction="down" max_depth="-1" recurse_file_system="local" />
      <unix:path>/var/log/journal</unix:path>
      <unix:filename xsi:nil="true" />
      <oval-def:filter action="exclude">oval:ssg-exclude_symlinks_dir_permissions_system_journal:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_permissionsdir_permissions_system_journal_1_mode_2750or_stricter_:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_groupowner_journalctl_0:obj:1" version="1" comment="/usr/bin/journalctl">
      <unix:filepath>/usr/bin/journalctl</unix:filepath>
      <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_groupowner_journalctl_0_0:ste:1</oval-def:filter>
    </unix:file_object>
    <ind:textfilecontent54_object id="oval:ssg-object_file_groupowner_system_journal_systemd-journal_gid_etc:obj:1" version="1" comment="gid of the systemd-journal group (from /etc/group)">
      <ind:filepath>/etc/group</ind:filepath>
      <ind:pattern operation="pattern match">^systemd-journal:\w+:(\w+):.*</ind:pattern>
      <ind:instance datatype="int" operation="equals">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_file_groupowner_system_journal_systemd-journal_gid_usr:obj:1" version="1" comment="gid of the systemd-journal group (from /usr/lib/group)">
      <ind:filepath>/usr/lib/group</ind:filepath>
      <ind:pattern operation="pattern match">^systemd-journal:\w+:(\w+):.*</ind:pattern>
      <ind:instance datatype="int" operation="equals">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_file_groupowner_system_journal_systemd-journal_gid:obj:1" version="1" comment="gid of the systemd-journal group (from /etc/group or /usr/lib/group)">
      <oval-def:set>
        <oval-def:object_reference>oval:ssg-object_file_groupowner_system_journal_systemd-journal_gid_etc:obj:1</oval-def:object_reference>
        <oval-def:object_reference>oval:ssg-object_file_groupowner_system_journal_systemd-journal_gid_usr:obj:1</oval-def:object_reference>
      </oval-def:set>
    </ind:textfilecontent54_object>
    <unix:file_object id="oval:ssg-object_file_groupowner_system_journal_0:obj:1" version="1" comment="^/var/log/journal/.*/system.journal$">
      <unix:filepath operation="pattern match">^/var/log/journal/.*/system.journal$</unix:filepath>
      <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_groupowner_system_journal_0_systemd-journal:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_groupowner_var_log_0:obj:1" version="1" comment="/var/log/">
      <unix:path>/var/log</unix:path>
      <unix:filename xsi:nil="true" />
      <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_groupowner_var_log_0_0:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_groupowner_var_log_syslog_0:obj:1" version="1" comment="/var/log/syslog">
      <unix:filepath>/var/log/syslog</unix:filepath>
      <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_groupowner_var_log_syslog_0_4:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_groupownership_audit_configuration_0:obj:1" version="1" comment="/etc/audit/">
      <unix:path>/etc/audit</unix:path>
      <unix:filename operation="pattern match">^.*audit(\.rules|d\.conf)$</unix:filename>
      <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_groupownership_audit_configuration_0_0:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_groupownership_audit_configuration_1:obj:1" version="1" comment="/etc/audit/rules.d/">
      <unix:path>/etc/audit/rules.d</unix:path>
      <unix:filename operation="pattern match">^.*\.rules$</unix:filename>
      <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_groupownership_audit_configuration_0_0:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_owner_journalctl_0:obj:1" version="1" comment="/usr/bin/journalctl">
      <unix:filepath>/usr/bin/journalctl</unix:filepath>
      <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_owner_journalctl_0_0:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_owner_system_journal_0:obj:1" version="1" comment="^/var/log/journal/.*/system.journal$">
      <unix:filepath operation="pattern match">^/var/log/journal/.*/system.journal$</unix:filepath>
      <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_owner_system_journal_0_0:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_owner_var_log_0:obj:1" version="1" comment="/var/log/">
      <unix:path>/var/log</unix:path>
      <unix:filename xsi:nil="true" />
      <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_owner_var_log_0_0:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:password_object id="oval:ssg-object_file_owner_var_log_syslog_syslog_uid:obj:1" version="1">
      <unix:username operation="equals">syslog</unix:username>
    </unix:password_object>
    <unix:file_object id="oval:ssg-object_file_owner_var_log_syslog_0:obj:1" version="1" comment="/var/log/syslog">
      <unix:filepath>/var/log/syslog</unix:filepath>
      <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_owner_var_log_syslog_0_syslog:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_ownership_audit_binaries_0:obj:1" version="1" comment="/sbin/auditctl">
      <unix:filepath>/sbin/auditctl</unix:filepath>
      <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_ownership_audit_binaries_0_0:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_ownership_audit_binaries_1:obj:1" version="1" comment="/sbin/aureport">
      <unix:filepath>/sbin/aureport</unix:filepath>
      <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_ownership_audit_binaries_0_0:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_ownership_audit_binaries_2:obj:1" version="1" comment="/sbin/ausearch">
      <unix:filepath>/sbin/ausearch</unix:filepath>
      <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_ownership_audit_binaries_0_0:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_ownership_audit_binaries_3:obj:1" version="1" comment="/sbin/autrace">
      <unix:filepath>/sbin/autrace</unix:filepath>
      <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_ownership_audit_binaries_0_0:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_ownership_audit_binaries_4:obj:1" version="1" comment="/sbin/auditd">
      <unix:filepath>/sbin/auditd</unix:filepath>
      <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_ownership_audit_binaries_0_0:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_ownership_audit_binaries_5:obj:1" version="1" comment="/sbin/audispd">
      <unix:filepath>/sbin/audispd</unix:filepath>
      <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_ownership_audit_binaries_0_0:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_ownership_audit_binaries_6:obj:1" version="1" comment="/sbin/augenrules">
      <unix:filepath>/sbin/augenrules</unix:filepath>
      <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_ownership_audit_binaries_0_0:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_ownership_audit_configuration_0:obj:1" version="1" comment="/etc/audit/">
      <unix:path>/etc/audit</unix:path>
      <unix:filename operation="pattern match">^.*audit(\.rules|d\.conf)$</unix:filename>
      <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_ownership_audit_configuration_0_0:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_ownership_audit_configuration_1:obj:1" version="1" comment="/etc/audit/rules.d/">
      <unix:path>/etc/audit/rules.d</unix:path>
      <unix:filename operation="pattern match">^.*\.rules$</unix:filename>
      <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_ownership_audit_configuration_0_0:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_ownership_library_dirs_0:obj:1" version="1" comment="/lib/">
      <unix:behaviors recurse="directories" recurse_direction="down" max_depth="-1" recurse_file_system="local" />
      <unix:path>/lib</unix:path>
      <unix:filename operation="pattern match">^.*$</unix:filename>
      <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_ownership_library_dirs_0_0:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_ownership_library_dirs_1:obj:1" version="1" comment="/lib64/">
      <unix:behaviors recurse="directories" recurse_direction="down" max_depth="-1" recurse_file_system="local" />
      <unix:path>/lib64</unix:path>
      <unix:filename operation="pattern match">^.*$</unix:filename>
      <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_ownership_library_dirs_0_0:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_ownership_library_dirs_2:obj:1" version="1" comment="/usr/lib/">
      <unix:behaviors recurse="directories" recurse_direction="down" max_depth="-1" recurse_file_system="local" />
      <unix:path>/usr/lib</unix:path>
      <unix:filename operation="pattern match">^.*$</unix:filename>
      <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_ownership_library_dirs_0_0:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_ownership_library_dirs_3:obj:1" version="1" comment="/usr/lib64/">
      <unix:behaviors recurse="directories" recurse_direction="down" max_depth="-1" recurse_file_system="local" />
      <unix:path>/usr/lib64</unix:path>
      <unix:filename operation="pattern match">^.*$</unix:filename>
      <oval-def:filter action="exclude">oval:ssg-symlink_file_owner:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_ownership_library_dirs_0_0:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_permissions_audit_binaries_0:obj:1" version="1" comment="/sbin/auditctl">
      <unix:filepath>/sbin/auditctl</unix:filepath>
      <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__audit_binaries:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_permissions_audit_binaries_0_mode_0755or_stricter_:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_permissions_audit_binaries_1:obj:1" version="1" comment="/sbin/aureport">
      <unix:filepath>/sbin/aureport</unix:filepath>
      <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__audit_binaries:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_permissions_audit_binaries_1_mode_0755or_stricter_:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_permissions_audit_binaries_2:obj:1" version="1" comment="/sbin/ausearch">
      <unix:filepath>/sbin/ausearch</unix:filepath>
      <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__audit_binaries:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_permissions_audit_binaries_2_mode_0755or_stricter_:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_permissions_audit_binaries_3:obj:1" version="1" comment="/sbin/autrace">
      <unix:filepath>/sbin/autrace</unix:filepath>
      <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__audit_binaries:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_permissions_audit_binaries_3_mode_0755or_stricter_:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_permissions_audit_binaries_4:obj:1" version="1" comment="/sbin/auditd">
      <unix:filepath>/sbin/auditd</unix:filepath>
      <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__audit_binaries:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_permissions_audit_binaries_4_mode_0755or_stricter_:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_permissions_audit_binaries_5:obj:1" version="1" comment="/sbin/audispd">
      <unix:filepath>/sbin/audispd</unix:filepath>
      <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__audit_binaries:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_permissions_audit_binaries_5_mode_0755or_stricter_:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_permissions_audit_binaries_6:obj:1" version="1" comment="/sbin/augenrules">
      <unix:filepath>/sbin/augenrules</unix:filepath>
      <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__audit_binaries:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_permissions_audit_binaries_6_mode_0755or_stricter_:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_permissions_etc_audit_auditd_0:obj:1" version="1" comment="/etc/audit/auditd.conf">
      <unix:filepath>/etc/audit/auditd.conf</unix:filepath>
      <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__etc_audit_auditd:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_permissions_etc_audit_auditd_0_mode_0640or_stricter_:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_permissions_etc_audit_rules_0:obj:1" version="1" comment="/etc/audit/audit.rules">
      <unix:filepath>/etc/audit/audit.rules</unix:filepath>
      <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__etc_audit_rules:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_permissions_etc_audit_rules_0_mode_0640or_stricter_:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_permissions_etc_audit_rulesd_0:obj:1" version="1" comment="/etc/audit/rules.d/">
      <unix:path>/etc/audit/rules.d</unix:path>
      <unix:filename operation="pattern match">^.*rules$</unix:filename>
      <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__etc_audit_rulesd:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_permissions_etc_audit_rulesd_0_mode_0600or_stricter_:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_permissions_journalctl_0:obj:1" version="1" comment="/usr/bin/journalctl">
      <unix:filepath>/usr/bin/journalctl</unix:filepath>
      <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__journalctl:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_permissions_journalctl_0_mode_0740or_stricter_:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_permissions_library_dirs_0:obj:1" version="1" comment="/lib/">
      <unix:behaviors recurse="directories" recurse_direction="down" max_depth="-1" recurse_file_system="local" />
      <unix:path>/lib</unix:path>
      <unix:filename operation="pattern match">^.*$</unix:filename>
      <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__library_dirs:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_permissions_library_dirs_0_mode_7755or_stricter_:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_permissions_library_dirs_1:obj:1" version="1" comment="/lib64/">
      <unix:behaviors recurse="directories" recurse_direction="down" max_depth="-1" recurse_file_system="local" />
      <unix:path>/lib64</unix:path>
      <unix:filename operation="pattern match">^.*$</unix:filename>
      <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__library_dirs:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_permissions_library_dirs_1_mode_7755or_stricter_:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_permissions_library_dirs_2:obj:1" version="1" comment="/usr/lib/">
      <unix:behaviors recurse="directories" recurse_direction="down" max_depth="-1" recurse_file_system="local" />
      <unix:path>/usr/lib</unix:path>
      <unix:filename operation="pattern match">^.*$</unix:filename>
      <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__library_dirs:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_permissions_library_dirs_2_mode_7755or_stricter_:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_permissions_library_dirs_3:obj:1" version="1" comment="/usr/lib64/">
      <unix:behaviors recurse="directories" recurse_direction="down" max_depth="-1" recurse_file_system="local" />
      <unix:path>/usr/lib64</unix:path>
      <unix:filename operation="pattern match">^.*$</unix:filename>
      <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__library_dirs:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_permissions_library_dirs_3_mode_7755or_stricter_:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_permissions_system_journal_0:obj:1" version="1" comment="^/var/log/journal/.*/system.journal$">
      <unix:filepath operation="pattern match">^/var/log/journal/.*/system.journal$</unix:filepath>
      <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__system_journal:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_permissions_system_journal_0_mode_0640or_stricter_:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_permissions_var_log_0:obj:1" version="1" comment="/var/log/">
      <unix:path>/var/log</unix:path>
      <unix:filename xsi:nil="true" />
      <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__var_log:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_permissions_var_log_0_mode_0755or_stricter_:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_permissions_var_log_syslog_0:obj:1" version="1" comment="/var/log/syslog">
      <unix:filepath>/var/log/syslog</unix:filepath>
      <oval-def:filter action="exclude">oval:ssg-exclude_symlinks__var_log_syslog:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_permissions_var_log_syslog_0_mode_0640or_stricter_:ste:1</oval-def:filter>
    </unix:file_object>
    <ind:textfilecontent54_object id="oval:ssg-obj_kernmod_usb-storage_disabled:obj:1" version="1" comment="kernel module usb-storage disabled">
      <ind:path var_ref="oval:ssg-var_kernel_module_usb-storage_paths:var:1" var_check="at least one" />
      <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
      <ind:pattern operation="pattern match">^\s*install\s+usb-storage\s+(/bin/false|/bin/true)$</ind:pattern>
      <ind:instance datatype="int">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-obj_kernmod_usb-storage_modprobeconf:obj:1" version="1" comment="Check deprecated /etc/modprobe.conf for disablement of usb-storage">
      <ind:filepath>/etc/modprobe.conf</ind:filepath>
      <ind:pattern operation="pattern match">^\s*install\s+usb-storage\s+(/bin/false|/bin/true)$</ind:pattern>
      <ind:instance datatype="int">1</ind:instance>
    </ind:textfilecontent54_object>
    <unix:file_object id="oval:ssg-object_file_permissionspermissions_local_var_log_0:obj:1" version="1" comment="/var/log/">
      <unix:path>/var/log</unix:path>
      <unix:filename operation="pattern match">.*</unix:filename>
      <oval-def:filter action="exclude">oval:ssg-exclude_symlinks_permissions_local_var_log:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_permissionspermissions_local_var_log_0_mode_0640or_stricter_:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_groupownerroot_permissions_syslibrary_files_0:obj:1" version="1" comment="/lib/">
      <unix:behaviors recurse="directories" recurse_direction="down" max_depth="-1" recurse_file_system="local" />
      <unix:path>/lib</unix:path>
      <unix:filename operation="pattern match">^.*$</unix:filename>
      <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_groupownerroot_permissions_syslibrary_files_0_0:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_groupownerroot_permissions_syslibrary_files_1:obj:1" version="1" comment="/lib64/">
      <unix:behaviors recurse="directories" recurse_direction="down" max_depth="-1" recurse_file_system="local" />
      <unix:path>/lib64</unix:path>
      <unix:filename operation="pattern match">^.*$</unix:filename>
      <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_groupownerroot_permissions_syslibrary_files_0_0:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_groupownerroot_permissions_syslibrary_files_2:obj:1" version="1" comment="/usr/lib/">
      <unix:behaviors recurse="directories" recurse_direction="down" max_depth="-1" recurse_file_system="local" />
      <unix:path>/usr/lib</unix:path>
      <unix:filename operation="pattern match">^.*$</unix:filename>
      <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_groupownerroot_permissions_syslibrary_files_0_0:ste:1</oval-def:filter>
    </unix:file_object>
    <unix:file_object id="oval:ssg-object_file_groupownerroot_permissions_syslibrary_files_3:obj:1" version="1" comment="/usr/lib64/">
      <unix:behaviors recurse="directories" recurse_direction="down" max_depth="-1" recurse_file_system="local" />
      <unix:path>/usr/lib64</unix:path>
      <unix:filename operation="pattern match">^.*$</unix:filename>
      <oval-def:filter action="exclude">oval:ssg-symlink_file_groupowner:ste:1</oval-def:filter>
      <oval-def:filter action="exclude">oval:ssg-state_file_groupownerroot_permissions_syslibrary_files_0_0:ste:1</oval-def:filter>
    </unix:file_object>
    <linux:systemdunitdependency_object id="oval:ssg-object_multi_user_target_for_auditd_enabled:obj:1" version="1" comment="list of dependencies of multi-user.target">
      <linux:unit>multi-user.target</linux:unit>
    </linux:systemdunitdependency_object>
    <linux:systemdunitdependency_object id="oval:ssg-object_multi_user_target_for_auditd_socket_enabled:obj:1" version="1" comment="list of dependencies of multi-user.target">
      <linux:unit>multi-user.target</linux:unit>
    </linux:systemdunitdependency_object>
    <linux:systemdunitproperty_object id="oval:ssg-obj_service_running_auditd:obj:1" version="1" comment="Retrieve the ActiveState property of auditd">
      <linux:unit operation="pattern match">^auditd\.(socket|service)$</linux:unit>
      <linux:property>ActiveState</linux:property>
    </linux:systemdunitproperty_object>
    <linux:dpkginfo_object id="oval:ssg-obj_test_service_auditd_package_audit_installed:obj:1" version="1">
      <linux:name>audit</linux:name>
    </linux:dpkginfo_object>
    <linux:systemdunitdependency_object id="oval:ssg-object_multi_user_target_for_rsyslog_enabled:obj:1" version="1" comment="list of dependencies of multi-user.target">
      <linux:unit>multi-user.target</linux:unit>
    </linux:systemdunitdependency_object>
    <linux:systemdunitdependency_object id="oval:ssg-object_multi_user_target_for_rsyslog_socket_enabled:obj:1" version="1" comment="list of dependencies of multi-user.target">
      <linux:unit>multi-user.target</linux:unit>
    </linux:systemdunitdependency_object>
    <linux:systemdunitproperty_object id="oval:ssg-obj_service_running_rsyslog:obj:1" version="1" comment="Retrieve the ActiveState property of rsyslog">
      <linux:unit operation="pattern match">^rsyslog\.(socket|service)$</linux:unit>
      <linux:property>ActiveState</linux:property>
    </linux:systemdunitproperty_object>
    <linux:dpkginfo_object id="oval:ssg-obj_test_service_rsyslog_package_rsyslog_installed:obj:1" version="1">
      <linux:name>rsyslog</linux:name>
    </linux:dpkginfo_object>
    <linux:systemdunitdependency_object id="oval:ssg-object_multi_user_target_for_sshd_enabled:obj:1" version="1" comment="list of dependencies of multi-user.target">
      <linux:unit>multi-user.target</linux:unit>
    </linux:systemdunitdependency_object>
    <linux:systemdunitdependency_object id="oval:ssg-object_multi_user_target_for_sshd_socket_enabled:obj:1" version="1" comment="list of dependencies of multi-user.target">
      <linux:unit>multi-user.target</linux:unit>
    </linux:systemdunitdependency_object>
    <linux:systemdunitproperty_object id="oval:ssg-obj_service_running_sshd:obj:1" version="1" comment="Retrieve the ActiveState property of sshd">
      <linux:unit operation="pattern match">^sshd\.(socket|service)$</linux:unit>
      <linux:property>ActiveState</linux:property>
    </linux:systemdunitproperty_object>
    <linux:dpkginfo_object id="oval:ssg-obj_test_service_sshd_package_openssh-server_installed:obj:1" version="1">
      <linux:name>openssh-server</linux:name>
    </linux:dpkginfo_object>
    <linux:systemdunitdependency_object id="oval:ssg-object_multi_user_target_for_sssd_enabled:obj:1" version="1" comment="list of dependencies of multi-user.target">
      <linux:unit>multi-user.target</linux:unit>
    </linux:systemdunitdependency_object>
    <linux:systemdunitdependency_object id="oval:ssg-object_multi_user_target_for_sssd_socket_enabled:obj:1" version="1" comment="list of dependencies of multi-user.target">
      <linux:unit>multi-user.target</linux:unit>
    </linux:systemdunitdependency_object>
    <linux:systemdunitproperty_object id="oval:ssg-obj_service_running_sssd:obj:1" version="1" comment="Retrieve the ActiveState property of sssd">
      <linux:unit operation="pattern match">^sssd\.(socket|service)$</linux:unit>
      <linux:property>ActiveState</linux:property>
    </linux:systemdunitproperty_object>
    <linux:dpkginfo_object id="oval:ssg-obj_test_service_sssd_package_sssd-common_installed:obj:1" version="1">
      <linux:name>sssd-common</linux:name>
    </linux:dpkginfo_object>
    <linux:systemdunitdependency_object id="oval:ssg-object_multi_user_target_for_ufw_enabled:obj:1" version="1" comment="list of dependencies of multi-user.target">
      <linux:unit>multi-user.target</linux:unit>
    </linux:systemdunitdependency_object>
    <linux:systemdunitdependency_object id="oval:ssg-object_multi_user_target_for_ufw_socket_enabled:obj:1" version="1" comment="list of dependencies of multi-user.target">
      <linux:unit>multi-user.target</linux:unit>
    </linux:systemdunitdependency_object>
    <linux:systemdunitproperty_object id="oval:ssg-obj_service_running_ufw:obj:1" version="1" comment="Retrieve the ActiveState property of ufw">
      <linux:unit operation="pattern match">^ufw\.(socket|service)$</linux:unit>
      <linux:property>ActiveState</linux:property>
    </linux:systemdunitproperty_object>
    <linux:dpkginfo_object id="oval:ssg-obj_test_service_ufw_package_ufw_installed:obj:1" version="1">
      <linux:name>ufw</linux:name>
    </linux:dpkginfo_object>
    <unix:sysctl_object id="oval:ssg-object_sysctl_kernel_dmesg_restrict_runtime:obj:1" version="1">
      <unix:name>kernel.dmesg_restrict</unix:name>
    </unix:sysctl_object>
    <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_kernel_dmesg_restrict:obj:1" version="1">
      <oval-def:set>
        <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_kernel_dmesg_restrict:obj:1</oval-def:object_reference>
        <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_kernel_dmesg_restrict:obj:1</oval-def:object_reference>
      </oval-def:set>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_kernel_dmesg_restrict:obj:1" version="1">
      <oval-def:set>
        <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_kernel_dmesg_restrict:obj:1</oval-def:object_reference>
        <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_kernel_dmesg_restrict:obj:1</oval-def:object_reference>
      </oval-def:set>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_kernel_dmesg_restrict:obj:1" version="1">
      <oval-def:set>
        <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_kernel_dmesg_restrict:obj:1</oval-def:object_reference>
        <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_kernel_dmesg_restrict:obj:1</oval-def:object_reference>
      </oval-def:set>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_kernel_dmesg_restrict:obj:1" version="1">
      <oval-def:set>
        <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_kernel_dmesg_restrict:obj:1</oval-def:object_reference>
        <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_kernel_dmesg_restrict:obj:1</oval-def:object_reference>
      </oval-def:set>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_kernel_dmesg_restrict:obj:1" version="1">
      <ind:filepath>/etc/sysctl.conf</ind:filepath>
      <ind:pattern operation="pattern match">^[\s]*kernel.dmesg_restrict[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
      <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_kernel_dmesg_restrict:obj:1" version="1">
      <ind:path>/etc/sysctl.d</ind:path>
      <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
      <ind:pattern operation="pattern match">^[\s]*kernel.dmesg_restrict[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
      <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_kernel_dmesg_restrict:obj:1" version="1">
      <ind:path>/run/sysctl.d</ind:path>
      <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
      <ind:pattern operation="pattern match">^[\s]*kernel.dmesg_restrict[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
      <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_kernel_dmesg_restrict:obj:1" version="1">
      <ind:path>/usr/local/lib/sysctl.d</ind:path>
      <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
      <ind:pattern operation="pattern match">^[\s]*kernel.dmesg_restrict[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
      <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_kernel_dmesg_restrict:obj:1" version="1">
      <ind:path>/usr/lib/sysctl.d</ind:path>
      <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
      <ind:pattern operation="pattern match">^[\s]*kernel.dmesg_restrict[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
      <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_kernel_dmesg_restrict:obj:1" version="1">
      <ind:path>/lib/sysctl.d</ind:path>
      <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
      <ind:pattern operation="pattern match">^[\s]*kernel.dmesg_restrict[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
      <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
    </ind:textfilecontent54_object>
    <unix:sysctl_object id="oval:ssg-object_sysctl_kernel_randomize_va_space_runtime:obj:1" version="1">
      <unix:name>kernel.randomize_va_space</unix:name>
    </unix:sysctl_object>
    <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_kernel_randomize_va_space:obj:1" version="1">
      <oval-def:set>
        <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_kernel_randomize_va_space:obj:1</oval-def:object_reference>
        <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_kernel_randomize_va_space:obj:1</oval-def:object_reference>
      </oval-def:set>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_kernel_randomize_va_space:obj:1" version="1">
      <oval-def:set>
        <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_kernel_randomize_va_space:obj:1</oval-def:object_reference>
        <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_kernel_randomize_va_space:obj:1</oval-def:object_reference>
      </oval-def:set>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_kernel_randomize_va_space:obj:1" version="1">
      <oval-def:set>
        <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_kernel_randomize_va_space:obj:1</oval-def:object_reference>
        <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_kernel_randomize_va_space:obj:1</oval-def:object_reference>
      </oval-def:set>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_kernel_randomize_va_space:obj:1" version="1">
      <oval-def:set>
        <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_kernel_randomize_va_space:obj:1</oval-def:object_reference>
        <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_kernel_randomize_va_space:obj:1</oval-def:object_reference>
      </oval-def:set>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_kernel_randomize_va_space:obj:1" version="1">
      <ind:filepath>/etc/sysctl.conf</ind:filepath>
      <ind:pattern operation="pattern match">^[\s]*kernel.randomize_va_space[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
      <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_kernel_randomize_va_space:obj:1" version="1">
      <ind:path>/etc/sysctl.d</ind:path>
      <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
      <ind:pattern operation="pattern match">^[\s]*kernel.randomize_va_space[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
      <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_kernel_randomize_va_space:obj:1" version="1">
      <ind:path>/run/sysctl.d</ind:path>
      <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
      <ind:pattern operation="pattern match">^[\s]*kernel.randomize_va_space[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
      <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_kernel_randomize_va_space:obj:1" version="1">
      <ind:path>/usr/local/lib/sysctl.d</ind:path>
      <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
      <ind:pattern operation="pattern match">^[\s]*kernel.randomize_va_space[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
      <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_kernel_randomize_va_space:obj:1" version="1">
      <ind:path>/usr/lib/sysctl.d</ind:path>
      <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
      <ind:pattern operation="pattern match">^[\s]*kernel.randomize_va_space[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
      <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_kernel_randomize_va_space:obj:1" version="1">
      <ind:path>/lib/sysctl.d</ind:path>
      <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
      <ind:pattern operation="pattern match">^[\s]*kernel.randomize_va_space[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
      <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
    </ind:textfilecontent54_object>
    <unix:sysctl_object id="oval:ssg-object_sysctl_net_ipv4_tcp_syncookies_runtime:obj:1" version="1">
      <unix:name>net.ipv4.tcp_syncookies</unix:name>
    </unix:sysctl_object>
    <ind:textfilecontent54_object id="oval:ssg-object_static_user_sysctl_net_ipv4_tcp_syncookies:obj:1" version="1">
      <oval-def:set>
        <oval-def:object_reference>oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv4_tcp_syncookies:obj:1</oval-def:object_reference>
        <oval-def:object_reference>oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv4_tcp_syncookies:obj:1</oval-def:object_reference>
      </oval-def:set>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_static_etc_lib_sysctls_sysctl_net_ipv4_tcp_syncookies:obj:1" version="1">
      <oval-def:set>
        <oval-def:object_reference>oval:ssg-object_static_etc_sysctls_sysctl_net_ipv4_tcp_syncookies:obj:1</oval-def:object_reference>
        <oval-def:object_reference>oval:ssg-object_static_lib_sysctld_sysctl_net_ipv4_tcp_syncookies:obj:1</oval-def:object_reference>
      </oval-def:set>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctls_sysctl_net_ipv4_tcp_syncookies:obj:1" version="1">
      <oval-def:set>
        <oval-def:object_reference>oval:ssg-object_static_sysctl_sysctl_net_ipv4_tcp_syncookies:obj:1</oval-def:object_reference>
        <oval-def:object_reference>oval:ssg-object_static_etc_sysctld_sysctl_net_ipv4_tcp_syncookies:obj:1</oval-def:object_reference>
      </oval-def:set>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_static_run_usr_local_sysctls_sysctl_net_ipv4_tcp_syncookies:obj:1" version="1">
      <oval-def:set>
        <oval-def:object_reference>oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv4_tcp_syncookies:obj:1</oval-def:object_reference>
        <oval-def:object_reference>oval:ssg-object_static_run_sysctld_sysctl_net_ipv4_tcp_syncookies:obj:1</oval-def:object_reference>
      </oval-def:set>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_static_sysctl_sysctl_net_ipv4_tcp_syncookies:obj:1" version="1">
      <ind:filepath>/etc/sysctl.conf</ind:filepath>
      <ind:pattern operation="pattern match">^[\s]*net.ipv4.tcp_syncookies[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
      <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_static_etc_sysctld_sysctl_net_ipv4_tcp_syncookies:obj:1" version="1">
      <ind:path>/etc/sysctl.d</ind:path>
      <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
      <ind:pattern operation="pattern match">^[\s]*net.ipv4.tcp_syncookies[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
      <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_static_run_sysctld_sysctl_net_ipv4_tcp_syncookies:obj:1" version="1">
      <ind:path>/run/sysctl.d</ind:path>
      <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
      <ind:pattern operation="pattern match">^[\s]*net.ipv4.tcp_syncookies[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
      <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_static_usr_local_lib_sysctld_sysctl_net_ipv4_tcp_syncookies:obj:1" version="1">
      <ind:path>/usr/local/lib/sysctl.d</ind:path>
      <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
      <ind:pattern operation="pattern match">^[\s]*net.ipv4.tcp_syncookies[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
      <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_static_usr_lib_sysctld_sysctl_net_ipv4_tcp_syncookies:obj:1" version="1">
      <ind:path>/usr/lib/sysctl.d</ind:path>
      <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
      <ind:pattern operation="pattern match">^[\s]*net.ipv4.tcp_syncookies[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
      <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-object_static_lib_sysctld_sysctl_net_ipv4_tcp_syncookies:obj:1" version="1">
      <ind:path>/lib/sysctl.d</ind:path>
      <ind:filename operation="pattern match">^.*\.conf$</ind:filename>
      <ind:pattern operation="pattern match">^[\s]*net.ipv4.tcp_syncookies[\s]*=[\s]*(.*\S)[\s]*$</ind:pattern>
      <ind:instance datatype="int" operation="greater than or equal">1</ind:instance>
    </ind:textfilecontent54_object>
    <ind:textfilecontent54_object id="oval:ssg-obj_verify_use_mappers:obj:1" version="1">
      <ind:filepath>/etc/pam_pkcs11/pam_pkcs11.conf</ind:filepath>
      <ind:pattern operation="pattern match">^[\s]*use_mappers = pwent[\s]*$</ind:pattern>
      <ind:instance operation="greater than or equal" datatype="int">1</ind:instance>
    </ind:textfilecontent54_object>
  </oval-def:objects>
  <oval-def:states>
    <ind:textfilecontent54_state id="oval:ssg-state_auditd_audispd_configure_remote_server:ste:1" version="1" operator="AND">
      <ind:subexpression operation="equals" var_ref="oval:ssg-var_audispd_remote_server:var:1" />
    </ind:textfilecontent54_state>
    <ind:textfilecontent54_state id="oval:ssg-state_auditd_data_disk_full_action:ste:1" version="1" operator="AND">
      <ind:subexpression operation="pattern match" var_ref="oval:ssg-var_auditd_disk_full_action_regex:var:1" />
    </ind:textfilecontent54_state>
    <ind:textfilecontent54_state id="oval:ssg-state_auditd_data_retention_action_mail_acct:ste:1" version="1" operator="AND">
      <ind:subexpression operation="equals" var_ref="oval:ssg-var_auditd_action_mail_acct:var:1" />
    </ind:textfilecontent54_state>
    <ind:textfilecontent54_state id="oval:ssg-state_auditd_data_retention_space_left_action:ste:1" version="2" operator="AND">
      <ind:subexpression operation="pattern match" var_ref="oval:ssg-var_auditd_space_left_action_regex:var:1" />
    </ind:textfilecontent54_state>
    <ind:textfilecontent54_state id="oval:ssg-state_auditd_data_retention_space_left_percentage:ste:1" version="1" operator="AND">
      <ind:subexpression operation="greater than or equal" var_ref="oval:ssg-var_auditd_space_left_percentage:var:1" datatype="int" />
    </ind:textfilecontent54_state>
    <ind:textfilecontent54_state id="oval:ssg-state_apt_conf_disallow_unauthenticated:ste:1" version="1" operator="AND">
      <ind:subexpression datatype="string" operation="pattern match">^[\s]+"false"[\s]*;[\s]*$</ind:subexpression>
    </ind:textfilecontent54_state>
    <ind:textfilecontent54_state id="oval:ssg-state_time_service_set_maxpoll:ste:1" version="1" operator="AND">
      <ind:subexpression operation="less than or equal" var_ref="oval:ssg-var_time_service_set_maxpoll:var:1" datatype="int" />
    </ind:textfilecontent54_state>
    <ind:textfilecontent54_state id="oval:ssg-state_server_has_maxpoll:ste:1" version="1" operator="AND">
      <ind:subexpression operation="pattern match" datatype="string">maxpoll \d+</ind:subexpression>
    </ind:textfilecontent54_state>
    <ind:textfilecontent54_state id="oval:ssg-state_sssd_certification_path_trust_anchor:ste:1" version="1" operator="AND" comment="value of certificate_verification">
      <ind:subexpression operation="equals">ca_cert,ocsp</ind:subexpression>
    </ind:textfilecontent54_state>
    <ind:textfilecontent54_state id="oval:ssg-state_sssd_enable_pam_services:ste:1" version="1" operator="AND">
      <ind:subexpression operation="pattern match">^.*pam.*$</ind:subexpression>
    </ind:textfilecontent54_state>
    <ind:textfilecontent54_state id="oval:ssg-state_sssd_enable_smartcards:ste:1" version="1" operator="AND">
      <ind:subexpression operation="pattern match">(?i)true</ind:subexpression>
    </ind:textfilecontent54_state>
    <ind:textfilecontent54_state id="oval:ssg-state_sssd_enable_user_cert:ste:1" version="1" operator="AND" comment="value of ldap_user_certificate">
      <ind:subexpression operation="equals">userCertificate;binary</ind:subexpression>
    </ind:textfilecontent54_state>
    <ind:textfilecontent54_state id="oval:ssg-state_sssd_offline_cred_expiration:ste:1" version="1" operator="AND">
      <ind:subexpression>1</ind:subexpression>
    </ind:textfilecontent54_state>
    <unix:symlink_state id="oval:ssg-state_pam_fingerprint_symlinked_to_authselect:ste:1" version="1" operator="AND" comment="see the test comment">
      <unix:filepath>/etc/pam.d/fingerprint-auth</unix:filepath>
      <unix:canonical_path>/etc/authselect/fingerprint-auth</unix:canonical_path>
    </unix:symlink_state>
    <unix:symlink_state id="oval:ssg-state_pam_password_symlinked_to_authselect:ste:1" version="1" operator="AND" comment="see the test comment">
      <unix:filepath>/etc/pam.d/password-auth</unix:filepath>
      <unix:canonical_path>/etc/authselect/password-auth</unix:canonical_path>
    </unix:symlink_state>
    <unix:symlink_state id="oval:ssg-state_pam_postlogin_symlinked_to_authselect:ste:1" version="1" operator="AND" comment="see the test comment">
      <unix:filepath>/etc/pam.d/postlogin</unix:filepath>
      <unix:canonical_path>/etc/authselect/postlogin</unix:canonical_path>
    </unix:symlink_state>
    <unix:symlink_state id="oval:ssg-state_pam_smartcard_symlinked_to_authselect:ste:1" version="1" operator="AND" comment="see the test comment">
      <unix:filepath>/etc/pam.d/smartcard-auth</unix:filepath>
      <unix:canonical_path>/etc/authselect/smartcard-auth</unix:canonical_path>
    </unix:symlink_state>
    <unix:symlink_state id="oval:ssg-state_pam_system_symlinked_to_authselect:ste:1" version="1" operator="AND" comment="see the test comment">
      <unix:filepath>/etc/pam.d/system-auth</unix:filepath>
      <unix:canonical_path>/etc/authselect/system-auth</unix:canonical_path>
    </unix:symlink_state>
    <ind:textfilecontent54_state id="oval:ssg-state_banner_etc_issue_net:ste:1" version="1" operator="AND">
      <ind:subexpression datatype="string" operation="pattern match" var_ref="oval:ssg-remote_login_banner_text:var:1" />
    </ind:textfilecontent54_state>
    <ind:textfilecontent54_state id="oval:ssg-state_password_pam_retry_upper_bound:ste:1" version="1" operator="AND" comment="upper bound of password_pam_retry">
      <ind:subexpression datatype="int" operation="less than or equal" var_ref="oval:ssg-var_password_pam_retry:var:1" />
    </ind:textfilecontent54_state>
    <ind:textfilecontent54_state id="oval:ssg-state_password_pam_retry_lower_bound:ste:1" version="1" operator="AND" comment="lower bound of password_pam_retry">
      <ind:subexpression datatype="int" operation="greater than">0</ind:subexpression>
    </ind:textfilecontent54_state>
    <ind:textfilecontent54_state id="oval:ssg-state_pam_unix_hashing_algorithm_commonauth:ste:1" version="1" operator="AND">
      <ind:subexpression operation="equals" datatype="string">sha512</ind:subexpression>
    </ind:textfilecontent54_state>
    <ind:variable_state id="oval:ssg-state_set_password_hashing_algorithm_logindefs:ste:1" version="1" operator="AND">
      <ind:value operation="pattern match" datatype="string" var_ref="oval:ssg-var_password_hashing_algorithm_regex:var:1" />
    </ind:variable_state>
    <unix:symlink_state id="oval:ssg-state_disable_ctrlaltdel_exists:ste:1" version="1" operator="AND" comment="Disable Ctrl-Alt-Del key sequence override exists">
      <unix:filepath>/etc/systemd/system/ctrl-alt-del.target</unix:filepath>
      <unix:canonical_path>/dev/null</unix:canonical_path>
    </unix:symlink_state>
    <ind:textfilecontent54_state id="oval:ssg-state_etc_default_useradd_inactive:ste:1" version="1" operator="AND">
      <ind:subexpression operation="less than or equal" var_ref="oval:ssg-var_account_disable_post_pw_expiration:var:1" datatype="int" />
    </ind:textfilecontent54_state>
    <ind:textfilecontent54_state id="oval:ssg-state_etc_default_useradd_inactive_nonnegative:ste:1" version="1" operator="AND">
      <ind:subexpression operation="greater than" datatype="int">-1</ind:subexpression>
    </ind:textfilecontent54_state>
    <ind:variable_state id="oval:ssg-state_last_pass_max_days_instance_value:ste:1" version="1" operator="AND">
      <ind:value operation="less than or equal" var_ref="oval:ssg-var_accounts_maximum_age_login_defs:var:1" datatype="int" var_check="at least one" />
    </ind:variable_state>
    <ind:variable_state id="oval:ssg-state_last_pass_min_days_instance_value:ste:1" version="1" operator="AND">
      <ind:value operation="greater than or equal" var_ref="oval:ssg-var_accounts_minimum_age_login_defs:var:1" datatype="int" var_check="at least one" />
    </ind:variable_state>
    <ind:textfilecontent54_state id="oval:ssg-state_password_auth_pam_unix_rounds:ste:1" version="1" operator="AND">
      <ind:subexpression datatype="int" operation="greater than or equal" var_ref="oval:ssg-var_password_pam_unix_rounds:var:1" />
    </ind:textfilecontent54_state>
    <ind:textfilecontent54_state id="oval:ssg-state_oot_access_locked_etc_shadow:ste:1" version="1" operator="AND">
      <ind:subexpression operation="pattern match">^(\!|\*).*$</ind:subexpression>
    </ind:textfilecontent54_state>
    <ind:textfilecontent54_state id="oval:ssg-state_maxlogins:ste:1" version="1" operator="AND">
      <ind:subexpression operation="less than or equal" var_ref="oval:ssg-var_accounts_max_concurrent_login_sessions:var:1" datatype="int" />
    </ind:textfilecontent54_state>
    <ind:variable_state id="oval:ssg-state_accounts_tmout_defined:ste:1" version="1" operator="AND">
      <ind:value operation="greater than or equal" datatype="int">1</ind:value>
    </ind:variable_state>
    <ind:textfilecontent54_state id="oval:ssg-state_etc_profile_tmout:ste:1" version="2" operator="AND">
      <ind:subexpression datatype="int" operation="less than or equal" var_check="all" var_ref="oval:ssg-var_accounts_tmout:var:1" />
    </ind:textfilecontent54_state>
    <ind:textfilecontent54_state id="oval:ssg-state_etc_profile_tmout_lower_bound:ste:1" version="1" operator="AND">
      <ind:subexpression datatype="int" operation="greater than or equal">1</ind:subexpression>
    </ind:textfilecontent54_state>
    <unix:symlink_state id="oval:ssg-object_ensure_symlink_utc_configuration:ste:1" version="1" operator="AND" comment="object_ensure_symlink_utc_configuration">
      <unix:filepath>/etc/localtime</unix:filepath>
      <unix:canonical_path operation="pattern match">^(/usr)?/share/zoneinfo(/Etc)?/(GMT|UTC)$</unix:canonical_path>
    </unix:symlink_state>
    <unix:interface_state id="oval:ssg-state_wifi_up:ste:1" version="1" operator="AND">
      <unix:flag datatype="string" entity_check="at least one" operation="equals">UP</unix:flag>
    </unix:interface_state>
    <unix:file_state id="oval:ssg-state_dir_perms_world_writable_sticky_bits:ste:1" version="1" operator="AND">
      <unix:sticky datatype="boolean">false</unix:sticky>
      <unix:owrite datatype="boolean">true</unix:owrite>
    </unix:file_state>
    <linux:partition_state id="oval:ssg-state_dir_perms_world_writable_sticky_bits_dev_partitons:ste:1" version="1" operator="AND">
      <linux:device operation="pattern match">^/dev/.*$</linux:device>
    </linux:partition_state>
    <unix:file_state id="oval:ssg-state_groupowner_system_commands_dirs_not_root_or_system_account:ste:1" version="1" operator="AND">
      <unix:group_id datatype="int" operation="greater than or equal">1000</unix:group_id>
    </unix:file_state>
    <unix:file_state id="oval:ssg-state_groupowner_system_commands_dirs_symlink:ste:1" version="1" operator="AND" comment="symbolic link">
      <unix:type operation="equals">symbolic link</unix:type>
    </unix:file_state>
    <unix:file_state id="oval:ssg-state_owner_binaries_not_root:ste:1" version="1" operator="OR">
      <unix:user_id datatype="int" operation="not equal">0</unix:user_id>
    </unix:file_state>
    <unix:file_state id="oval:ssg-state_perms_binary_files_nogroupwrite_noworldwrite:ste:1" version="1" operator="OR">
      <unix:gwrite datatype="boolean">true</unix:gwrite>
      <unix:owrite datatype="boolean">true</unix:owrite>
    </unix:file_state>
    <unix:file_state id="oval:ssg-state_perms_binary_files_symlink:ste:1" version="1" operator="AND">
      <unix:type operation="equals">symbolic link</unix:type>
    </unix:file_state>
    <ind:textfilecontent54_state id="oval:ssg-is_fips_mode_enabled_state_whole_file_contents_fips_equal_to_one:ste:1" version="1" operator="AND">
      <ind:text operation="equals">1
</ind:text>
    </ind:textfilecontent54_state>
    <ind:textfilecontent54_state id="oval:ssg-state_pam_auth_pam_faildelay_delay:ste:1" version="3" operator="AND">
      <ind:subexpression datatype="int" operation="greater than or equal" var_ref="oval:ssg-var_password_pam_delay:var:1" />
    </ind:textfilecontent54_state>
    <ind:textfilecontent54_state id="oval:ssg-state_accounts_passwords_pam_faillock_deny_parameter_upper_bound:ste:1" version="1" operator="AND">
      <ind:subexpression datatype="int" operation="less than or equal" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_deny:var:1" />
    </ind:textfilecontent54_state>
    <ind:textfilecontent54_state id="oval:ssg-state_accounts_passwords_pam_faillock_deny_parameter_lower_bound:ste:1" version="1" operator="AND">
      <ind:subexpression datatype="int" operation="greater than or equal">1</ind:subexpression>
    </ind:textfilecontent54_state>
    <ind:textfilecontent54_state id="oval:ssg-state_accounts_passwords_pam_faillock_fail_interval_parameter_lower_bound:ste:1" version="1" operator="AND">
      <ind:subexpression datatype="int" operation="greater than or equal" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_fail_interval:var:1" />
    </ind:textfilecontent54_state>
    <ind:textfilecontent54_state id="oval:ssg-state_accounts_passwords_pam_faillock_unlock_time_parameter_lower_bound:ste:1" version="1" operator="AND">
      <ind:subexpression datatype="int" operation="greater than or equal" var_ref="oval:ssg-var_accounts_passwords_pam_faillock_unlock_time:var:1" />
    </ind:textfilecontent54_state>
    <ind:textfilecontent54_state id="oval:ssg-state_aide_disable_silentreports:ste:1" version="1" operator="AND">
      <ind:subexpression datatype="string" operation="pattern match">^no$</ind:subexpression>
    </ind:textfilecontent54_state>
    <linux:systemdunitdependency_state id="oval:ssg-state_systemd_apparmor_on:ste:1" version="1" operator="AND" comment="apparmor listed at least once in the dependencies">
      <linux:dependency entity_check="at least one">apparmor.service</linux:dependency>
    </linux:systemdunitdependency_state>
    <linux:systemdunitdependency_state id="oval:ssg-state_systemd_apparmor_socket_on:ste:1" version="1" operator="AND" comment="apparmor listed at least once in the dependencies">
      <linux:dependency entity_check="at least one">apparmor.socket</linux:dependency>
    </linux:systemdunitdependency_state>
    <linux:systemdunitproperty_state id="oval:ssg-state_service_running_apparmor:ste:1" version="1" operator="AND" comment="apparmor is running">
      <linux:value>active</linux:value>
    </linux:systemdunitproperty_state>
    <ind:textfilecontent54_state id="oval:ssg-state_chronyd_sync_clock:ste:1" version="1" operator="AND">
      <ind:subexpression datatype="string" operation="pattern match">^1 -1$</ind:subexpression>
    </ind:textfilecontent54_state>
    <unix:file_state id="oval:ssg-state_file_groupownerdir_group_ownership_library_dirs_0_0:ste:1" version="1" operator="AND">
      <unix:group_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_groupownerdir_group_ownership_library_dirs_0_gid:var:1" />
    </unix:file_state>
    <unix:file_state id="oval:ssg-symlink_file_groupowner:ste:1" version="1" operator="AND">
      <unix:type operation="equals">symbolic link</unix:type>
    </unix:file_state>
    <unix:file_state id="oval:ssg-state_file_groupownerdir_groupowner_system_journal_0_systemd-journal:ste:1" version="1" operator="AND">
      <unix:group_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_groupownerdir_groupowner_system_journal_systemd-journal_gid:var:1" />
    </unix:file_state>
    <unix:file_state id="oval:ssg-state_file_groupownerdir_groupownership_binary_dirs_0_0:ste:1" version="1" operator="AND">
      <unix:group_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_groupownerdir_groupownership_binary_dirs_0_gid:var:1" />
    </unix:file_state>
    <unix:file_state id="oval:ssg-state_file_ownerdir_owner_system_journal_0_0:ste:1" version="1" operator="AND">
      <unix:user_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_ownerdir_owner_system_journal_0_uid:var:1" />
    </unix:file_state>
    <unix:file_state id="oval:ssg-symlink_file_owner:ste:1" version="1" operator="AND">
      <unix:type operation="equals">symbolic link</unix:type>
    </unix:file_state>
    <unix:file_state id="oval:ssg-state_file_ownerdir_ownership_binary_dirs_0_0:ste:1" version="1" operator="AND">
      <unix:user_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_ownerdir_ownership_binary_dirs_0_uid:var:1" />
    </unix:file_state>
    <unix:file_state id="oval:ssg-state_file_ownerdir_ownership_library_dirs_0_0:ste:1" version="1" operator="AND">
      <unix:user_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_ownerdir_ownership_library_dirs_0_uid:var:1" />
    </unix:file_state>
    <unix:file_state id="oval:ssg-state_file_permissionsdir_permissions_binary_dirs_0_mode_0755or_stricter_:ste:1" version="3" operator="AND">
      <unix:suid datatype="boolean">false</unix:suid>
      <unix:sgid datatype="boolean">false</unix:sgid>
      <unix:sticky datatype="boolean">false</unix:sticky>
      <unix:gwrite datatype="boolean">false</unix:gwrite>
      <unix:owrite datatype="boolean">false</unix:owrite>
    </unix:file_state>
    <unix:file_state id="oval:ssg-state_file_permissionsdir_permissions_binary_dirs_1_mode_0755or_stricter_:ste:1" version="3" operator="AND">
      <unix:suid datatype="boolean">false</unix:suid>
      <unix:sgid datatype="boolean">false</unix:sgid>
      <unix:sticky datatype="boolean">false</unix:sticky>
      <unix:gwrite datatype="boolean">false</unix:gwrite>
      <unix:owrite datatype="boolean">false</unix:owrite>
    </unix:file_state>
    <unix:file_state id="oval:ssg-state_file_permissionsdir_permissions_binary_dirs_2_mode_0755or_stricter_:ste:1" version="3" operator="AND">
      <unix:suid datatype="boolean">false</unix:suid>
      <unix:sgid datatype="boolean">false</unix:sgid>
      <unix:sticky datatype="boolean">false</unix:sticky>
      <unix:gwrite datatype="boolean">false</unix:gwrite>
      <unix:owrite datatype="boolean">false</unix:owrite>
    </unix:file_state>
    <unix:file_state id="oval:ssg-state_file_permissionsdir_permissions_binary_dirs_3_mode_0755or_stricter_:ste:1" version="3" operator="AND">
      <unix:suid datatype="boolean">false</unix:suid>
      <unix:sgid datatype="boolean">false</unix:sgid>
      <unix:sticky datatype="boolean">false</unix:sticky>
      <unix:gwrite datatype="boolean">false</unix:gwrite>
      <unix:owrite datatype="boolean">false</unix:owrite>
    </unix:file_state>
    <unix:file_state id="oval:ssg-state_file_permissionsdir_permissions_binary_dirs_4_mode_0755or_stricter_:ste:1" version="3" operator="AND">
      <unix:suid datatype="boolean">false</unix:suid>
      <unix:sgid datatype="boolean">false</unix:sgid>
      <unix:sticky datatype="boolean">false</unix:sticky>
      <unix:gwrite datatype="boolean">false</unix:gwrite>
      <unix:owrite datatype="boolean">false</unix:owrite>
    </unix:file_state>
    <unix:file_state id="oval:ssg-state_file_permissionsdir_permissions_binary_dirs_5_mode_0755or_stricter_:ste:1" version="3" operator="AND">
      <unix:suid datatype="boolean">false</unix:suid>
      <unix:sgid datatype="boolean">false</unix:sgid>
      <unix:sticky datatype="boolean">false</unix:sticky>
      <unix:gwrite datatype="boolean">false</unix:gwrite>
      <unix:owrite datatype="boolean">false</unix:owrite>
    </unix:file_state>
    <unix:file_state id="oval:ssg-exclude_symlinks_dir_permissions_binary_dirs:ste:1" version="1" operator="AND">
      <unix:type operation="equals">symbolic link</unix:type>
    </unix:file_state>
    <unix:file_state id="oval:ssg-state_file_permissionsdir_permissions_system_journal_0_mode_2750or_stricter_:ste:1" version="3" operator="AND">
      <unix:suid datatype="boolean">false</unix:suid>
      <unix:sticky datatype="boolean">false</unix:sticky>
      <unix:gwrite datatype="boolean">false</unix:gwrite>
      <unix:oread datatype="boolean">false</unix:oread>
      <unix:owrite datatype="boolean">false</unix:owrite>
      <unix:oexec datatype="boolean">false</unix:oexec>
    </unix:file_state>
    <unix:file_state id="oval:ssg-state_file_permissionsdir_permissions_system_journal_1_mode_2750or_stricter_:ste:1" version="3" operator="AND">
      <unix:suid datatype="boolean">false</unix:suid>
      <unix:sticky datatype="boolean">false</unix:sticky>
      <unix:gwrite datatype="boolean">false</unix:gwrite>
      <unix:oread datatype="boolean">false</unix:oread>
      <unix:owrite datatype="boolean">false</unix:owrite>
      <unix:oexec datatype="boolean">false</unix:oexec>
    </unix:file_state>
    <unix:file_state id="oval:ssg-exclude_symlinks_dir_permissions_system_journal:ste:1" version="1" operator="AND">
      <unix:type operation="equals">symbolic link</unix:type>
    </unix:file_state>
    <unix:file_state id="oval:ssg-state_file_groupowner_journalctl_0_0:ste:1" version="1" operator="AND">
      <unix:group_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_groupowner_journalctl_0_gid:var:1" />
    </unix:file_state>
    <unix:file_state id="oval:ssg-state_file_groupowner_system_journal_0_systemd-journal:ste:1" version="1" operator="AND">
      <unix:group_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_groupowner_system_journal_systemd-journal_gid:var:1" />
    </unix:file_state>
    <unix:file_state id="oval:ssg-state_file_groupowner_var_log_0_0:ste:1" version="1" operator="AND">
      <unix:group_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_groupowner_var_log_0_gid:var:1" />
    </unix:file_state>
    <unix:file_state id="oval:ssg-state_file_groupowner_var_log_syslog_0_4:ste:1" version="1" operator="AND">
      <unix:group_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_groupowner_var_log_syslog_4_gid:var:1" />
    </unix:file_state>
    <unix:file_state id="oval:ssg-state_file_groupownership_audit_configuration_0_0:ste:1" version="1" operator="AND">
      <unix:group_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_groupownership_audit_configuration_0_gid:var:1" />
    </unix:file_state>
    <unix:file_state id="oval:ssg-state_file_owner_journalctl_0_0:ste:1" version="1" operator="AND">
      <unix:user_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_owner_journalctl_0_uid:var:1" />
    </unix:file_state>
    <unix:file_state id="oval:ssg-state_file_owner_system_journal_0_0:ste:1" version="1" operator="AND">
      <unix:user_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_owner_system_journal_0_uid:var:1" />
    </unix:file_state>
    <unix:file_state id="oval:ssg-state_file_owner_var_log_0_0:ste:1" version="1" operator="AND">
      <unix:user_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_owner_var_log_0_uid:var:1" />
    </unix:file_state>
    <unix:file_state id="oval:ssg-state_file_owner_var_log_syslog_0_syslog:ste:1" version="1" operator="AND">
      <unix:user_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_owner_var_log_syslog_syslog_uid:var:1" />
    </unix:file_state>
    <unix:file_state id="oval:ssg-state_file_ownership_audit_binaries_0_0:ste:1" version="1" operator="AND">
      <unix:user_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_ownership_audit_binaries_0_uid:var:1" />
    </unix:file_state>
    <unix:file_state id="oval:ssg-state_file_ownership_audit_configuration_0_0:ste:1" version="1" operator="AND">
      <unix:user_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_ownership_audit_configuration_0_uid:var:1" />
    </unix:file_state>
    <unix:file_state id="oval:ssg-state_file_ownership_library_dirs_0_0:ste:1" version="1" operator="AND">
      <unix:user_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_ownership_library_dirs_0_uid:var:1" />
    </unix:file_state>
    <unix:file_state id="oval:ssg-state_file_permissions_audit_binaries_0_mode_0755or_stricter_:ste:1" version="3" operator="AND">
      <unix:suid datatype="boolean">false</unix:suid>
      <unix:sgid datatype="boolean">false</unix:sgid>
      <unix:sticky datatype="boolean">false</unix:sticky>
      <unix:gwrite datatype="boolean">false</unix:gwrite>
      <unix:owrite datatype="boolean">false</unix:owrite>
    </unix:file_state>
    <unix:file_state id="oval:ssg-state_file_permissions_audit_binaries_1_mode_0755or_stricter_:ste:1" version="3" operator="AND">
      <unix:suid datatype="boolean">false</unix:suid>
      <unix:sgid datatype="boolean">false</unix:sgid>
      <unix:sticky datatype="boolean">false</unix:sticky>
      <unix:gwrite datatype="boolean">false</unix:gwrite>
      <unix:owrite datatype="boolean">false</unix:owrite>
    </unix:file_state>
    <unix:file_state id="oval:ssg-state_file_permissions_audit_binaries_2_mode_0755or_stricter_:ste:1" version="3" operator="AND">
      <unix:suid datatype="boolean">false</unix:suid>
      <unix:sgid datatype="boolean">false</unix:sgid>
      <unix:sticky datatype="boolean">false</unix:sticky>
      <unix:gwrite datatype="boolean">false</unix:gwrite>
      <unix:owrite datatype="boolean">false</unix:owrite>
    </unix:file_state>
    <unix:file_state id="oval:ssg-state_file_permissions_audit_binaries_3_mode_0755or_stricter_:ste:1" version="3" operator="AND">
      <unix:suid datatype="boolean">false</unix:suid>
      <unix:sgid datatype="boolean">false</unix:sgid>
      <unix:sticky datatype="boolean">false</unix:sticky>
      <unix:gwrite datatype="boolean">false</unix:gwrite>
      <unix:owrite datatype="boolean">false</unix:owrite>
    </unix:file_state>
    <unix:file_state id="oval:ssg-state_file_permissions_audit_binaries_4_mode_0755or_stricter_:ste:1" version="3" operator="AND">
      <unix:suid datatype="boolean">false</unix:suid>
      <unix:sgid datatype="boolean">false</unix:sgid>
      <unix:sticky datatype="boolean">false</unix:sticky>
      <unix:gwrite datatype="boolean">false</unix:gwrite>
      <unix:owrite datatype="boolean">false</unix:owrite>
    </unix:file_state>
    <unix:file_state id="oval:ssg-state_file_permissions_audit_binaries_5_mode_0755or_stricter_:ste:1" version="3" operator="AND">
      <unix:suid datatype="boolean">false</unix:suid>
      <unix:sgid datatype="boolean">false</unix:sgid>
      <unix:sticky datatype="boolean">false</unix:sticky>
      <unix:gwrite datatype="boolean">false</unix:gwrite>
      <unix:owrite datatype="boolean">false</unix:owrite>
    </unix:file_state>
    <unix:file_state id="oval:ssg-state_file_permissions_audit_binaries_6_mode_0755or_stricter_:ste:1" version="3" operator="AND">
      <unix:suid datatype="boolean">false</unix:suid>
      <unix:sgid datatype="boolean">false</unix:sgid>
      <unix:sticky datatype="boolean">false</unix:sticky>
      <unix:gwrite datatype="boolean">false</unix:gwrite>
      <unix:owrite datatype="boolean">false</unix:owrite>
    </unix:file_state>
    <unix:file_state id="oval:ssg-exclude_symlinks__audit_binaries:ste:1" version="1" operator="AND">
      <unix:type operation="equals">symbolic link</unix:type>
    </unix:file_state>
    <unix:file_state id="oval:ssg-state_file_permissions_etc_audit_auditd_0_mode_0640or_stricter_:ste:1" version="3" operator="AND">
      <unix:suid datatype="boolean">false</unix:suid>
      <unix:sgid datatype="boolean">false</unix:sgid>
      <unix:sticky datatype="boolean">false</unix:sticky>
      <unix:uexec datatype="boolean">false</unix:uexec>
      <unix:gwrite datatype="boolean">false</unix:gwrite>
      <unix:gexec datatype="boolean">false</unix:gexec>
      <unix:oread datatype="boolean">false</unix:oread>
      <unix:owrite datatype="boolean">false</unix:owrite>
      <unix:oexec datatype="boolean">false</unix:oexec>
    </unix:file_state>
    <unix:file_state id="oval:ssg-exclude_symlinks__etc_audit_auditd:ste:1" version="1" operator="AND">
      <unix:type operation="equals">symbolic link</unix:type>
    </unix:file_state>
    <unix:file_state id="oval:ssg-state_file_permissions_etc_audit_rules_0_mode_0640or_stricter_:ste:1" version="3" operator="AND">
      <unix:suid datatype="boolean">false</unix:suid>
      <unix:sgid datatype="boolean">false</unix:sgid>
      <unix:sticky datatype="boolean">false</unix:sticky>
      <unix:uexec datatype="boolean">false</unix:uexec>
      <unix:gwrite datatype="boolean">false</unix:gwrite>
      <unix:gexec datatype="boolean">false</unix:gexec>
      <unix:oread datatype="boolean">false</unix:oread>
      <unix:owrite datatype="boolean">false</unix:owrite>
      <unix:oexec datatype="boolean">false</unix:oexec>
    </unix:file_state>
    <unix:file_state id="oval:ssg-exclude_symlinks__etc_audit_rules:ste:1" version="1" operator="AND">
      <unix:type operation="equals">symbolic link</unix:type>
    </unix:file_state>
    <unix:file_state id="oval:ssg-state_file_permissions_etc_audit_rulesd_0_mode_0600or_stricter_:ste:1" version="3" operator="AND">
      <unix:suid datatype="boolean">false</unix:suid>
      <unix:sgid datatype="boolean">false</unix:sgid>
      <unix:sticky datatype="boolean">false</unix:sticky>
      <unix:uexec datatype="boolean">false</unix:uexec>
      <unix:gread datatype="boolean">false</unix:gread>
      <unix:gwrite datatype="boolean">false</unix:gwrite>
      <unix:gexec datatype="boolean">false</unix:gexec>
      <unix:oread datatype="boolean">false</unix:oread>
      <unix:owrite datatype="boolean">false</unix:owrite>
      <unix:oexec datatype="boolean">false</unix:oexec>
    </unix:file_state>
    <unix:file_state id="oval:ssg-exclude_symlinks__etc_audit_rulesd:ste:1" version="1" operator="AND">
      <unix:type operation="equals">symbolic link</unix:type>
    </unix:file_state>
    <unix:file_state id="oval:ssg-state_file_permissions_journalctl_0_mode_0740or_stricter_:ste:1" version="3" operator="AND">
      <unix:suid datatype="boolean">false</unix:suid>
      <unix:sgid datatype="boolean">false</unix:sgid>
      <unix:sticky datatype="boolean">false</unix:sticky>
      <unix:gwrite datatype="boolean">false</unix:gwrite>
      <unix:gexec datatype="boolean">false</unix:gexec>
      <unix:oread datatype="boolean">false</unix:oread>
      <unix:owrite datatype="boolean">false</unix:owrite>
      <unix:oexec datatype="boolean">false</unix:oexec>
    </unix:file_state>
    <unix:file_state id="oval:ssg-exclude_symlinks__journalctl:ste:1" version="1" operator="AND">
      <unix:type operation="equals">symbolic link</unix:type>
    </unix:file_state>
    <unix:file_state id="oval:ssg-state_file_permissions_library_dirs_0_mode_7755or_stricter_:ste:1" version="3" operator="AND">
      <unix:gwrite datatype="boolean">false</unix:gwrite>
      <unix:owrite datatype="boolean">false</unix:owrite>
    </unix:file_state>
    <unix:file_state id="oval:ssg-state_file_permissions_library_dirs_1_mode_7755or_stricter_:ste:1" version="3" operator="AND">
      <unix:gwrite datatype="boolean">false</unix:gwrite>
      <unix:owrite datatype="boolean">false</unix:owrite>
    </unix:file_state>
    <unix:file_state id="oval:ssg-state_file_permissions_library_dirs_2_mode_7755or_stricter_:ste:1" version="3" operator="AND">
      <unix:gwrite datatype="boolean">false</unix:gwrite>
      <unix:owrite datatype="boolean">false</unix:owrite>
    </unix:file_state>
    <unix:file_state id="oval:ssg-state_file_permissions_library_dirs_3_mode_7755or_stricter_:ste:1" version="3" operator="AND">
      <unix:gwrite datatype="boolean">false</unix:gwrite>
      <unix:owrite datatype="boolean">false</unix:owrite>
    </unix:file_state>
    <unix:file_state id="oval:ssg-exclude_symlinks__library_dirs:ste:1" version="1" operator="AND">
      <unix:type operation="equals">symbolic link</unix:type>
    </unix:file_state>
    <unix:file_state id="oval:ssg-state_file_permissions_system_journal_0_mode_0640or_stricter_:ste:1" version="3" operator="AND">
      <unix:suid datatype="boolean">false</unix:suid>
      <unix:sgid datatype="boolean">false</unix:sgid>
      <unix:sticky datatype="boolean">false</unix:sticky>
      <unix:uexec datatype="boolean">false</unix:uexec>
      <unix:gwrite datatype="boolean">false</unix:gwrite>
      <unix:gexec datatype="boolean">false</unix:gexec>
      <unix:oread datatype="boolean">false</unix:oread>
      <unix:owrite datatype="boolean">false</unix:owrite>
      <unix:oexec datatype="boolean">false</unix:oexec>
    </unix:file_state>
    <unix:file_state id="oval:ssg-exclude_symlinks__system_journal:ste:1" version="1" operator="AND">
      <unix:type operation="equals">symbolic link</unix:type>
    </unix:file_state>
    <unix:file_state id="oval:ssg-state_file_permissions_var_log_0_mode_0755or_stricter_:ste:1" version="3" operator="AND">
      <unix:suid datatype="boolean">false</unix:suid>
      <unix:sgid datatype="boolean">false</unix:sgid>
      <unix:sticky datatype="boolean">false</unix:sticky>
      <unix:gwrite datatype="boolean">false</unix:gwrite>
      <unix:owrite datatype="boolean">false</unix:owrite>
    </unix:file_state>
    <unix:file_state id="oval:ssg-exclude_symlinks__var_log:ste:1" version="1" operator="AND">
      <unix:type operation="equals">symbolic link</unix:type>
    </unix:file_state>
    <unix:file_state id="oval:ssg-state_file_permissions_var_log_syslog_0_mode_0640or_stricter_:ste:1" version="3" operator="AND">
      <unix:suid datatype="boolean">false</unix:suid>
      <unix:sgid datatype="boolean">false</unix:sgid>
      <unix:sticky datatype="boolean">false</unix:sticky>
      <unix:uexec datatype="boolean">false</unix:uexec>
      <unix:gwrite datatype="boolean">false</unix:gwrite>
      <unix:gexec datatype="boolean">false</unix:gexec>
      <unix:oread datatype="boolean">false</unix:oread>
      <unix:owrite datatype="boolean">false</unix:owrite>
      <unix:oexec datatype="boolean">false</unix:oexec>
    </unix:file_state>
    <unix:file_state id="oval:ssg-exclude_symlinks__var_log_syslog:ste:1" version="1" operator="AND">
      <unix:type operation="equals">symbolic link</unix:type>
    </unix:file_state>
    <unix:file_state id="oval:ssg-state_file_permissionspermissions_local_var_log_0_mode_0640or_stricter_:ste:1" version="3" operator="AND">
      <unix:suid datatype="boolean">false</unix:suid>
      <unix:sgid datatype="boolean">false</unix:sgid>
      <unix:sticky datatype="boolean">false</unix:sticky>
      <unix:uexec datatype="boolean">false</unix:uexec>
      <unix:gwrite datatype="boolean">false</unix:gwrite>
      <unix:gexec datatype="boolean">false</unix:gexec>
      <unix:oread datatype="boolean">false</unix:oread>
      <unix:owrite datatype="boolean">false</unix:owrite>
      <unix:oexec datatype="boolean">false</unix:oexec>
    </unix:file_state>
    <unix:file_state id="oval:ssg-exclude_symlinks_permissions_local_var_log:ste:1" version="1" operator="AND">
      <unix:type operation="equals">symbolic link</unix:type>
    </unix:file_state>
    <unix:file_state id="oval:ssg-state_file_groupownerroot_permissions_syslibrary_files_0_0:ste:1" version="1" operator="AND">
      <unix:group_id datatype="int" operation="equals" var_ref="oval:ssg-var_file_groupownerroot_permissions_syslibrary_files_0_gid:var:1" />
    </unix:file_state>
    <linux:systemdunitdependency_state id="oval:ssg-state_systemd_auditd_on:ste:1" version="1" operator="AND" comment="auditd listed at least once in the dependencies">
      <linux:dependency entity_check="at least one">auditd.service</linux:dependency>
    </linux:systemdunitdependency_state>
    <linux:systemdunitdependency_state id="oval:ssg-state_systemd_auditd_socket_on:ste:1" version="1" operator="AND" comment="auditd listed at least once in the dependencies">
      <linux:dependency entity_check="at least one">auditd.socket</linux:dependency>
    </linux:systemdunitdependency_state>
    <linux:systemdunitproperty_state id="oval:ssg-state_service_running_auditd:ste:1" version="1" operator="AND" comment="auditd is running">
      <linux:value>active</linux:value>
    </linux:systemdunitproperty_state>
    <linux:systemdunitdependency_state id="oval:ssg-state_systemd_rsyslog_on:ste:1" version="1" operator="AND" comment="rsyslog listed at least once in the dependencies">
      <linux:dependency entity_check="at least one">rsyslog.service</linux:dependency>
    </linux:systemdunitdependency_state>
    <linux:systemdunitdependency_state id="oval:ssg-state_systemd_rsyslog_socket_on:ste:1" version="1" operator="AND" comment="rsyslog listed at least once in the dependencies">
      <linux:dependency entity_check="at least one">rsyslog.socket</linux:dependency>
    </linux:systemdunitdependency_state>
    <linux:systemdunitproperty_state id="oval:ssg-state_service_running_rsyslog:ste:1" version="1" operator="AND" comment="rsyslog is running">
      <linux:value>active</linux:value>
    </linux:systemdunitproperty_state>
    <linux:systemdunitdependency_state id="oval:ssg-state_systemd_sshd_on:ste:1" version="1" operator="AND" comment="sshd listed at least once in the dependencies">
      <linux:dependency entity_check="at least one">sshd.service</linux:dependency>
    </linux:systemdunitdependency_state>
    <linux:systemdunitdependency_state id="oval:ssg-state_systemd_sshd_socket_on:ste:1" version="1" operator="AND" comment="sshd listed at least once in the dependencies">
      <linux:dependency entity_check="at least one">sshd.socket</linux:dependency>
    </linux:systemdunitdependency_state>
    <linux:systemdunitproperty_state id="oval:ssg-state_service_running_sshd:ste:1" version="1" operator="AND" comment="sshd is running">
      <linux:value>active</linux:value>
    </linux:systemdunitproperty_state>
    <linux:systemdunitdependency_state id="oval:ssg-state_systemd_sssd_on:ste:1" version="1" operator="AND" comment="sssd listed at least once in the dependencies">
      <linux:dependency entity_check="at least one">sssd.service</linux:dependency>
    </linux:systemdunitdependency_state>
    <linux:systemdunitdependency_state id="oval:ssg-state_systemd_sssd_socket_on:ste:1" version="1" operator="AND" comment="sssd listed at least once in the dependencies">
      <linux:dependency entity_check="at least one">sssd.socket</linux:dependency>
    </linux:systemdunitdependency_state>
    <linux:systemdunitproperty_state id="oval:ssg-state_service_running_sssd:ste:1" version="1" operator="AND" comment="sssd is running">
      <linux:value>active</linux:value>
    </linux:systemdunitproperty_state>
    <linux:systemdunitdependency_state id="oval:ssg-state_systemd_ufw_on:ste:1" version="1" operator="AND" comment="ufw listed at least once in the dependencies">
      <linux:dependency entity_check="at least one">ufw.service</linux:dependency>
    </linux:systemdunitdependency_state>
    <linux:systemdunitdependency_state id="oval:ssg-state_systemd_ufw_socket_on:ste:1" version="1" operator="AND" comment="ufw listed at least once in the dependencies">
      <linux:dependency entity_check="at least one">ufw.socket</linux:dependency>
    </linux:systemdunitdependency_state>
    <linux:systemdunitproperty_state id="oval:ssg-state_service_running_ufw:ste:1" version="1" operator="AND" comment="ufw is running">
      <linux:value>active</linux:value>
    </linux:systemdunitproperty_state>
    <unix:sysctl_state id="oval:ssg-state_sysctl_kernel_dmesg_restrict_runtime:ste:1" version="1" operator="AND">
      <unix:value datatype="int" operation="equals">1</unix:value>
    </unix:sysctl_state>
    <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_kernel_dmesg_restrict:ste:1" version="1" operator="AND">
      <ind:subexpression operation="equals" datatype="int">1</ind:subexpression>
    </ind:textfilecontent54_state>
    <unix:sysctl_state id="oval:ssg-state_sysctl_kernel_randomize_va_space_runtime:ste:1" version="1" operator="AND">
      <unix:value datatype="int" operation="equals">2</unix:value>
    </unix:sysctl_state>
    <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_kernel_randomize_va_space:ste:1" version="1" operator="AND">
      <ind:subexpression operation="equals" datatype="int">2</ind:subexpression>
    </ind:textfilecontent54_state>
    <unix:sysctl_state id="oval:ssg-state_sysctl_net_ipv4_tcp_syncookies_runtime:ste:1" version="1" operator="AND">
      <unix:value datatype="int" operation="equals" var_ref="oval:ssg-sysctl_net_ipv4_tcp_syncookies_value:var:1" />
    </unix:sysctl_state>
    <ind:textfilecontent54_state id="oval:ssg-state_static_sysctld_sysctl_net_ipv4_tcp_syncookies:ste:1" version="1" operator="AND">
      <ind:subexpression operation="equals" var_ref="oval:ssg-sysctl_net_ipv4_tcp_syncookies_value:var:1" datatype="int" />
    </ind:textfilecontent54_state>
  </oval-def:states>
  <oval-def:variables>
    <oval-def:external_variable id="oval:ssg-var_audispd_remote_server:var:1" version="1" datatype="string" comment="audispd remote_server setting" />
    <oval-def:local_variable id="oval:ssg-var_auditd_disk_full_action_regex:var:1" version="1" datatype="string" comment="Build regex to be case insensitive">
      <oval-def:concat>
        <oval-def:literal_component>(?i)</oval-def:literal_component>
        <oval-def:variable_component var_ref="oval:ssg-var_auditd_disk_full_action:var:1" />
      </oval-def:concat>
    </oval-def:local_variable>
    <oval-def:external_variable id="oval:ssg-var_auditd_disk_full_action:var:1" version="1" datatype="string" comment="audit disk_full_action setting" />
    <oval-def:external_variable id="oval:ssg-var_auditd_action_mail_acct:var:1" version="1" datatype="string" comment="audit action_mail_acct setting" />
    <oval-def:local_variable id="oval:ssg-var_auditd_space_left_action_regex:var:1" version="1" datatype="string" comment="Build regex to be case insensitive">
      <oval-def:concat>
        <oval-def:literal_component>(?i)</oval-def:literal_component>
        <oval-def:variable_component var_ref="oval:ssg-var_auditd_space_left_action:var:1" />
      </oval-def:concat>
    </oval-def:local_variable>
    <oval-def:external_variable id="oval:ssg-var_auditd_space_left_action:var:1" version="2" datatype="string" comment="audit space_left_action setting" />
    <oval-def:external_variable id="oval:ssg-var_auditd_space_left_percentage:var:1" version="1" datatype="int" comment="audit space_left setting" />
    <oval-def:external_variable id="oval:ssg-var_time_service_set_maxpoll:var:1" version="1" datatype="int" comment="maxpoll value" />
    <oval-def:external_variable id="oval:ssg-remote_login_banner_text:var:1" version="1" datatype="string" comment="warning banner text variable" />
    <oval-def:constant_variable id="oval:ssg-var_pam_faillock_audit_parameter_regex:var:1" version="1" datatype="string" comment="regex to identify audit parameter in pam files">
      <oval-def:value>^[\s]*auth[\s]+(?:required|requisite)[\s]+pam_faillock.so[^\n#]preauth[^\n#]*audit</oval-def:value>
    </oval-def:constant_variable>
    <oval-def:constant_variable id="oval:ssg-var_pam_faillock_silent_parameter_regex:var:1" version="1" datatype="string" comment="regex to identify silent parameter in pam files">
      <oval-def:value>^[\s]*auth[\s]+(?:required|requisite)[\s]+pam_faillock.so[^\n#]+preauth[^\n#]+silent</oval-def:value>
    </oval-def:constant_variable>
    <oval-def:external_variable id="oval:ssg-var_accounts_passwords_pam_faillock_unlock_time:var:1" version="1" datatype="int" comment="external variable to use" />
    <oval-def:external_variable id="oval:ssg-var_password_pam_retry:var:1" version="1" datatype="int" comment="External variable for pam_pwquality retry" />
    <oval-def:local_variable id="oval:ssg-variable_last_encrypt_method_instance_value:var:1" version="1" datatype="string" comment="The value of last ENCRYPT_METHOD directive in /etc/login.defs">
      <oval-def:regex_capture pattern="ENCRYPT_METHOD\s+(\w+)">
        <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_last_encrypt_method_from_etc_login_defs:obj:1" />
      </oval-def:regex_capture>
    </oval-def:local_variable>
    <oval-def:local_variable id="oval:ssg-var_password_hashing_algorithm_regex:var:1" version="1" datatype="string" comment="Limit regex">
      <oval-def:concat>
        <oval-def:literal_component>^</oval-def:literal_component>
        <oval-def:variable_component var_ref="oval:ssg-var_password_hashing_algorithm:var:1" />
        <oval-def:literal_component>$</oval-def:literal_component>
      </oval-def:concat>
    </oval-def:local_variable>
    <oval-def:external_variable id="oval:ssg-var_password_hashing_algorithm:var:1" version="1" datatype="string" comment="hashing algorithm for /etc/login.defs" />
    <oval-def:external_variable id="oval:ssg-var_account_disable_post_pw_expiration:var:1" version="1" datatype="int" comment="inactive days expiration" />
    <oval-def:local_variable id="oval:ssg-variable_last_pass_max_days_instance_value:var:1" version="1" datatype="int" comment="The value of last PASS_MAX_DAYS directive in /etc/login.defs">
      <oval-def:regex_capture pattern="PASS_MAX_DAYS\s+(\d+)">
        <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_last_pass_max_days_from_etc_login_defs:obj:1" />
      </oval-def:regex_capture>
    </oval-def:local_variable>
    <oval-def:external_variable id="oval:ssg-var_accounts_maximum_age_login_defs:var:1" version="1" datatype="int" comment="Maximum password age" />
    <oval-def:local_variable id="oval:ssg-variable_last_pass_min_days_instance_value:var:1" version="1" datatype="int" comment="The value of last PASS_MIN_DAYS directive in /etc/login.defs">
      <oval-def:regex_capture pattern="PASS_MIN_DAYS\s+(\d+)">
        <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_last_pass_min_days_from_etc_login_defs:obj:1" />
      </oval-def:regex_capture>
    </oval-def:local_variable>
    <oval-def:external_variable id="oval:ssg-var_accounts_minimum_age_login_defs:var:1" version="1" datatype="int" comment="Minimum password age in days" />
    <oval-def:external_variable id="oval:ssg-var_password_pam_unix_rounds:var:1" version="1" datatype="int" comment="number of passwords hashing rounds" />
    <oval-def:external_variable id="oval:ssg-var_accounts_max_concurrent_login_sessions:var:1" version="1" datatype="int" comment="maximum number of concurrent logins per user" />
    <oval-def:local_variable id="oval:ssg-variable_count_of_tmout_instances:var:1" version="1" datatype="int" comment="Count of TMOUT instances">
      <oval-def:count>
        <oval-def:object_component object_ref="oval:ssg-object_accounts_tmout_all_tmout_instances:obj:1" item_field="text" />
      </oval-def:count>
    </oval-def:local_variable>
    <oval-def:external_variable id="oval:ssg-var_accounts_tmout:var:1" version="1" datatype="int" comment="external variable for TMOUT" />
    <oval-def:local_variable id="oval:ssg-var_dir_perms_world_writable_sticky_bits_local_mountpoints:var:1" version="1" datatype="string" comment="Mount points for local devices">
      <oval-def:object_component item_field="mount_point" object_ref="oval:ssg-object_dir_perms_world_writable_sticky_bits_local_partitions:obj:1" />
    </oval-def:local_variable>
    <oval-def:external_variable id="oval:ssg-var_password_pam_delay:var:1" version="1" datatype="int" comment="PAM external variable var_password_pam_delay" />
    <oval-def:constant_variable id="oval:ssg-var_accounts_passwords_pam_faillock_deny_pam_unix_regex:var:1" version="2" datatype="string" comment="regex to identify pam_unix.so in auth section of pam files">
      <oval-def:value>^\s*auth\N+pam_unix\.so</oval-def:value>
    </oval-def:constant_variable>
    <oval-def:constant_variable id="oval:ssg-var_accounts_passwords_pam_faillock_deny_pam_faillock_auth_regex:var:1" version="2" datatype="string" comment="regex to identify pam_faillock.so entries in auth section of pam files">
      <oval-def:value>^[\s]*auth[\s]+(required|\[(?=.*?\bsuccess=ok\b)(?=.*?\bnew_authtok_reqd=ok\b)(?=.*?\bignore=ignore\b)(?=.*?\bdefault=bad\b).*\])[\s]+pam_faillock\.so[\s\w\d=]+preauth[\s\S]*^[\s]*auth[\s]+(sufficient|\[(?=.*\bsuccess=done\b)(?=.*?\bnew_authtok_reqd=done\b)(?=.*?\bdefault=ignore\b).*\])[\s]+pam_unix\.so[\s\S]*^[\s]*auth[\s]+(required|\[(?=.*?\bsuccess=ok\b)(?=.*?\bnew_authtok_reqd=ok\b)(?=.*?\bignore=ignore\b)(?=.*?\bdefault=bad\b).*\])[\s]+pam_faillock\.so[\s\w\d=]+authfail</oval-def:value>
    </oval-def:constant_variable>
    <oval-def:constant_variable id="oval:ssg-var_accounts_passwords_pam_faillock_deny_pam_faillock_account_regex:var:1" version="2" datatype="string" comment="regex to identify pam_faillock.so entry in account section of pam files">
      <oval-def:value>^[\s]*account[\s]+(required|\[(?=.*?\bsuccess=ok\b)(?=.*?\bnew_authtok_reqd=ok\b)(?=.*?\bignore=ignore\b)(?=.*?\bdefault=bad\b).*\])[\s]+pam_faillock\.so[\s\S]*^[\s]*account[\s]+(required|\[(?=.*?\bsuccess=ok\b)(?=.*?\bnew_authtok_reqd=ok\b)(?=.*?\bignore=ignore\b)(?=.*?\bdefault=bad\b).*\])[\s]+pam_unix\.so</oval-def:value>
    </oval-def:constant_variable>
    <oval-def:constant_variable id="oval:ssg-var_accounts_passwords_pam_faillock_deny_pam_faillock_deny_parameter_regex:var:1" version="1" datatype="string" comment="regex to identify pam_faillock.so deny entry in auth section of pam files">
      <oval-def:value>^[\s]*auth[\s]+.+[\s]+pam_faillock.so[\s]+[^\n]*deny=([0-9]+)</oval-def:value>
    </oval-def:constant_variable>
    <oval-def:constant_variable id="oval:ssg-var_accounts_passwords_pam_faillock_deny_faillock_conf_deny_parameter_regex:var:1" version="1" datatype="string" comment="regex to identify deny entry in /etc/security/faillock.conf">
      <oval-def:value>^[\s]*deny[\s]*=[\s]*([0-9]+)</oval-def:value>
    </oval-def:constant_variable>
    <oval-def:external_variable id="oval:ssg-var_accounts_passwords_pam_faillock_deny:var:1" version="1" datatype="int" comment="external variable to use" />
    <oval-def:constant_variable id="oval:ssg-var_accounts_passwords_pam_faillock_fail_interval_pam_unix_regex:var:1" version="2" datatype="string" comment="regex to identify pam_unix.so in auth section of pam files">
      <oval-def:value>^\s*auth\N+pam_unix\.so</oval-def:value>
    </oval-def:constant_variable>
    <oval-def:constant_variable id="oval:ssg-var_accounts_passwords_pam_faillock_fail_interval_pam_faillock_auth_regex:var:1" version="2" datatype="string" comment="regex to identify pam_faillock.so entries in auth section of pam files">
      <oval-def:value>^[\s]*auth[\s]+(required|\[(?=.*?\bsuccess=ok\b)(?=.*?\bnew_authtok_reqd=ok\b)(?=.*?\bignore=ignore\b)(?=.*?\bdefault=bad\b).*\])[\s]+pam_faillock\.so[\s\w\d=]+preauth[\s\S]*^[\s]*auth[\s]+(sufficient|\[(?=.*\bsuccess=done\b)(?=.*?\bnew_authtok_reqd=done\b)(?=.*?\bdefault=ignore\b).*\])[\s]+pam_unix\.so[\s\S]*^[\s]*auth[\s]+(required|\[(?=.*?\bsuccess=ok\b)(?=.*?\bnew_authtok_reqd=ok\b)(?=.*?\bignore=ignore\b)(?=.*?\bdefault=bad\b).*\])[\s]+pam_faillock\.so[\s\w\d=]+authfail</oval-def:value>
    </oval-def:constant_variable>
    <oval-def:constant_variable id="oval:ssg-var_accounts_passwords_pam_faillock_fail_interval_pam_faillock_account_regex:var:1" version="2" datatype="string" comment="regex to identify pam_faillock.so entry in account section of pam files">
      <oval-def:value>^[\s]*account[\s]+(required|\[(?=.*?\bsuccess=ok\b)(?=.*?\bnew_authtok_reqd=ok\b)(?=.*?\bignore=ignore\b)(?=.*?\bdefault=bad\b).*\])[\s]+pam_faillock\.so[\s\S]*^[\s]*account[\s]+(required|\[(?=.*?\bsuccess=ok\b)(?=.*?\bnew_authtok_reqd=ok\b)(?=.*?\bignore=ignore\b)(?=.*?\bdefault=bad\b).*\])[\s]+pam_unix\.so</oval-def:value>
    </oval-def:constant_variable>
    <oval-def:constant_variable id="oval:ssg-var_accounts_passwords_pam_faillock_fail_interval_pam_faillock_fail_interval_parameter_regex:var:1" version="1" datatype="string" comment="regex to identify pam_faillock.so fail_interval entry in auth section of pam files">
      <oval-def:value>^[\s]*auth[\s]+.+[\s]+pam_faillock.so[\s]+[^\n]*fail_interval=([0-9]+)</oval-def:value>
    </oval-def:constant_variable>
    <oval-def:constant_variable id="oval:ssg-var_accounts_passwords_pam_faillock_fail_interval_faillock_conf_fail_interval_parameter_regex:var:1" version="1" datatype="string" comment="regex to identify fail_interval entry in /etc/security/faillock.conf">
      <oval-def:value>^[\s]*fail_interval[\s]*=[\s]*([0-9]+)</oval-def:value>
    </oval-def:constant_variable>
    <oval-def:external_variable id="oval:ssg-var_accounts_passwords_pam_faillock_fail_interval:var:1" version="1" datatype="int" comment="external variable to use" />
    <oval-def:constant_variable id="oval:ssg-var_accounts_passwords_pam_faillock_unlock_time_pam_unix_regex:var:1" version="2" datatype="string" comment="regex to identify pam_unix.so in auth section of pam files">
      <oval-def:value>^\s*auth\N+pam_unix\.so</oval-def:value>
    </oval-def:constant_variable>
    <oval-def:constant_variable id="oval:ssg-var_accounts_passwords_pam_faillock_unlock_time_pam_faillock_auth_regex:var:1" version="2" datatype="string" comment="regex to identify pam_faillock.so entries in auth section of pam files">
      <oval-def:value>^[\s]*auth[\s]+(required|\[(?=.*?\bsuccess=ok\b)(?=.*?\bnew_authtok_reqd=ok\b)(?=.*?\bignore=ignore\b)(?=.*?\bdefault=bad\b).*\])[\s]+pam_faillock\.so[\s\w\d=]+preauth[\s\S]*^[\s]*auth[\s]+(sufficient|\[(?=.*\bsuccess=done\b)(?=.*?\bnew_authtok_reqd=done\b)(?=.*?\bdefault=ignore\b).*\])[\s]+pam_unix\.so[\s\S]*^[\s]*auth[\s]+(required|\[(?=.*?\bsuccess=ok\b)(?=.*?\bnew_authtok_reqd=ok\b)(?=.*?\bignore=ignore\b)(?=.*?\bdefault=bad\b).*\])[\s]+pam_faillock\.so[\s\w\d=]+authfail</oval-def:value>
    </oval-def:constant_variable>
    <oval-def:constant_variable id="oval:ssg-var_accounts_passwords_pam_faillock_unlock_time_pam_faillock_account_regex:var:1" version="2" datatype="string" comment="regex to identify pam_faillock.so entry in account section of pam files">
      <oval-def:value>^[\s]*account[\s]+(required|\[(?=.*?\bsuccess=ok\b)(?=.*?\bnew_authtok_reqd=ok\b)(?=.*?\bignore=ignore\b)(?=.*?\bdefault=bad\b).*\])[\s]+pam_faillock\.so[\s\S]*^[\s]*account[\s]+(required|\[(?=.*?\bsuccess=ok\b)(?=.*?\bnew_authtok_reqd=ok\b)(?=.*?\bignore=ignore\b)(?=.*?\bdefault=bad\b).*\])[\s]+pam_unix\.so</oval-def:value>
    </oval-def:constant_variable>
    <oval-def:constant_variable id="oval:ssg-var_accounts_passwords_pam_faillock_unlock_time_pam_faillock_unlock_time_parameter_regex:var:1" version="1" datatype="string" comment="regex to identify pam_faillock.so unlock_time entry in auth section of pam files">
      <oval-def:value>^[\s]*auth[\s]+.+[\s]+pam_faillock.so[\s]+[^\n]*unlock_time=([0-9]+)</oval-def:value>
    </oval-def:constant_variable>
    <oval-def:constant_variable id="oval:ssg-var_accounts_passwords_pam_faillock_unlock_time_faillock_conf_unlock_time_parameter_regex:var:1" version="1" datatype="string" comment="regex to identify unlock_time entry in /etc/security/faillock.conf">
      <oval-def:value>^[\s]*unlock_time[\s]*=[\s]*([0-9]+)</oval-def:value>
    </oval-def:constant_variable>
    <oval-def:local_variable id="oval:ssg-var_file_groupownerdir_group_ownership_library_dirs_0_gid:var:1" version="1" datatype="int" comment="Set the gid to 0">
      <oval-def:literal_component datatype="int">0</oval-def:literal_component>
    </oval-def:local_variable>
    <oval-def:local_variable id="oval:ssg-var_file_groupownerdir_groupowner_system_journal_systemd-journal_gid:var:1" version="1" datatype="int" comment="Retrieve the gid of systemd-journal from either /etc/group or /usr/lib/group">
      <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_file_groupownerdir_groupowner_system_journal_systemd-journal_gid:obj:1" />
    </oval-def:local_variable>
    <oval-def:local_variable id="oval:ssg-var_file_groupownerdir_groupownership_binary_dirs_0_gid:var:1" version="1" datatype="int" comment="Set the gid to 0">
      <oval-def:literal_component datatype="int">0</oval-def:literal_component>
    </oval-def:local_variable>
    <oval-def:local_variable id="oval:ssg-var_file_ownerdir_owner_system_journal_0_uid:var:1" version="1" datatype="int" comment="Set the uid to 0">
      <oval-def:literal_component datatype="int">0</oval-def:literal_component>
    </oval-def:local_variable>
    <oval-def:local_variable id="oval:ssg-var_file_ownerdir_ownership_binary_dirs_0_uid:var:1" version="1" datatype="int" comment="Set the uid to 0">
      <oval-def:literal_component datatype="int">0</oval-def:literal_component>
    </oval-def:local_variable>
    <oval-def:local_variable id="oval:ssg-var_file_ownerdir_ownership_library_dirs_0_uid:var:1" version="1" datatype="int" comment="Set the uid to 0">
      <oval-def:literal_component datatype="int">0</oval-def:literal_component>
    </oval-def:local_variable>
    <oval-def:local_variable id="oval:ssg-var_file_groupowner_journalctl_0_gid:var:1" version="1" datatype="int" comment="Set the gid to 0">
      <oval-def:literal_component datatype="int">0</oval-def:literal_component>
    </oval-def:local_variable>
    <oval-def:local_variable id="oval:ssg-var_file_groupowner_system_journal_systemd-journal_gid:var:1" version="1" datatype="int" comment="Retrieve the gid of systemd-journal from either /etc/group or /usr/lib/group">
      <oval-def:object_component item_field="subexpression" object_ref="oval:ssg-object_file_groupowner_system_journal_systemd-journal_gid:obj:1" />
    </oval-def:local_variable>
    <oval-def:local_variable id="oval:ssg-var_file_groupowner_var_log_0_gid:var:1" version="1" datatype="int" comment="Set the gid to 0">
      <oval-def:literal_component datatype="int">0</oval-def:literal_component>
    </oval-def:local_variable>
    <oval-def:local_variable id="oval:ssg-var_file_groupowner_var_log_syslog_4_gid:var:1" version="1" datatype="int" comment="Set the gid to 4">
      <oval-def:literal_component datatype="int">4</oval-def:literal_component>
    </oval-def:local_variable>
    <oval-def:local_variable id="oval:ssg-var_file_groupownership_audit_configuration_0_gid:var:1" version="1" datatype="int" comment="Set the gid to 0">
      <oval-def:literal_component datatype="int">0</oval-def:literal_component>
    </oval-def:local_variable>
    <oval-def:local_variable id="oval:ssg-var_file_owner_journalctl_0_uid:var:1" version="1" datatype="int" comment="Set the uid to 0">
      <oval-def:literal_component datatype="int">0</oval-def:literal_component>
    </oval-def:local_variable>
    <oval-def:local_variable id="oval:ssg-var_file_owner_system_journal_0_uid:var:1" version="1" datatype="int" comment="Set the uid to 0">
      <oval-def:literal_component datatype="int">0</oval-def:literal_component>
    </oval-def:local_variable>
    <oval-def:local_variable id="oval:ssg-var_file_owner_var_log_0_uid:var:1" version="1" datatype="int" comment="Set the uid to 0">
      <oval-def:literal_component datatype="int">0</oval-def:literal_component>
    </oval-def:local_variable>
    <oval-def:local_variable id="oval:ssg-var_file_owner_var_log_syslog_syslog_uid:var:1" version="1" datatype="int" comment="Retrieve the uid of syslog">
      <oval-def:object_component item_field="user_id" object_ref="oval:ssg-object_file_owner_var_log_syslog_syslog_uid:obj:1" />
    </oval-def:local_variable>
    <oval-def:local_variable id="oval:ssg-var_file_ownership_audit_binaries_0_uid:var:1" version="1" datatype="int" comment="Set the uid to 0">
      <oval-def:literal_component datatype="int">0</oval-def:literal_component>
    </oval-def:local_variable>
    <oval-def:local_variable id="oval:ssg-var_file_ownership_audit_configuration_0_uid:var:1" version="1" datatype="int" comment="Set the uid to 0">
      <oval-def:literal_component datatype="int">0</oval-def:literal_component>
    </oval-def:local_variable>
    <oval-def:local_variable id="oval:ssg-var_file_ownership_library_dirs_0_uid:var:1" version="1" datatype="int" comment="Set the uid to 0">
      <oval-def:literal_component datatype="int">0</oval-def:literal_component>
    </oval-def:local_variable>
    <oval-def:constant_variable id="oval:ssg-var_kernel_module_usb-storage_paths:var:1" version="1" datatype="string" comment="Other paths where kernel modules can be configured">
      <oval-def:value>/etc/modprobe.d</oval-def:value>
      <oval-def:value>/etc/modules-load.d</oval-def:value>
      <oval-def:value>/run/modprobe.d</oval-def:value>
      <oval-def:value>/run/modules-load.d</oval-def:value>
      <oval-def:value>/usr/lib/modprobe.d</oval-def:value>
      <oval-def:value>/usr/lib/modules-load.d</oval-def:value>
    </oval-def:constant_variable>
    <oval-def:local_variable id="oval:ssg-var_file_groupownerroot_permissions_syslibrary_files_0_gid:var:1" version="1" datatype="int" comment="Set the gid to 0">
      <oval-def:literal_component datatype="int">0</oval-def:literal_component>
    </oval-def:local_variable>
    <oval-def:external_variable id="oval:ssg-sysctl_net_ipv4_tcp_syncookies_value:var:1" version="1" datatype="int" comment="External variable for net.ipv4.tcp_syncookies" />
  </oval-def:variables>
</oval-def:oval_definitions>