[BESAdmin-Announcements] BigFix Compliance: Updated DISA STIG Checklist for Oracle Linux 8, published 2026-9-14
Announcements for BES Administrators
besadmin-announcements at bigmail.bigfix.com
Tue Sep 15 10:48:05 PDT 2026
*Product:*
BigFix Compliance
*Title:*
Updated DISA STIG Checklist for Oracle Linux 8
*Security Benchmark:*
Oracle Linux 8 Security Technical Implementation Guide , V2R9
*Published Sites:*
DISA STIG Checklist for Oracle Linux 8, site version 14
(The site version is provided for air-gap customers.)
*Details: *
● Total New Fixlets: 9
● Total Updated Fixlets: 4
● Total Deleted Fixlets: 6
● Total Fixlets in Site: 374
*New Fixlets:*
● Oracle Linux must elevate the SELinux context when an administrator
calls the sudo command.
● OL 8 must have the crypto-policies package installed.
● OL 8 must implement a FIPS 140-3-compliant systemwide cryptographic
policy.
● OL 8 must implement NIST FIPS-validated cryptography for the
following: To provision digital signatures, to generate cryptographic
hashes, and to protect data requiring data-at-rest protections in
accordance with applicable federal laws, Executive Orders, directives,
policies, regulations, and standards.
● OL 8 cryptographic policy must not be overridden.
● The OL 8 SSH client must be configured to use only DOD-approved
encryption ciphers employing FIPS 140-3-validated cryptographic hash
algorithms to protect the confidentiality of SSH client connections.
● The OL 8 SSH client must be configured to use only DOD-approved
Message Authentication Codes (MACs) employing FIPS 140-3-validated
cryptographic hash algorithms to protect the confidentiality of SSH client
connections.
● OL 8 IP tunnels must use FIPS 140-3-approved cryptographic
algorithms.
● OL 8 must implement DOD-approved encryption in the bind package.
*Updated Fixlets:*
● OL 8 must implement a FIPS 140-3-compliant systemwide cryptographic
policy.
● The OL 8 SSH private host key files must have mode "0600" or less
permissive.
● The OL 8 SSH server must be configured to use only Message
Authentication Codes (MACs) employing FIPS 140-3 validated cryptographic
hash algorithms to protect the confidentiality of SSH server connections.
● The OL 8 SSH server must be configured to use only DOD-approved
encryption ciphers employing FIPS 140-3 validated cryptographic hash
algorithms to protect the confidentiality of SSH server connections.
*Deleted Fixlets:*
● The OL 8 SSH daemon must be configured to use system-wide crypto
policies.
● The OL 8 operating system must implement DOD-approved encryption in
the OpenSSL package.
● The OL 8 operating system must implement DoD-approved TLS encryption
in the OpenSSL package.
● The OL 8 operating system must implement DoD-approved TLS encryption
in the GnuTLS package.
● OL 8 SSH server must be configured to use only FIPS-validated key
exchange algorithms.
● OL 8 passwords for new users must have a minimum of 15 characters.
*Additional details:*
● Both analysis and remediation checks are included.
● Some of the checks allow you to use the parameterized setting to
enable customization for compliance evaluation. Note that parameterization
and remediation actions require the creation of a custom site.
● Improved a few checks by adding the pending restart feature to them.
The pending restart feature works in the following ways:
● The action results will show “Pending Restart” instead of “Fixed”
for those checks which require OS reboot.
● The check will show relevant for those endpoints until they are
rebooted.
● Post reboot of the endpoint the action results will show as “Fixed”
and the check will be compliant.
*Action to take:*
● To subscribe to the above site, you can use the License Overview
Dashboard to enable and gather the site. Note that you must be entitled to
the BigFix Compliance product and you must be using BigFix version 10.0.0
and later.
● If you use custom sites, update your custom sites accordingly to use
the latest content. You can synchronize your content by using the
Synchronize Custom Checks wizard. For more information, see Using the
Synchronize Custom Checks wizard
<https://help.hcltechsw.com/bigfix/11.0/compliance/Compliance/SCM_Users_Guide/c_using_synchronize_custom_checks_wiz.html>
*More information: *To know more about the BigFix Compliance SCM
checklists, please see the following resources:
● BigFix Forum:
*Compliance (Release Announcements)*
<https://forum.bigfix.com/c/release-announcements/compliance/63>
This category is used by HCL to announce new releases for BigFix
Compliance.
● BigFix Compliance SCM Checklists:
*SCM Checklists*
<https://forum.bigfix.com/c/release-announcements/scm-checklists/86>
This category is the central reference for all SCM Checklists supported by
BigFix Compliance. It covers the complete list of active checklists across
all supported frameworks and platforms, including CIS, DISA STIG, PCI DSS,
NIST, and more, along with site name, version details, and supported OS
versions.
We hope you find this latest release of SCM content useful and effective.
Thank you!
*– The BigFix Compliance team*
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://bigmail.bigfix.com/pipermail/besadmin-announcements/attachments/20260915/29997199/attachment.html>
More information about the Besadmin-announcements
mailing list