setCMHardening

Last Updated : Apr 05, 2018 |

Syntax

Run the following command as a super-user:

 setCMHardening [-w] <enabled>
[-w]

Add the Web Profiles associated with useradmin, switchadmin, maintenance, and auditor. These can be added later if desired by running this command again.

After the command is enabled, the command cannot be undone.

Description

Use setCMHardening to configure a number of system parameters into a hardened state. When you run this command, the system will undergo the following changes:

  • Remove console.perms and console.perms.d

  • Only allow console access in /etc/securetty

  • Disable the kdump service for kernel crash monitoring

  • Configure password strength and expiration policy

  • Configure failed login account locking

  • Change ownership of ppp-login shell to root:root

  • Restrict audit tool permissions to privileged users

  • Restrict crontab permissions to root user

  • Remove the unused rasaccess user

  • Configure session timeouts to 600 seconds for command line and SMI web interfaces

  • Change default lock time for expired accounts to immediate

  • Set the maximum polling time for ntp to 1024 seconds

  • Start ntpd and verify that it is enabled to start at next boot

  • Constrain modules and options used in web server directories