SV-230499r627750_rule
V-230499
SRG-OS-000095-GPOS-00049
RHEL-08-040026
CAT III
10
Configure the operating system to disable the ability to use the firewire-core kernel module.
Add or update the following lines in the file "/etc/modprobe.d/blacklist.conf":
install firewire-core /bin/true
blacklist firewire-core
Reboot the system for the settings to take effect.
Verify the operating system disables the ability to load the firewire-core kernel module.
$ sudo grep -ri firewire-core /etc/modprobe.d/* | grep -i "/bin/true"
install firewire-core /bin/true
If the command does not return any output, or the line is commented out, and use of the firewire-core protocol is not documented with the Information System Security Officer (ISSO) as an operational requirement, this is a finding.
Verify the operating system disables the ability to use the firewire-core kernel module.
Check to see if the firewire-core kernel module is disabled with the following command:
$ sudo grep -ri firewire-core /etc/modprobe.d/* | grep -i "blacklist"
blacklist firewire-core
If the command does not return any output or the output is not "blacklist firewire-core", and use of the firewire-core kernel module is not documented with the Information System Security Officer (ISSO) as an operational requirement, this is a finding.
V-230499
False
RHEL-08-040026
Verify the operating system disables the ability to load the firewire-core kernel module.
$ sudo grep -ri firewire-core /etc/modprobe.d/* | grep -i "/bin/true"
install firewire-core /bin/true
If the command does not return any output, or the line is commented out, and use of the firewire-core protocol is not documented with the Information System Security Officer (ISSO) as an operational requirement, this is a finding.
Verify the operating system disables the ability to use the firewire-core kernel module.
Check to see if the firewire-core kernel module is disabled with the following command:
$ sudo grep -ri firewire-core /etc/modprobe.d/* | grep -i "blacklist"
blacklist firewire-core
If the command does not return any output or the output is not "blacklist firewire-core", and use of the firewire-core kernel module is not documented with the Information System Security Officer (ISSO) as an operational requirement, this is a finding.
M
2921