diff --git a/bin/hardening/9.3.8_disable_root_login.sh b/bin/hardening/5.2.10_disable_root_login.sh similarity index 98% rename from bin/hardening/9.3.8_disable_root_login.sh rename to bin/hardening/5.2.10_disable_root_login.sh index 1de2668..3b01009 100755 --- a/bin/hardening/9.3.8_disable_root_login.sh +++ b/bin/hardening/5.2.10_disable_root_login.sh @@ -5,7 +5,7 @@ # # -# 9.3.8 Disable SSH Root Login (Scored) +# 5.2.10 Ensure SSH root login is disabled (Scored) # set -e # One error, it's over diff --git a/bin/hardening/9.3.9_disable_sshd_permitemptypasswords.sh b/bin/hardening/5.2.11_disable_sshd_permitemptypasswords.sh similarity index 97% rename from bin/hardening/9.3.9_disable_sshd_permitemptypasswords.sh rename to bin/hardening/5.2.11_disable_sshd_permitemptypasswords.sh index 1ebe36a..39bbb1a 100755 --- a/bin/hardening/9.3.9_disable_sshd_permitemptypasswords.sh +++ b/bin/hardening/5.2.11_disable_sshd_permitemptypasswords.sh @@ -5,7 +5,7 @@ # # -# 9.3.9 Set SSH PermitEmptyPasswords to No (Scored) +# 5.2.11 Ensure SSH PermitEmptyPasswords is disabled (Scored) # set -e # One error, it's over diff --git a/bin/hardening/9.3.10_disable_sshd_setenv.sh b/bin/hardening/5.2.12_disable_sshd_setenv.sh similarity index 97% rename from bin/hardening/9.3.10_disable_sshd_setenv.sh rename to bin/hardening/5.2.12_disable_sshd_setenv.sh index 6af3e84..514c222 100755 --- a/bin/hardening/9.3.10_disable_sshd_setenv.sh +++ b/bin/hardening/5.2.12_disable_sshd_setenv.sh @@ -5,7 +5,7 @@ # # -# 9.3.10 Do Not Allow Users to Set Environment Options (Scored) +# 5.2.12 Ensure SSH PermitUserEnvironment is disabled (Scored) # set -e # One error, it's over diff --git a/bin/hardening/9.3.11_sshd_ciphers.sh b/bin/hardening/5.2.13_sshd_ciphers.sh similarity index 98% rename from bin/hardening/9.3.11_sshd_ciphers.sh rename to bin/hardening/5.2.13_sshd_ciphers.sh index 2713c6e..8c16860 100755 --- a/bin/hardening/9.3.11_sshd_ciphers.sh +++ b/bin/hardening/5.2.13_sshd_ciphers.sh @@ -5,7 +5,7 @@ # # -# 9.3.11 Use Only Approved Cipher in Counter Mode (Scored) +# 5.2.13 Ensure only strong ciphers are used (Scored) # set -e # One error, it's over diff --git a/bin/hardening/99.5.2.2_ssh_cry_mac.sh b/bin/hardening/5.2.14_ssh_cry_mac.sh similarity index 96% rename from bin/hardening/99.5.2.2_ssh_cry_mac.sh rename to bin/hardening/5.2.14_ssh_cry_mac.sh index bf6e0b9..eb96b9e 100755 --- a/bin/hardening/99.5.2.2_ssh_cry_mac.sh +++ b/bin/hardening/5.2.14_ssh_cry_mac.sh @@ -6,7 +6,7 @@ # # -# Checking Message Authentication Code ciphers for preferred UMAC and SHA-256|512 with Encrypt-Then-Mac (etm) setting. +# 5.2.14 Ensure only strong MAC algorithms are used (Scored) # set -e # One error, it's over diff --git a/bin/hardening/99.5.2.1_ssh_cry_kex.sh b/bin/hardening/5.2.15_ssh_cry_kex.sh similarity index 98% rename from bin/hardening/99.5.2.1_ssh_cry_kex.sh rename to bin/hardening/5.2.15_ssh_cry_kex.sh index faa1bae..99e155b 100755 --- a/bin/hardening/99.5.2.1_ssh_cry_kex.sh +++ b/bin/hardening/5.2.15_ssh_cry_kex.sh @@ -6,7 +6,7 @@ # # -# Checking key exchange ciphers. +# 5.2.15 Ensure only strong Key Exchange algorithms are used (Scored) # set -e # One error, it's over diff --git a/bin/hardening/9.3.12_sshd_idle_timeout.sh b/bin/hardening/5.2.16_sshd_idle_timeout.sh similarity index 97% rename from bin/hardening/9.3.12_sshd_idle_timeout.sh rename to bin/hardening/5.2.16_sshd_idle_timeout.sh index 98aaa4d..3588e12 100755 --- a/bin/hardening/9.3.12_sshd_idle_timeout.sh +++ b/bin/hardening/5.2.16_sshd_idle_timeout.sh @@ -5,7 +5,7 @@ # # -# 9.3.12 Set Idle Timeout Interval for User Login (Scored) +# 5.2.16 Ensure SSH Idle Timeout Interval is configured (Scored) # FIXME: the implementation of this script doesn't do what it says # @@ -76,7 +76,7 @@ create_config() { status=audit # In seconds, value of ClientAliveInterval, ClientAliveCountMax bedoing set to 0 # Settles sshd idle timeout -SSHD_TIMEOUT=900 +SSHD_TIMEOUT=300 EOF } diff --git a/bin/hardening/9.3.13_sshd_limit_access.sh b/bin/hardening/5.2.18_sshd_limit_access.sh similarity index 98% rename from bin/hardening/9.3.13_sshd_limit_access.sh rename to bin/hardening/5.2.18_sshd_limit_access.sh index a4d75ad..58be24a 100755 --- a/bin/hardening/9.3.13_sshd_limit_access.sh +++ b/bin/hardening/5.2.18_sshd_limit_access.sh @@ -5,7 +5,7 @@ # # -# 9.3.13 Limit Access via SSH (Scored) +# 5.2.18 Ensure SSH access is limited (Scored) # set -e # One error, it's over diff --git a/bin/hardening/9.3.14_ssh_banner.sh b/bin/hardening/5.2.19_ssh_banner.sh similarity index 98% rename from bin/hardening/9.3.14_ssh_banner.sh rename to bin/hardening/5.2.19_ssh_banner.sh index 5f52511..8158cf0 100755 --- a/bin/hardening/9.3.14_ssh_banner.sh +++ b/bin/hardening/5.2.19_ssh_banner.sh @@ -5,7 +5,7 @@ # # -# 9.3.14 Set SSH Banner (Scored) +# 5.2.19 Ensure SSH warning banner is configured (Scored) # set -e # One error, it's over diff --git a/bin/hardening/9.3.3_sshd_conf_perm_ownership.sh b/bin/hardening/5.2.1_sshd_conf_perm_ownership.sh similarity index 96% rename from bin/hardening/9.3.3_sshd_conf_perm_ownership.sh rename to bin/hardening/5.2.1_sshd_conf_perm_ownership.sh index c0687cf..cb2e24c 100755 --- a/bin/hardening/9.3.3_sshd_conf_perm_ownership.sh +++ b/bin/hardening/5.2.1_sshd_conf_perm_ownership.sh @@ -5,7 +5,7 @@ # # -# 9.3.3 Set Permissions on /etc/ssh/sshd_config (Scored) +# 5.2.1 Ensure permissions on /etc/ssh/sshd_config are configured (Scored) # set -e # One error, it's over diff --git a/bin/hardening/9.3.1_sshd_protocol.sh b/bin/hardening/5.2.4_sshd_protocol.sh similarity index 98% rename from bin/hardening/9.3.1_sshd_protocol.sh rename to bin/hardening/5.2.4_sshd_protocol.sh index 3d7d031..1e57c18 100755 --- a/bin/hardening/9.3.1_sshd_protocol.sh +++ b/bin/hardening/5.2.4_sshd_protocol.sh @@ -5,7 +5,7 @@ # # -# 9.3.1 Set SSH Protocol to 2 (Scored) +# 5.2.4 Ensure SSH Protocol is set to 2 (Scored) # set -e # One error, it's over diff --git a/bin/hardening/9.3.2_sshd_loglevel.sh b/bin/hardening/5.2.5_sshd_loglevel.sh similarity index 98% rename from bin/hardening/9.3.2_sshd_loglevel.sh rename to bin/hardening/5.2.5_sshd_loglevel.sh index 1ab98a1..c4eb31e 100755 --- a/bin/hardening/9.3.2_sshd_loglevel.sh +++ b/bin/hardening/5.2.5_sshd_loglevel.sh @@ -6,7 +6,7 @@ # # -# 9.3.2 Set LogLevel to INFO (Scored) +# 5.2.5 Ensure SSH LogLevel is appropriate (Scored) # set -e # One error, it's over diff --git a/bin/hardening/9.3.4_disable_x11_forwarding.sh b/bin/hardening/5.2.6_disable_x11_forwarding.sh similarity index 98% rename from bin/hardening/9.3.4_disable_x11_forwarding.sh rename to bin/hardening/5.2.6_disable_x11_forwarding.sh index dadc1c0..98e59e8 100755 --- a/bin/hardening/9.3.4_disable_x11_forwarding.sh +++ b/bin/hardening/5.2.6_disable_x11_forwarding.sh @@ -5,7 +5,7 @@ # # -# 9.3.4 Disable SSH X11 Forwarding (Scored) +# 5.2.6 Ensure SSH X11 forwarding is disabled (Scored) # set -e # One error, it's over diff --git a/bin/hardening/9.3.5_sshd_maxauthtries.sh b/bin/hardening/5.2.7_sshd_maxauthtries.sh similarity index 97% rename from bin/hardening/9.3.5_sshd_maxauthtries.sh rename to bin/hardening/5.2.7_sshd_maxauthtries.sh index 5e4e6ae..f0e90f7 100755 --- a/bin/hardening/9.3.5_sshd_maxauthtries.sh +++ b/bin/hardening/5.2.7_sshd_maxauthtries.sh @@ -5,7 +5,7 @@ # # -# 9.3.5 Set SSH MaxAuthTries to 4 or Less (Scored) +# 5.2.7 Ensure SSH MaxAuthTries is set to 4 or less (Scored) # set -e # One error, it's over diff --git a/bin/hardening/9.3.6_enable_sshd_ignorerhosts.sh b/bin/hardening/5.2.8_enable_sshd_ignorerhosts.sh similarity index 98% rename from bin/hardening/9.3.6_enable_sshd_ignorerhosts.sh rename to bin/hardening/5.2.8_enable_sshd_ignorerhosts.sh index dbed72b..380f092 100755 --- a/bin/hardening/9.3.6_enable_sshd_ignorerhosts.sh +++ b/bin/hardening/5.2.8_enable_sshd_ignorerhosts.sh @@ -5,7 +5,7 @@ # # -# 9.3.6 Set SSH IgnoreRhosts to Yes (Scored) +# 5.2.8 Set SSH IgnoreRhosts to Yes (Scored) # set -e # One error, it's over diff --git a/bin/hardening/9.3.7_disable_sshd_hostbasedauthentication.sh b/bin/hardening/5.2.9_disable_sshd_hostbasedauthentication.sh similarity index 97% rename from bin/hardening/9.3.7_disable_sshd_hostbasedauthentication.sh rename to bin/hardening/5.2.9_disable_sshd_hostbasedauthentication.sh index 4d2fc87..5e5c7e6 100755 --- a/bin/hardening/9.3.7_disable_sshd_hostbasedauthentication.sh +++ b/bin/hardening/5.2.9_disable_sshd_hostbasedauthentication.sh @@ -5,7 +5,7 @@ # # -# 9.3.7 Set SSH HostbasedAuthentication to No (Scored) +# 5.2.9 Ensure SSH HostbasedAuthentication is disabled (Scored) # set -e # One error, it's over diff --git a/tests/hardening/9.3.10_disable_sshd_setenv.sh b/tests/hardening/5.2.10_disable_root_login.sh similarity index 100% rename from tests/hardening/9.3.10_disable_sshd_setenv.sh rename to tests/hardening/5.2.10_disable_root_login.sh diff --git a/tests/hardening/9.3.11_sshd_ciphers.sh b/tests/hardening/5.2.11_disable_sshd_permitemptypasswords.sh similarity index 100% rename from tests/hardening/9.3.11_sshd_ciphers.sh rename to tests/hardening/5.2.11_disable_sshd_permitemptypasswords.sh diff --git a/tests/hardening/9.3.12_sshd_idle_timeout.sh b/tests/hardening/5.2.12_disable_sshd_setenv.sh similarity index 100% rename from tests/hardening/9.3.12_sshd_idle_timeout.sh rename to tests/hardening/5.2.12_disable_sshd_setenv.sh diff --git a/tests/hardening/9.3.13_sshd_limit_access.sh b/tests/hardening/5.2.13_sshd_ciphers.sh similarity index 100% rename from tests/hardening/9.3.13_sshd_limit_access.sh rename to tests/hardening/5.2.13_sshd_ciphers.sh diff --git a/tests/hardening/99.5.2.2_ssh_cry_mac.sh b/tests/hardening/5.2.14_ssh_cry_mac.sh similarity index 100% rename from tests/hardening/99.5.2.2_ssh_cry_mac.sh rename to tests/hardening/5.2.14_ssh_cry_mac.sh diff --git a/tests/hardening/99.5.2.1_ssh_cry_kex.sh b/tests/hardening/5.2.15_ssh_cry_kex.sh similarity index 100% rename from tests/hardening/99.5.2.1_ssh_cry_kex.sh rename to tests/hardening/5.2.15_ssh_cry_kex.sh diff --git a/tests/hardening/9.3.14_ssh_banner.sh b/tests/hardening/5.2.16_sshd_idle_timeout.sh similarity index 100% rename from tests/hardening/9.3.14_ssh_banner.sh rename to tests/hardening/5.2.16_sshd_idle_timeout.sh diff --git a/tests/hardening/9.3.1_sshd_protocol.sh b/tests/hardening/5.2.18_sshd_limit_access.sh similarity index 100% rename from tests/hardening/9.3.1_sshd_protocol.sh rename to tests/hardening/5.2.18_sshd_limit_access.sh diff --git a/tests/hardening/9.3.3_sshd_conf_perm_ownership.sh b/tests/hardening/5.2.19_ssh_banner.sh similarity index 100% rename from tests/hardening/9.3.3_sshd_conf_perm_ownership.sh rename to tests/hardening/5.2.19_ssh_banner.sh diff --git a/tests/hardening/9.3.4_disable_x11_forwarding.sh b/tests/hardening/5.2.1_sshd_conf_perm_ownership.sh similarity index 100% rename from tests/hardening/9.3.4_disable_x11_forwarding.sh rename to tests/hardening/5.2.1_sshd_conf_perm_ownership.sh diff --git a/tests/hardening/9.3.5_sshd_maxauthtries.sh b/tests/hardening/5.2.4_sshd_protocol.sh similarity index 100% rename from tests/hardening/9.3.5_sshd_maxauthtries.sh rename to tests/hardening/5.2.4_sshd_protocol.sh diff --git a/tests/hardening/9.3.2_sshd_loglevel.sh b/tests/hardening/5.2.5_sshd_loglevel.sh similarity index 100% rename from tests/hardening/9.3.2_sshd_loglevel.sh rename to tests/hardening/5.2.5_sshd_loglevel.sh diff --git a/tests/hardening/9.3.6_enable_sshd_ignorerhosts.sh b/tests/hardening/5.2.6_disable_x11_forwarding.sh similarity index 100% rename from tests/hardening/9.3.6_enable_sshd_ignorerhosts.sh rename to tests/hardening/5.2.6_disable_x11_forwarding.sh diff --git a/tests/hardening/9.3.7_disable_sshd_hostbasedauthentication.sh b/tests/hardening/5.2.7_sshd_maxauthtries.sh similarity index 100% rename from tests/hardening/9.3.7_disable_sshd_hostbasedauthentication.sh rename to tests/hardening/5.2.7_sshd_maxauthtries.sh diff --git a/tests/hardening/9.3.8_disable_root_login.sh b/tests/hardening/5.2.8_enable_sshd_ignorerhosts.sh similarity index 100% rename from tests/hardening/9.3.8_disable_root_login.sh rename to tests/hardening/5.2.8_enable_sshd_ignorerhosts.sh diff --git a/tests/hardening/9.3.9_disable_sshd_permitemptypasswords.sh b/tests/hardening/5.2.9_disable_sshd_hostbasedauthentication.sh similarity index 100% rename from tests/hardening/9.3.9_disable_sshd_permitemptypasswords.sh rename to tests/hardening/5.2.9_disable_sshd_hostbasedauthentication.sh