The kernel module cramfs should be disabled.

The kernel module freevxfs should be disabled.

Limit the ciphers to those which are FIPS-approved and only use ciphers in counter (CTR) mode.

The screen saver should be blank.

The kernel module jffs2 should be disabled.

The gpgcheck option should be used to ensure that checking of an RPM package's signature always occurs prior to its installation.

The rsyslog service should be enabled if possible.

The /etc/group file should be owned by the appropriate user.

The /etc/passwd file should be owned by the appropriate group.

This test makes sure that '/etc/passwd' has proper permission. If the target file or directory has an extended ACL then it will fail the mode check.

