Skip to content

Instantly share code, notes, and snippets.

@jboyd01
Created April 24, 2020 10:32
Show Gist options
  • Save jboyd01/da46c69584f2859a150855c57969a09d to your computer and use it in GitHub Desktop.
Save jboyd01/da46c69584f2859a150855c57969a09d to your computer and use it in GitHub Desktop.
<?xml version="1.0" encoding="UTF-8"?>
<xccdf:Tailoring xmlns:xccdf="http://checklists.nist.gov/xccdf/1.2" id="xccdf_scap-workbench_tailoring_default">
<xccdf:benchmark href="/usr/share/xml/scap/ssg/content/ssg-centos7-ds.xml"/>
<xccdf:version time="2020-04-22T02:09:15">1</xccdf:version>
<xccdf:Profile id="xccdf_com.hcl_profile_ssbe_passwords">
<xccdf:title xmlns:xhtml="http://www.w3.org/1999/xhtml" xml:lang="en-US" override="true">PCI-DSS v3.2.1 Control Baseline for Red Hat Enterprise Linux 7 [CUSTOMIZED]</xccdf:title>
<xccdf:description xmlns:xhtml="http://www.w3.org/1999/xhtml" xml:lang="en-US" override="true">**Not applicable to CentOS Linux, included for reference only**
Ensures PCI-DSS v3.2.1 related security configuration settings are applied.</xccdf:description>
<xccdf:select idref="xccdf_org.ssgproject.content_group_intro" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_how-to-use" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_intro-formatting-conventions" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_intro-read-sections-completely" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_intro-test-non-production" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_intro-root-shell-assumed" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_intro-reboot-required" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_general-principles" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_principle-minimize-software" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_principle-separate-servers" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_principle-use-security-tools" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_principle-least-privilege" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_principle-encrypt-transmitted-data" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_remediation_functions" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_services" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_proxy" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_disabling_squid" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_package_squid_removed" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_squid_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_avahi" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_avahi_configuration" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_avahi_prevent_port_sharing" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_avahi_ip_only" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_avahi_restrict_published_information" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_avahi_disable_publishing" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_avahi_check_ttl" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_disable_avahi_group" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_avahi-daemon_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_printing" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_cups_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_configure_printing" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_cups_disable_printserver" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_cups_disable_browsing" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_nfs_and_rpc" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_nfs_configuring_clients" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_disabling_nfsd" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_rpcsvcgssd_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_nfs_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_nfs_no_anonymous" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_mounting_remote_filesystems" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_mount_option_nodev_remote_filesystems" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_mount_option_nosuid_remote_filesystems" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_mount_option_krb_sec_remote_filesystems" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_mount_option_noexec_remote_filesystems" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_nfs_configuring_all_machines" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_nfs_client_or_server_not_both" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_nfs_configure_fixed_ports" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_nfs_fixed_mountd_port" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_nfs_fixed_statd_port" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_nfs_fixed_lockd_udp_port" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_nfs_fixed_lockd_tcp_port" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_disabling_nfs" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_disabling_netfs" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_netfs_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_disabling_nfs_services" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_rpcbind_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_rpcgssd_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_rpcidmapd_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_nfslock_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_nfs_configuring_servers" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_no_insecure_locks_exports" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_use_kerberos_security_all_exports" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_restrict_nfs_clients_to_privileged_ports" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_no_all_squash_exports" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_use_root_squashing_all_exports" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_use_acl_enforce_auth_restrictions" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_configure_exports_restrictively" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_export_filesystems_read_only" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_deprecated" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_package_telnetd_removed" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_package_telnetd-ssl_removed" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_package_ntpdate_removed" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_package_inetutils-telnetd_removed" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_package_nis_removed" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_imap" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_disabling_dovecot" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_dovecot_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_package_dovecot_removed" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_configure_dovecot" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_dovecot_support_necessary_protocols" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_dovecot_allow_imap_access" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_dovecot_enabling_ssl" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_dovecot_configure_ssl_cert" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_dovecot_enable_ssl" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_dovecot_disable_plaintext_auth" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_dovecot_configure_ssl_key" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_mail" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_postfix_enabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_package_sendmail_removed" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_postfix_harden_os" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_postfix_server_cfg" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_postfix_server_banner" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_postfix_server_dos" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_postfix_server_relay" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_postfix_prevent_unrestricted_relay" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_postfix_server_relay_require_tls" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_postfix_server_mail_smtpd_relay_restrictions" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_postfix_server_mail_smtpd_recipient_restrictions" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_postfix_server_relay_smtp_auth_for_untrusted" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_postfix_server_relay_set_trusted" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_postfix_configure_ssl_certs" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_postfix_install_ssl_cert" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_postfix_client" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_postfix_network_listening_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_postfix_client_configure_mail_alias" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_ssh" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_iptables_sshd_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_permissions_sshd_private_key" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_permissions_sshd_pub_key" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_sshd_enabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_firewalld_sshd_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_package_openssh-server_installed" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_sshd_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_ssh_server" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_root_login" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_compression" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_gssapi_auth" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sshd_use_strong_ciphers" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sshd_print_last_log" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sshd_use_priv_separation" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sshd_use_strong_macs" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sshd_set_max_auth_tries" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_firewalld_sshd_port_enabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_disable_host_auth" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sshd_use_approved_ciphers" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sshd_enable_x11_forwarding" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sshd_set_loglevel_info" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sshd_set_idle_timeout" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_rhosts" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sshd_allow_only_protocol2" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_kerb_auth" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sshd_do_not_permit_user_env" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sshd_use_approved_macs" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sshd_enable_warning_banner" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sshd_limit_user_access" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_rhosts_rsa" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sshd_set_keepalive" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_empty_passwords" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sshd_disable_user_known_hosts" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sshd_enable_strictmodes" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_sshd_strengthen_firewall" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_base" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_sysstat_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_portreserve_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_rhsmcertd_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_rdisc_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_ntpdate_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_cgconfig_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_saslauthd_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_cpupower_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_abrtd_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_qpidd_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_smartd_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_oddjobd_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_irqbalance_enabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_mdmonitor_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_package_psacct_installed" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_rhnsd_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_psacct_enabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_quota_nld_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_certmonger_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_netconsole_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_kdump_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_acpid_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_messagebus_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_cgred_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_package_abrt_removed" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_ntp" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_ntp_enabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_ntpd_specify_remote_server" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_chronyd_or_ntpd_specify_remote_server" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_timesyncd_enabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_ntpd_enabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_package_ntp_installed" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_chronyd_or_ntpd_enabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_chronyd_or_ntpd_set_maxpoll" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_ntpd_specify_multiple_servers" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_chronyd_or_ntpd_specify_multiple_servers" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_sssd" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_sssd_enabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sssd_ssh_known_hosts_timeout" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_package_sssd_installed" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sssd_offline_cred_expiration" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sssd_enable_smartcards" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sssd_enable_pam_services" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sssd_memcache_timeout" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_sssd-ldap" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sssd_ldap_configure_tls_ca" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sssd_ldap_start_tls" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sssd_ldap_configure_tls_ca_dir" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_http" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_securing_httpd" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_httpd_no_compilers_in_prod" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_httpd_enable_loglevel" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_httpd_enable_system_logging" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_httpd_disable_mime_types" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_httpd_remove_backups" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_httpd_configure_log_format" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_httpd_entrust_passwords" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_httpd_public_resources_not_shared" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_httpd_configure_max_keepalive_requests" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_httpd_private_server_on_separate_subnet" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_httpd_nipr_accredited_dmz" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_httpd_enable_error_logging" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_httpd_secure_content" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_partition_for_web_content" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_httpd_configure_banner_page" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_httpd_remove_robots_file" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_httpd_configure_documentroot" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_httpd_limit_java_files" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_httpd_disable_content_symlinks" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_httpd_encrypt_file_uploads" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_httpd_configure_perl_securely" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_httpd_configure_perl_taint" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_httpd_minimize_loadable_modules" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_httpd_core_modules" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_httpd_enable_log_config" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_httpd_proxy_support" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_httpd_mod_rewrite" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_httpd_cache_support" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_httpd_server_side_includes" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_httpd_webdav" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_httpd_mime_magic" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_httpd_digest_authentication" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_httpd_server_configuration_display" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_httpd_server_activity_status" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_httpd_url_correction" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_httpd_cgi_support" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_httpd_ldap_support" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_httpd_optional_components" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_httpd_minimize_config_files_included" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_httpd_basic_authentication" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_httpd_configure_php_securely" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_httpd_directory_restrictions" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_httpd_anonymous_content_sharing" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_httpd_limit_available_methods" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_httpd_configure_script_permissions" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_httpd_disable_anonymous_ftp_access" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_httpd_ignore_htaccess_files" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_httpd_restrict_root_directory" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_httpd_restrict_critical_directories" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_httpd_restrict_web_directory" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_httpd_modules_improve_security" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_httpd_deploy_mod_ssl" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_httpd_install_mod_ssl" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_httpd_configure_valid_server_cert" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_httpd_require_client_certs" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_httpd_configure_tls" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_httpd_deploy_mod_security" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_httpd_install_mod_security" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_httpd_use_dos_protection_modules" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_httpd_configure_os_protect_web_server" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_httpd_antivirus_scan_uploads" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_httpd_configure_remote_session_encryption" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_httpd_configure_firewall" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_httpd_restrict_file_dir_access" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_permissions_httpd_server_conf_files" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_permissions_httpd_server_conf_d_files" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_dir_perms_etc_httpd_conf" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_permissions_httpd_server_modules_files" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_dir_perms_var_log_httpd" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_http_configure_log_file_ownership" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_httpd_chroot" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_httpd_restrict_info_leakage" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_httpd_serversignature_off" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_httpd_servertokens_prod" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_disabling_httpd" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_package_httpd_removed" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_httpd_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_installing_httpd" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_httpd_minimal_modules_installed" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_smb" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_configuring_samba" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_smb_server_disable_root" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_require_smb_client_signing" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_mount_option_smb_client_signing" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_package_samba-common_installed" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_smb_restrict_file_sharing" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_smb_disable_printing" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_disabling_samba" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_package_samba_removed" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_smb_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_dhcp" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_dhcp_client_configuration" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_dhcp_client_restrict_options" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_disabling_dhcp_server" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_dhcpd_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_package_dhcp_removed" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_dhcp_server_configuration" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_dhcp_server_configure_logging" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_dhcp_server_deny_bootp" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_dhcp_server_minimize_served_info" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_dhcp_server_disable_ddns" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_dhcp_server_deny_decline" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_disabling_dhcp_client" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sysconfig_networking_bootproto_ifcfg" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_ldap" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_openldap_client" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_enable_ldap_client" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_ldap_client_tls_cacertpath" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_ldap_client_start_tls" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_openldap_server" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_package_openldap-servers_removed" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_ldap_server_config_certificate_files" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_dns" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_disabling_dns_server" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_package_bind_removed" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_named_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_dns_server_protection" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_dns_server_authenticate_zone_transfers" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_dns_server_disable_dynamic_updates" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_dns_server_disable_zone_transfers" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_dns_server_partition_with_views" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_dns_server_separate_internal_external" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_dns_server_isolation" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_dns_server_dedicated" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_dns_server_chroot" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_routing" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_disabling_quagga" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_zebra_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_package_quagga_removed" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_xwindows" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_disabling_xwindows" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_package_xorg-x11-server-common_removed" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_xwindows_runlevel_target" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_cron_and_at" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_package_cron_installed" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_cron_enabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_atd_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_crond_enabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_disable_anacron" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_restrict_at_cron_users" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_owner_cron_allow" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_cron_allow" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_snmp" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_disabling_snmp_service" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_snmpd_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_package_net-snmp_removed" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_snmp_configure_server" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_snmpd_not_default_password" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_snmpd_use_newer_protocol" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_ftp" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_disabling_vsftpd" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_package_vsftpd_removed" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_vsftpd_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_ftp_use_vsftpd" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_package_vsftpd_installed" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_ftp_configure_vsftpd" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_ftp_log_transactions" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_ftp_present_banner" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_ftp_disable_uploads" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_ftp_home_partition" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_ftp_configure_firewall" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_ftp_restrict_users" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_ftp_limit_users" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_ftp_restrict_to_anon" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_apt" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_apt_sources_list_official" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_apt_conf_disallow_unauthenticated" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_obsolete" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_talk" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_package_talk-server_removed" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_package_talk_removed" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_inetd_and_xinetd" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_package_xinetd_removed" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_xinetd_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_package_tcp_wrappers_installed" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_tftp" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_package_tftp-server_removed" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_tftpd_uses_secure_mode" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_package_tftp_removed" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_tftp_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_nis" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_package_ypserv_removed" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_ypbind_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_package_ypbind_removed" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_telnet" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_package_telnet-server_removed" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_telnet_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_package_telnet_removed" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_r_services" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_no_rsh_trust_files" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_package_rsh-server_removed" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_rexec_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_rsh_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_no_host_based_files" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_no_user_host_based_files" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_rlogin_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_package_rsh_removed" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_docker" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_docker_enabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_docker_selinux_enabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_docker_storage_configured" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_package_docker_installed" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_permissions" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_partitions" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_mount_option_dev_shm_nodev" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_tmp_nosuid" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_tmp_noexec" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_tmp_bind" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_mount_option_home_nodev" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_mount_option_noexec_removable_partitions" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_mount_option_nodev_removable_partitions" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_mount_option_nodev_nonroot_local_partitions" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_mount_option_nosuid_removable_partitions" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_mount_option_var_tmp_nodev" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_mount_option_tmp_nosuid" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_mount_option_home_nosuid" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_mount_option_tmp_noexec" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_mount_option_tmp_nodev" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_mount_option_dev_shm_nosuid" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_mount_option_dev_shm_noexec" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_mounting" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_kernel_module_udf_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_kernel_module_hfs_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_grub2_nousb_argument" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_kernel_module_jffs2_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_bios_assign_password" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_kernel_module_hfsplus_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_kernel_module_squashfs_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_kernel_module_cramfs_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_autofs_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_bios_disable_usb_boot" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_kernel_module_freevxfs_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_kernel_module_usb-storage_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_restrictions" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_dmesg_restrict" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_yama_ptrace_scope" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_grub2_vsyscall_argument" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_kexec_load_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_enable_execshield_settings" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_randomize_va_space" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_exec_shield" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sysctl_kernel_kptr_restrict" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_enable_nx" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_bios_enable_execution_restrictions" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_install_PAE_kernel_on_x86-32" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_coredumps" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_disable_users_coredumps" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sysctl_fs_suid_dumpable" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_poisoning" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_grub2_page_poison_argument" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_grub2_slub_debug_argument" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_daemon_umask" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_umask_for_daemons" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_files" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_dir_perms_world_writable_sticky_bits" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_permissions_systemmap" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_permissions_unauthorized_suid" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_permissions_unauthorized_world_writable" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sysctl_fs_protected_hardlinks" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_no_files_unowned_by_user" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_permissions_ungroupowned" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_dir_perms_world_writable_system_owned" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sysctl_fs_protected_symlinks" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_permissions_unauthorized_sgid" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_permissions_within_important_dirs" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_permissions_library_dirs" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_ownership_binary_dirs" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_ownership_library_dirs" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_permissions_binary_dirs" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_permissions_important_account_files" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_passwd" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_passwd" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_gshadow" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_group" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_gshadow" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_shadow" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_passwd" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_etc_gshadow" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_group" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_group" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_owner_etc_shadow" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_permissions_etc_shadow" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_auditing" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_auditd_enabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_package_auditd_installed" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_grub2_audit_argument" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_grub2_audit_backlog_limit_argument" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_auditd_configure_rules" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_group" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_passwd" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_gshadow" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_permissions_var_log_audit" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_system_shutdown" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_mac_modification" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_ownership_var_log_audit" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_opasswd" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_media_export" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_directory_access_var_log_audit" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_etc_passwd_openat" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_shadow" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_etc_group_open" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_immutable" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_etc_group_openat" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_directory_permissions_var_log_audit" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_etc_passwd_open" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_session_events" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_etc_group_open_by_handle_at" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_etc_passwd_open_by_handle_at" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_networkconfig_modification" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_sysadmin_actions" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_audit_unsuccessful_file_modification" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_rename" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_openat" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_open_by_handle_at_o_trunc_write" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_fchmod" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_openat_o_trunc_write" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_unlinkat" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_open_by_handle_at_rule_order" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_ftruncate" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_open_by_handle_at" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_open_by_handle_at_o_creat" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_lsetxattr" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_open" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_open_rule_order" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_openat_rule_order" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_fsetxattr" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_unlink" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_fremovexattr" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_open_o_creat" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_creat" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_lremovexattr" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_setxattr" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_fchmodat" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_fchown" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_chown" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_removexattr" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_truncate" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_lchown" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_openat_o_creat" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_fchownat" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_open_o_trunc_write" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_chmod" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_renameat" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_audit_privileged_commands" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_newgrp" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_su" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_gpasswd" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_newuidmap" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_mount" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_sudoedit" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_ssh_keysign" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_pt_chown" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_unix_chkpwd" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_umount" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_crontab" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_pam_timestamp_check" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_at" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_userhelper" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_chage" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_postqueue" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_newgidmap" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_chsh" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_postdrop" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_usernetctl" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_sudo" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_passwd" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_audit_file_deletion_events" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_file_deletion_events_unlink" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_file_deletion_events_renameat" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_file_deletion_events_rename" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_file_deletion_events" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_file_deletion_events_unlinkat" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_file_deletion_events_rmdir" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_audit_execution_selinux_commands" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_execution_restorecon" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_execution_chcon" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_execution_semanage" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_execution_setsebool" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_execution_setfiles" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_execution_seunshare" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_audit_dac_actions" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_lremovexattr" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_fsetxattr" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_lchown" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_fremovexattr" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_fchownat" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_fchmod" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_removexattr" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_fchmodat" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chmod" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_lsetxattr" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_chown" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_setxattr" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_dac_modification_fchown" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_audit_time_rules" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_time_adjtimex" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_time_clock_settime" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_time_watch_localtime" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_time_settimeofday" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_time_stime" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_audit_login_events" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_login_events_tallylog" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_login_events_faillock" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_login_events_lastlog" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_login_events" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_audit_kernel_module_loading" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_kernel_module_loading_init" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_kernel_module_loading_create" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_kernel_module_loading_insmod" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_kernel_module_loading_modprobe" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_kernel_module_loading_finit" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_kernel_module_loading_delete" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_kernel_module_loading" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_audit_rules_kernel_module_loading_rmmod" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_configure_auditd_data_retention" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_auditd_data_retention_max_log_file_action" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_auditd_data_retention_num_logs" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_auditd_data_disk_full_action" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_auditd_data_retention_space_left_action" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_auditd_audispd_disk_full_action" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_auditd_data_retention_admin_space_left_action" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_auditd_audispd_network_failure_action" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_auditd_data_retention_action_mail_acct" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_auditd_data_retention_space_left" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_auditd_data_retention_max_log_file" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_auditd_data_disk_error_action" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_auditd_audispd_syslog_plugin_activated" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_auditd_audispd_configure_remote_server" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_auditd_audispd_encrypt_sent_records" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_auditd_data_retention_flush" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_entropy" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_kernel_disable_entropy_contribution_for_solid_state_drives" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_accounts-session" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_groupownership_home_directories" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_permissions_home_directories" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_ownership_home_directories" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_accounts_users_home_files_ownership" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_accounts_user_interactive_home_directory_defined" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_permission_user_init_files" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_accounts_user_interactive_home_directory_exists" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_accounts_max_concurrent_login_sessions" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_accounts_users_home_files_permissions" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_accounts_user_home_paths_only" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_accounts_users_home_files_groupownership" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_accounts_logon_fail_delay" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_accounts_have_homedir_login_defs" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_accounts_user_dot_no_world_writable_programs" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_permissions_home_dirs" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_accounts_user_dot_user_ownership" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_accounts_user_dot_group_ownership" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_accounts_tmout" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_root_paths" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_accounts_root_path_dirs_no_write" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_root_path_no_dot" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_user_umask" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_accounts_umask_etc_profile" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_accounts_umask_etc_csh_cshrc" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_accounts_umask_etc_bashrc" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_accounts_umask_etc_login_defs" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_accounts_umask_interactive_users" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_accounts-banners" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_banner_etc_issue" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_gui_login_banner" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_gconf_gdm_set_login_banner_text" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_gconf_gdm_enable_warning_gui_banner" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_login_banner_text" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_banner_enabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_accounts-physical" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_debug-shell_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_disable_ctrlaltdel_reboot" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_grub2_disable_interactive_boot" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_disable_ctrlaltdel_burstaction" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_require_singleuser_auth" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_screen_locking" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_smart_card_login" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_package_opensc_installed" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_smartcard_auth" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_pcscd_enabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_package_pcsc-lite_installed" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_force_opensc_card_drivers" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_smartcard_configure_cert_checking" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_configure_opensc_nss_db" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_configure_opensc_card_drivers" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_install_smartcard_packages" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_console_screen_locking" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_package_screen_installed" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_password_storage" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_gid_passwd_group_same" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_no_empty_passwords" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_accounts_password_all_shadowed" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_no_netrc_files" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_bootloader-grub-legacy" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_enterprise_app" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_enterprise_app_mode_travel" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_selinux" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_selinux_state" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_selinux_user_login_roles" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_selinux_all_devicefiles_labeled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_selinux_confinement_of_daemons" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_package_setroubleshoot_removed" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_selinux_policytype" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_grub2_enable_selinux" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_package_mcstrans_removed" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_selinux-booleans" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_git_session_users" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_spamd_enable_home_dirs" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_secadm_exec_content" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_selinuxuser_execheap" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_secure_mode_policyload" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_httpd_dontaudit_search_dirs" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_selinuxuser_ping" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_virt_sandbox_use_mknod" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_authlogin_nsswitch_use_ldap" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_postgresql_selinux_transmit_client_label" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_selinuxuser_use_ssh_chroot" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_icecast_use_any_tcp_ports" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_polyinstantiation_enabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_httpd_can_network_connect_cobbler" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_fips_mode" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_git_system_enable_homedirs" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_cvs_read_shadow" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_exim_read_user_files" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_xdm_exec_bootloader" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_postfix_local_write_mail_spool" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_daemons_dump_core" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_postgresql_selinux_unconfined_dbadm" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_httpd_use_cifs" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_httpd_use_openstack" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_httpd_mod_auth_ntlm_winbind" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_varnishd_connect_any" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_mcelog_foreground" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_ftpd_use_passive_mode" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_guest_exec_content" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_ftpd_anon_write" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_sanlock_use_samba" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_tor_can_network_relay" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_logging_syslogd_can_sendmail" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_kerberos_enabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_unprivuser_use_svirt" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_xguest_use_bluetooth" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_sysadm_exec_content" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_racoon_read_shadow" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_named_write_master_zones" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_telepathy_connect_all_ports" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_saslauthd_read_shadow" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_virt_use_sanlock" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_samba_enable_home_dirs" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_xguest_connect_network" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_rsync_export_all_ro" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_cron_system_cronjob_use_shares" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_virt_use_fusefs" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_cobbler_anon_write" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_samba_export_all_rw" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_nfs_export_all_ro" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_unconfined_chrome_sandbox_transition" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_domain_fd_use" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_cluster_can_network_connect" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_mcelog_client" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_xend_run_blktap" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_ftpd_use_cifs" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_selinuxuser_share_music" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_mmap_low_allowed" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_samba_create_home_dirs" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_staff_exec_content" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_selinuxuser_execmod" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_fenced_can_network_connect" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_ksmtuned_use_cifs" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_httpd_can_connect_mythtv" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_ftpd_connect_all_unreserved" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_lsmd_plugin_connect_any" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_xdm_bind_vnc_tcp_port" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_xdm_write_home" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_use_lpd_server" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_secure_mode_insmod" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_nfsd_anon_write" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_httpd_ssi_exec" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_domain_kernel_load_modules" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_nagios_run_sudo" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_xguest_exec_content" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_httpd_can_network_relay" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_mock_enable_homedirs" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_use_nfs_home_dirs" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_dbadm_exec_content" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_use_ecryptfs_home_dirs" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_mpd_enable_homedirs" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_xserver_clients_write_xshm" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_puppetmaster_use_db" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_cups_execmem" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_cobbler_use_nfs" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_xserver_execmem" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_cluster_manage_all_files" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_nscd_use_shm" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_sanlock_use_fusefs" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_virt_sandbox_use_sys_admin" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_httpd_unified" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_swift_can_network" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_selinuxuser_direct_dri_enabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_irssi_use_full_network" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_httpd_serve_cobbler_files" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_cluster_use_execmem" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_selinuxuser_udp_server" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_webadm_manage_user_files" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_pppd_can_insmod" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_httpd_graceful_shutdown" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_smbd_anon_write" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_cron_can_relabel" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_selinuxuser_tcp_server" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_ftpd_use_nfs" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_daemons_use_tty" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_cobbler_can_network_connect" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_conman_can_network" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_unconfined_mozilla_plugin_transition" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_openshift_use_nfs" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_abrt_upload_watch_anon_write" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_xend_run_qemu" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_privoxy_connect_any" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_httpd_use_nfs" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_squid_connect_any" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_virt_use_rawip" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_zoneminder_anon_write" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_samba_export_all_ro" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_zarafa_setrlimit" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_exim_can_connect_db" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_httpd_enable_cgi" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_httpd_can_network_connect_db" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_boinc_execmem" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_selinuxuser_postgresql_connect_enabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_virt_use_comm" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_git_system_use_cifs" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_httpd_use_sasl" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_gitosis_can_sendmail" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_webadm_read_user_files" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_virt_use_samba" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_unconfined_login" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_neutron_can_network" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_httpd_enable_homedirs" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_git_cgi_use_nfs" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_glance_use_execmem" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_virt_read_qemu_ga_data" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_httpd_verify_dns" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_daemons_enable_cluster_mode" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_tftp_home_dir" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_virt_sandbox_use_netlink" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_use_fusefs_home_dirs" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_exim_manage_user_files" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_piranha_lvs_can_network_connect" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_tor_bind_all_unreserved_ports" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_sge_use_nfs" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_gpg_web_anon_write" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_mcelog_server" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_postgresql_can_rsync" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_auditadm_exec_content" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_samba_share_fusefs" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_logging_syslogd_run_nagios_plugins" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_puppetagent_manage_all_files" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_ksmtuned_use_nfs" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_gluster_export_all_ro" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_abrt_handle_event" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_httpd_mod_auth_pam" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_login_console_enabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_logging_syslogd_use_tty" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_mozilla_plugin_bind_unreserved_ports" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_gluster_export_all_rw" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_fenced_can_ssh" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_sanlock_use_nfs" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_glance_use_fusefs" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_samba_share_nfs" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_antivirus_can_scan_system" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_httpd_builtin_scripting" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_dhcpd_use_ldap" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_squid_use_tproxy" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_named_tcp_bind_http_port" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_abrt_anon_write" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_httpd_can_connect_ftp" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_openvpn_enable_homedirs" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_authlogin_yubikey" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_glance_api_can_network" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_ssh_chroot_rw_homedirs" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_deny_execmem" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_ftpd_use_fusefs" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_ftpd_full_access" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_cdrecord_read_content" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_selinuxuser_rw_noexattrfile" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_samba_portmapper" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_virt_use_xserver" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_httpd_run_preupgrade" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_mplayer_execstack" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_irc_use_any_tcp_ports" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_mysql_connect_any" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_xguest_mount_media" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_httpd_can_connect_ldap" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_samba_load_libgfapi" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_mozilla_plugin_use_spice" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_cron_userdomain_transition" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_use_samba_home_dirs" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_mcelog_exec_scripts" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_httpd_dbus_sssd" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_mpd_use_cifs" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_virt_use_nfs" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_zabbix_can_network" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_httpd_can_sendmail" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_logwatch_can_network_connect_mail" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_wine_mmap_zero_ignore" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_gluster_anon_write" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_telepathy_tcp_connect_generic_network_ports" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_global_ssp" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_sge_domain_can_network_connect" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_polipo_use_cifs" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_httpd_use_fusefs" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_httpd_tmp_exec" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_ssh_keysign" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_virt_use_execmem" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_tmpreaper_use_nfs" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_awstats_purge_apache_log_files" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_dbadm_manage_user_files" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_kdumpgui_run_bootloader" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_polipo_session_users" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_mozilla_plugin_use_gps" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_virt_sandbox_use_all_caps" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_spamassassin_can_network" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_pppd_for_user" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_httpd_enable_ftp_server" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_polipo_use_nfs" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_selinuxuser_mysql_connect_enabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_nis_enabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_virt_use_usb" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_git_system_use_nfs" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_container_connect_any" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_postgresql_selinux_users_ddl" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_polipo_session_bind_all_unreserved_ports" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_tftp_anon_write" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_pcp_read_generic_logs" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_xdm_sysadm_login" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_collectd_tcp_network_connect" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_httpd_tty_comm" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_virt_transition_userdomain" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_xserver_object_manager" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_mozilla_read_content" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_virt_sandbox_use_audit" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_httpd_can_network_memcache" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_secure_mode" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_cobbler_use_cifs" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_deny_ptrace" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_dbadm_read_user_files" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_rsync_client" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_httpd_read_user_content" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_mpd_use_nfs" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_gssd_read_tmp" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_condor_tcp_network_connect" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_user_exec_content" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_httpd_run_ipa" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_rsync_full_access" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_antivirus_use_jit" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_httpd_setrlimit" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_haproxy_connect_any" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_httpd_manage_ipa" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_authlogin_radius" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_logadm_exec_content" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_rsync_anon_write" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_fcron_crond" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_nfs_export_all_rw" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_virt_rw_qemu_ga_data" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_zebra_write_config" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_openvpn_run_unconfined" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_xen_use_nfs" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_zoneminder_run_sudo" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_ftpd_connect_db" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_daemons_use_tcp_wrapper" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_httpd_dbus_avahi" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_staff_use_svirt" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_httpd_anon_write" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_httpd_can_connect_zabbix" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_tmpreaper_use_samba" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_git_session_bind_all_unreserved_ports" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_mozilla_plugin_can_network_connect" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_httpd_can_network_connect" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_nagios_run_pnp4nagios" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_prosody_bind_http_port" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_httpd_can_check_spam" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_mailman_use_fusefs" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_git_cgi_enable_homedirs" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_smartmon_3ware" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_mount_anyfile" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_httpd_execmem" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_entropyd_use_audio" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_selinuxuser_execstack" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_git_cgi_use_cifs" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_logrotate_use_nfs" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_dhcpc_exec_iptables" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_samba_run_unconfined" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_mozilla_plugin_use_bluejeans" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_samba_domain_controller" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_minidlna_read_generic_user_content" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_pcp_bind_all_unreserved_ports" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_httpd_sys_script_anon_write" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_polipo_connect_all_unreserved" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_httpd_run_stickshift" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_ssh_sysadm_login" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_httpd_use_gpg" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sebool_openvpn_can_network_connect" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_bootloader-grub2" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_permissions_efi_grub2_cfg" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_owner_efi_grub2_cfg" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_uefi_no_removeable_media" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_grub2_cfg" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_grub2_enable_iommu_force" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_groupowner_efi_grub2_cfg" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_grub2_no_removeable_media" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_grub2_uefi_password" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_owner_grub2_cfg" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_file_permissions_grub2_cfg" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_grub2_password" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_network" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_network_disable_ddns_interfaces" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_network_disable_zeroconf" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_network_configure_name_resolution" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_network_sniffer_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_network-wireless" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_wireless_software" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_wireless_disable_interfaces" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_bluetooth_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_wireless_disable_in_bios" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_kernel_module_bluetooth_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_network-uncommon" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_kernel_module_sctp_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_kernel_module_tipc_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_kernel_module_rds_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_kernel_module_dccp_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_network_disable_unused_interfaces" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_network_ssl" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_network-kernel" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_network_host_parameters" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_send_redirects" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_send_redirects" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_ip_forward" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_network_host_and_router_parameters" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_log_martians" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_accept_source_route" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_tcp_syncookies" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_icmp_echo_ignore_broadcasts" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_rp_filter" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_log_martians" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_accept_redirects" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_secure_redirects" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_secure_redirects" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_rp_filter" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_accept_redirects" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_icmp_ignore_bogus_error_responses" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_accept_source_route" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_network-ipv6" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_disabling_ipv6" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_network_ipv6_disable_rpc" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_kernel_module_ipv6_option_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_disable_ipv6" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_network_ipv6_disable_interfaces" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_configuring_ipv6" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_network_ipv6_static_address" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_network_ipv6_privacy_extensions" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_network_ipv6_default_gateway" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_network_ipv6_limit_requests" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_disabling_ipv6_autoconfig" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_accept_redirects" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_accept_ra" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_accept_ra" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_accept_redirects" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_forwarding" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_accept_source_route" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_accept_source_route" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_network-iptables" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_iptables_ruleset_modifications" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_set_iptables_default_rule" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_set_iptables_default_rule_forward" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_iptables_log_and_drop_suspicious" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_iptables_icmp_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_iptables_activation" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_set_ip6tables_default_rule" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_iptables_enabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_ip6tables_enabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_network-ipsec" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_package_libreswan_installed" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_libreswan_approved_tunnels" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_network-firewalld" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_firewalld_activation" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_package_firewalld_installed" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_firewalld_enabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_ruleset_modifications" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_configure_firewalld_rate_limiting" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_configure_firewalld_ports" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_set_firewalld_default_zone" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_logging" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_package_rsyslog_installed" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_disable_logwatch_for_logserver" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_rsyslog_enabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_rsyslog_accepting_remote_messages" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_rsyslog_accept_remote_messages_tcp" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_rsyslog_nolisten" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_rsyslog_accept_remote_messages_udp" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_syslogng_enabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_package_syslogng_installed" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_configure_logwatch_on_logserver" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_logwatch_configured_hostlimit" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_logwatch_configured_splithosts" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_ensure_rsyslog_log_file_configuration" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_rsyslog_files_permissions" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_rsyslog_cron_logging" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_rsyslog_files_ownership" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_rsyslog_files_groupownership" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_log_rotation" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_ensure_logrotate_activated" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_rsyslog_sending_messages" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_rsyslog_remote_loghost" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_software" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_gnome" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_package_gdm_removed" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_dconf_use_text_backend" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_enable_dconf_user_profile" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_dconf_db_up_to_date" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_gnome_remote_access_settings" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_remote_access_credential_prompt" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_remote_access_encryption" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_gnome_network_settings" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_gconf_gnome_disable_wifi_disconnect" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_gconf_gnome_disable_wifi_notification" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_gconf_gnome_disable_wifi_create" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_disable_wifi_create" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_disable_wifi_notification" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_gnome_login_screen" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_gnome_gdm_disable_guest_login" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_gconf_gdm_disable_user_list" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_disable_user_list" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_login_retries" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_gnome_gdm_disable_automatic_login" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_gconf_gnome_disable_restart_shutdown" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_disable_restart_shutdown" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_enable_smartcard_auth" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_gnome_system_settings" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_disable_user_admin" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_gconf_gnome_disable_clock_weather" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_disable_ctrlaltdel_reboot" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_gconf_gnome_disable_clock_temperature" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_disable_power_settings" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_gconf_gnome_disable_ctrlaltdel_reboot" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_disable_geolocation" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_gnome_media_settings" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_disable_automount" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_disable_thumbnailers" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_gconf_gnome_disable_thumbnailers" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_gconf_gnome_disable_automount" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_gnome_screen_locking" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_screensaver_idle_activation_locked" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_screensaver_lock_enabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_gconf_gnome_screensaver_idle_delay" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_screensaver_mode_blank" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_gconf_gnome_screensaver_max_idle_time" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_screensaver_lock_locked" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_screensaver_idle_delay" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_gconf_gnome_screensaver_max_idle_action" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_screensaver_idle_activation_enabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_gconf_gnome_screensaver_idle_activation_enabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_screensaver_user_locks" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_screensaver_user_info" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_screensaver_lock_delay" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_dconf_gnome_session_idle_user_locks" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_gconf_gnome_screen_locking_keybindings" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_gconf_gnome_screensaver_lock_enabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_gconf_gnome_screensaver_mode_blank" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_updating" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_ensure_gpgcheck_globally_activated" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_clean_components_post_updating" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_ensure_gpgcheck_repo_metadata" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_ensure_redhat_gpgkey_installed" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_ensure_gpgcheck_local_packages" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_security_patches_up_to_date" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_ensure_gpgcheck_never_disabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_integrity" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_disable_prelink" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_software-integrity" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_aide" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_aide_build_database" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_aide_periodic_cron_checking" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_aide_scan_notification" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_aide_use_fips_hashes" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_aide_verify_acls" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_aide_verify_ext_attributes" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_package_aide_installed" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_rpm_verification" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_rpm_verify_hashes" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_rpm_verify_ownership" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_rpm_verify_permissions" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_endpoint_security_software" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_install_hids" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_configure_user_data_backups" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_install_antivirus" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_mcafee_security_software" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_install_mcafee_antivirus" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_mcafee_antivirus_definitions_updated" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_install_mcafee_cma_rt" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_service_nails_enabled" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_mcafee_hbss_software" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_install_mcafee_hbss_hips" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_install_mcafee_hbss_accm" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_install_mcafee_hbss_pa" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_crypto" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_fips" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_grub2_enable_fips_mode" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_package_dracut-fips_installed" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_certified-vendor" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_installed_OS_is_FIPS_certified" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_installed_OS_is_vendor_supported" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_sap" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_sudo" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sudo_remove_nopasswd" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sudo_remove_no_authenticate" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sudo_vdsm_nopasswd" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_sudo_require_authentication" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_disk_partitioning" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_partition_for_var_log" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_partition_for_var_log_audit" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_partition_for_tmp" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_partition_for_var" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_partition_for_var_tmp" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_encrypt_partitions" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_partition_for_home" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_partition_for_srv" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_root_logins" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_accounts_no_uid_except_zero" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_no_shelllogin_for_systemaccounts" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_securetty_root_login_console_only" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_no_direct_root_logins" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_restrict_serial_port_logins" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_accounts-restrictions" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_accounts" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_system" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_account_expiration" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_account_unique_name" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_account_use_centralized_automated_auth" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_password_expiration" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_accounts_maximum_age_login_defs" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_accounts_minimum_age_login_defs" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_accounts_password_warn_age_login_defs" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_accounts_password_minlen_login_defs" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_password_quality" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_password_quality_pwquality" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_retry" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_ucredit" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_lcredit" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_ocredit" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_minclass" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_dcredit" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_maxrepeat" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_maxclassrepeat" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_minlen" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_accounts-pam" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_password_quality_pamcracklib" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_cracklib_accounts_password_pam_difok" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_cracklib_accounts_password_pam_minclass" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_cracklib_accounts_password_pam_minlen" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_cracklib_accounts_password_pam_lcredit" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_cracklib_accounts_password_pam_ucredit" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_cracklib_accounts_password_pam_maxrepeat" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_cracklib_accounts_password_pam_dcredit" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_cracklib_accounts_password_pam_ocredit" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_cracklib_accounts_password_pam_retry" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_display_login_attempts" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_set_password_hashing_algorithm" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_set_password_hashing_algorithm_libuserconf" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_set_password_hashing_algorithm_systemauth" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_set_password_hashing_algorithm_logindefs" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_group_locking_out_password_attempts" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_deny" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_interval" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_unix_remember" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_unlock_time" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_deny_root" selected="true"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_account_disable_post_pw_expiration" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_account_temp_expire_date" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_accounts_password_pam_difok" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_no_root_webbrowsing" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_no_password_auth_for_systemaccounts" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_accounts_password_set_min_life_existing" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_accounts_password_set_max_life_existing" selected="false"/>
<xccdf:select idref="xccdf_org.ssgproject.content_rule_root_path_default" selected="false"/>
<xccdf:set-value idref="xccdf_org.ssgproject.content_value_var_accounts_maximum_age_login_defs">45</xccdf:set-value>
<xccdf:set-value idref="xccdf_org.ssgproject.content_value_var_accounts_minimum_age_login_defs">1</xccdf:set-value>
<xccdf:set-value idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_deny">5</xccdf:set-value>
<xccdf:set-value idref="xccdf_org.ssgproject.content_value_var_password_pam_minclass">4</xccdf:set-value>
<xccdf:set-value idref="xccdf_org.ssgproject.content_value_var_password_pam_minlen">15</xccdf:set-value>
<xccdf:set-value idref="xccdf_org.ssgproject.content_value_var_password_pam_retry">5</xccdf:set-value>
<xccdf:set-value idref="xccdf_org.ssgproject.content_value_var_password_pam_maxclassrepeat">0</xccdf:set-value>
<xccdf:set-value idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_unlock_time">1800</xccdf:set-value>
<xccdf:set-value idref="xccdf_org.ssgproject.content_value_var_password_pam_unix_remember">25</xccdf:set-value>
<xccdf:set-value idref="xccdf_org.ssgproject.content_value_var_password_pam_difok">1</xccdf:set-value>
<xccdf:set-value idref="xccdf_org.ssgproject.content_value_var_password_pam_maxrepeat">3</xccdf:set-value>
<xccdf:set-value idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_fail_interval">1800</xccdf:set-value>
<xccdf:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_unix_remember" selector="4"/>
<xccdf:refine-value idref="xccdf_org.ssgproject.content_value_var_account_disable_post_pw_expiration" selector="90"/>
<xccdf:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_deny" selector="6"/>
<xccdf:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_passwords_pam_faillock_unlock_time" selector="1800"/>
<xccdf:refine-value idref="xccdf_org.ssgproject.content_value_sshd_idle_timeout_value" selector="15_minutes"/>
<xccdf:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_minlen" selector="7"/>
<xccdf:refine-value idref="xccdf_org.ssgproject.content_value_var_password_pam_minclass" selector="2"/>
<xccdf:refine-value idref="xccdf_org.ssgproject.content_value_var_accounts_maximum_age_login_defs" selector="90"/>
<xccdf:refine-value idref="xccdf_org.ssgproject.content_value_var_auditd_num_logs" selector="5"/>
<xccdf:refine-value idref="xccdf_org.ssgproject.content_value_var_multiple_time_servers" selector="rhel"/>
</xccdf:Profile>
</xccdf:Tailoring>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment