Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

PowerScale OneFS Web Administration Guide

STIG hardening profile

The OneFS STIG hardening profile contains a subset of the configuration requirements set by the Department of Defense. The STIG hardening profile is designed for PowerScale clusters that support Federal Government accounts. A PowerScale cluster that is installed with a STIG profile relies on the surrounding ecosystem being secure.

After you apply the OneFS STIG hardening profile, the OneFS configuration is modified to make the PowerScale cluster more secure and to support controls that are defined by the DISA STIGs. Some examples of the many system changes are as follows:

  • After you log in through SSH or the web interface, the system displays a message that you are accessing a U.S. Government Information System and displays the terms and conditions of using the system.
  • On each node, SSH and the web interface listen only on the node's external IP address.
  • Password complexity requirements increase for local user accounts. Passwords must be at least 14 characters and contain at least one of each of the following character types: numeric, uppercase, lowercase, symbol.
  • Root SSH is disabled. You can log in as root only through the web interface or through a serial console session.
  • The system umask is changed to 077 by default.
  • Restricted access to device config and system files.
  • Basic authentication is disabled by default.

Rate this content

Accurate
Useful
Easy to understand
Was this article helpful?
0/3000 characters
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please select whether the article was helpful or not.
  Comments cannot contain these special characters: <>()\