Overview of updates - RHEL version

Latest available version: v26.08.03

Overview of the most recent updates to UNIX Health Check for Red Hat Enterprise Linux:

Version: v26.08.03
  • Update to check script checkabrtconfperms.sh to update command execution.
  • Update to check script checkadapterlink.sh to update command execution.
  • Update to check script checkadmgroup.sh to update command execution.
  • Update to check script checkadminpassword.sh to update command execution.
  • Update to check script checkall.sh to update command execution and improve how carriage returns are handled.
  • Update to check script checkxivdevlist.sh to improve how carriage returns are handled.
  • Update to check script checkxivdevlisterrors.sh to improve how carriage returns are handled.
  • Update to check script checkxivhakvsnoxivdevices.sh to improve how carriage returns are handled.
  • Update to check script checkxivfcadminstoragesystem.sh to improve how carriage returns are handled.
  • Update to check script checkxiviscsiadminstoragesystem.sh to improve how carriage returns are handled.
  • Update to check script checkxivsyslist.sh to improve how carriage returns are handled.
Version: v26.08.02
  • Update to check script checkextendedhistory.sh to update command execution and to correct the use of double quotes.
  • Update to check script checketcgrubconfentries.sh to remove subshells and allow the return code to work correctly.
  • Update to check script checkinittabrunlevels.sh to correct the usage of double quotes.
  • Update to check script checkpostfixmyorigin.sh to fix an issue with the grep command.
  • Update to check script checkpostfixipv4support.sh to correct the usage of double quotes.
  • Update to check script checksshallowusers to fix a variable.
  • Update to check script checksubscriptionmanagerinstalled.sh to correct the usage of double quotes.
Version: v26.02.14
  • Update to check script checketcfstabfilesystems.sh to exclude all auto-mounted file systems from being reported.
Version: v26.01.02
  • Update to all check scripts to update the copyright message for 2026.
Version: v25.09.02
  • Update to check script checkatd.sh to update the dnf / yum commands used.
  • Update to the description of check script checkauditrules.sh to fix a typo.
  • Update to check script checkauthorizedkeysentries.sh to improve checking of SSH authorized keys files for RHEL 10.
  • Update to the description of check script checkblankpassword.sh to provide additional information.
  • Update to check script checkcifsnetdev.sh to replace the egrep command with grep -E.
  • Update to check script checkall.sh to replace the egrep command with grep -E.
  • Update to check script checkcleanetcmail.sh to replace the egrep command with grep -E.
  • Update to check script checkcleanetc.sh to replace the egrep command with grep -E.
  • Update to check script checkcleanetcssh.sh to replace the egrep command with grep -E.
  • Update to check script checkcleanetcsysconfig.sh to replace the egrep command with grep -E.
  • Update to check script checkcleanroot.sh to replace the egrep command with grep -E.
  • Update to check script checkcpuload.sh to replace the egrep command with grep -E.
  • Update to check script checkcrontabcommandsexec.sh to replace the egrep command with grep -E.
  • Update to check script checkcrontabcommands.sh to replace the egrep command with grep -E.
  • Update to check script checkcrontabdups.sh to replace the egrep command with grep -E.
  • Update to check script checkdavfsnetdev.sh to replace the egrep command with grep -E.
  • Update to check script checkdnslookup.sh to replace the egrep command with grep -E.
  • Update to check script checkenvironment.sh to replace the egrep command with grep -E.
  • Update to check script checketcfstabfilesystems.sh to replace the egrep command with grep -E.
  • Update to check script checketcgroupperms.sh to replace the egrep command with grep -E.
  • Update to check script checketchostsduplicates.sh to replace the egrep command with grep -E.
  • Update to check script checketchostsdups.sh to replace the egrep command with grep -E.
  • Update to check script checketchostsnohostname.sh to replace the egrep command with grep -E.
  • Update to check script checketchostsvsdns.sh to replace the egrep command with grep -E.
  • Update to check script checketcpasswdperms.sh to replace the egrep command with grep -E.
  • Update to check script checkfreespaceinfs.sh to replace the egrep command with grep -E.
  • Update to check script checkfsreadonly.sh to replace the egrep command with grep -E.
  • Update to check script checketcshadowperms.sh to replace the egrep command with grep -E.
  • Update to check script checkgecos.sh to replace the egrep command with grep -E.
  • Update to check script checkhomedirs.sh to replace the egrep command with grep -E.
  • Update to check script checkhostname.sh to replace the egrep command with grep -E.
  • Update to check script checkhostnamevsdns.sh to replace the egrep command with grep -E.
  • Update to check script checkhyperthreading.sh to replace the egrep command with grep -E.
  • Update to check script checkinittabcommands.sh to replace the egrep command with grep -E.
  • Update to check script checklvmconfbackup.sh to replace the egrep command with grep -E.
  • Update to check script checkmailq.sh to replace the egrep command with grep -E.
  • Update to check script checkmultipleipinetchosts.sh to replace the egrep command with grep -E.
  • Update to check script checknameservers.sh to replace the egrep command with grep -E.
  • Update to check script checknfsaccess.sh to replace the egrep command with grep -E.
  • Update to check script checknfsconfig.sh to replace the egrep command with grep -E.
  • Update to check script checknfsnetdev.sh to replace the egrep command with grep -E.
  • Update to check script checkopennfsexports.sh to replace the egrep command with grep -E.
  • Update to check script checkpostfixsmtpconnection.sh to replace the egrep command with grep -E.
  • Update to check script checkresolvconf.sh to replace the egrep command with grep -E.
  • Update to check script checkrootrhosts.sh to replace the egrep command with grep -E.
  • Update to check script checksendmailsmtpconnection.sh to replace the egrep command with grep -E.
  • Update to check script checkshowmount.sh to replace the egrep command with grep -E.
  • Update to check script checksnmp.sh to replace the egrep command with grep -E.
  • Update to check script checksockets.sh to replace the egrep command with grep -E.
  • Update to check script checksudocommands.sh to replace the egrep command with grep -E.
  • Update to check script checksudoersusers.sh to replace the egrep command with grep -E.
  • Update to check script checksuid.sh to replace the egrep command with grep -E.
  • Update to check script checktelnetserver.sh to replace the egrep command with grep -E.
  • Update to check script checktmout.sh to replace the egrep command with grep -E.
  • Update to check script checktmpmounts.sh to replace the egrep command with grep -E.
  • Update to check script checktopcpuusers.sh to replace the egrep command with grep -E.
  • Update to check script checktsmbackup.sh to replace the egrep command with grep -E.
  • Update to check script checktsmsched.sh to replace the egrep command with grep -E.
  • Update to check script checkuidzero.sh to replace the egrep command with grep -E.
  • Update to check script checkvnbbackup.sh to replace the egrep command with grep -E.
  • Update to check script checkvnbserver.sh to replace the egrep command with grep -E.
  • Update to check script checketchostsduplicates.sh to exclude localhost from checking.
  • Update to check script checkfsreadonly.sh to avoid checking /boot/efi.
  • Update to check script checkhistappend.sh to fix a grep command.
  • Update to check script checkmlocate.sh to avoid checking on Red Hat Enterprise Linux 10.
  • Update to check script checkmultipleipinetchosts.sh to avoid checking localhost.
  • Update to check script checksudocommands.sh to fix a grep command.
  • Update to check script checksudocommandsexec.sh to fix a grep command.
  • Update to check script checkusersloggedonlongtime.sh to avoid a syntax error.
  • Update to check script checkwget.sh to provide the command to install wget.
  • Update to check script checkiotop.sh to check for packages iotop and iotop-c.
  • Update to check script checkrpmv.sh to avoid checking files in /boot/grub2.
  • Update to check script checkentropy.sh to lower the recommended entropy due to kernel changes.
  • Update to check script checkmcelog.sh to exclude an additional entry.
  • Update to check script checksudoerspasswords.sh to avoid testing passwords of users with increased rounds of password hashing.
  • Update to check script checkfsdirwrite.sh to avoid checking /run/user file systems.
  • Validation of Red Hat Enterprise Linux 10.0 completed.
Version: v25.02.04
  • Update to the description of check script checknmapportscan.sh to indicate an alternative command to display the open ports on the system.
Version: v25.01.06
  • Update to all check scripts to update the copyright message for 2025.
Version: v24.12.12
  • Updated the signature for the RPM package of UNIX Health Check for Red Hat Enterprise Linux to a SHA256 signature.
Version: v24.05.17
  • Update to check script checkoslevel.sh to recommend version 9.4 for Oracle Linux.
Version: v24.05.15
  • New check script checkprocpsnginstalled.sh to check if the procps-ng RPM package is installed on the system.
  • New check script checkiputilsinstalled.sh to check if the iputils RPM package is installed on the system.
Version: v24.05.13
  • New check script checkhostnameinstalled.sh to check if the hostname RPM package is installed on the system.
  • Update to check script checkcleanetcssh.sh to include a check if directory /etc/ssh exists before proceeding.
  • Update to check script checkbinbasenameperms.sh to allow an additional set of permissions for /bin/basename.
  • Update to check script checkall.sh to correctly display the logfile name in the results section.
  • Update to check script checkall.sh to redirect errors of the dmidecode command to /dev/null.
  • Update to check script checkcifsnetdev.sh to check for the existence of file /etc/fstab before proceeding.
  • Update to check script checkcpuload.sh to check for the existence of the vmstat command before proceeding.
  • Update to check script checkcrash.sh to check for the existence of the /var/crash folder before proceeding.
  • Update to check script checkcrondprocesses.sh to check for the existence of /bin/ps before proceeding.
  • Update to check script checkcronsystemcronfiles.sh to redirect errors of the find command to /dev/null.
  • Update to check script checkcrontabdups.sh to check for the existence of folder /var/spool/cron before proceeding.
  • Update to check script checkcrontabsunused.sh to check for the existence of folder /var/spool/cron before proceeding.
  • Update to check script checkdavfsnetdev.sh to check for the existence of file /etc/fstab before proceeding.
  • Update to check script checkdeployment.sh to redirect errors of the hostnamectl command to /dev/null.
  • Update to check script checkdevnull.sh to also allow the user:group to be set to nobody:nobody.
  • Update to check script checkdnslookupmultipleip.sh to check for the existence of /bin/ps before proceeding.
  • Update to check script checketcnamedconfperms.sh to check for the existence of /bin/ps before proceeding.
  • Update to check script checkfind.sh to check for the existence of /bin/ps before proceeding.
  • Update to check script checkfritzfrog.sh to redirect errors of the netstat command to /dev/null.
  • Update to check script checkfsmounted.sh to redirect errors of the cat command to /dev/null.
  • Update to check script checkfsmountpoint.sh to redirect errors of the cat command to /dev/null.
  • Update to check script checkfsreadonly.sh to check for the existence of /etc/fstab before proceeding.
  • Update to check script checkgangliagmetadrunning.sh to check for the existence of /bin/ps before proceeding.
  • Update to check script checkgangliagmondrunning.sh to check for the existence of /bin/ps before proceeding.
  • Update to check script checkguestagent.sh to redirect errors of the dmidecode command to /dev/null.
  • Update to check script checkhighcpu.sh to check for the existence of /bin/ps before proceeding.
  • Update to check script checkhostname.sh to redirect errors of the hostnamectl command to /dev/null.
  • Update to check script checkhyperthreading.sh to redirect errors of the dmidecode command to /dev/null.
  • Update to check script checkkernelmatchinginitramfs.sh to redirect errors of the ls command to /dev/null.
  • Update to check script checkleapvulnerability.sh to check for the existence of the /bin/ps command before proceeding.
  • Update to check script checklocalhost.sh to check for the existence of the /bin/ping command before proceeding.
  • Update to check script checklocation.sh to redirect errors of the hostnamectl command to /dev/null.
  • Update to check script checklvmpoolusage.sh to check for the existence of the /sbin/lvs command before proceeding.
  • Update to check script checkmemoryutilization.sh to check for the existence of the /bin/free command before proceeding.
  • Update to check script checkmemvscpu.sh to ensure either dmidecode or free provides the memory information before proceeding.
  • Update to check script checknfsnetdev.sh to check for the existence of file /etc/fstab before proceeding.
  • Update to check script checknfsnodename.sh to check for the existence of file /etc/fstab before proceeding.
  • Update to check script checkopennfsexports.sh to check for the existence of the /bin/ps command before proceeding.
  • Update to check script checkpacketloss.sh to check for the existence of the /bin/ping command before proceeding.
  • Update to check script checkpatrolagent.sh to check for the existence of the /bin/ps command before proceeding.
  • Update to check script checkpatrolpukremote.sh to check for the existence of the /bin/ps command before proceeding.
  • Update to check script checkpatrolpukserver.sh to check for the existence of the /bin/ps command before proceeding.
  • Update to check script checkpwd.sh to check for the existence of the /bin/ps command before proceeding.
  • Update to check script checkscript.sh to check for the existence of the /bin/ps command before proceeding.
  • Update to check script checksnmp.sh to check for the existence of the /bin/ps command before proceeding.
  • Update to check script checksudocommands.sh to redirect errors of the cat command to /dev/null.
  • Update to check script checksudocommandsexec.sh to redirect errors of the cat command to /dev/null.
  • Update to check script checkswapminsize.sh to check for the existence of the /bin/free command before proceeding.
  • Update to check script checkswapusage.sh to check for the existence of the /bin/free command before proceeding.
  • Update to check script checksyslogdremote.sh to check for the existence of the /bin/ps command before proceeding.
  • Update to check script checktemperature.sh to check for the existence of the /bin/bc command before proceeding.
  • Update to check script checkthreads.sh to check for the existence of the /bin/ps command before proceeding.
  • Update to check script checktimedatectlntpenabled.sh to redirect errors of the timedatectl command to /dev/null.
  • Update to check script checktop20memoryprocs.sh to check for the existence of the /bin/ps command before proceeding.
  • Update to check script checktopcpuusers.sh to check for the existence of the /bin/ps command before proceeding.
  • Update to check script checkupdate.sh to redirect errors of the ps command to /dev/null.
  • Update to check script checkuptime.sh to check for the existence of the /bin/uptime command before proceeding.
  • Update to the description of check script checkvarempty.sh to remove a typo.
  • Update to check script checkvarrunpid.sh to redirect errors of the ls command to /dev/null.
  • Update to check script checkwtmpsize.sh to improve the output message.
  • Update to check script checkzombies.sh to check for the existence of /bin/ps before proceeding.
  • Update to check script checkadminpassword.sh to check for the existence of /bin/perl before proceeding.
  • Update to check script checkall.sh to avoid the usage of perl.
  • Update to check script checkuidzeropassword.sh to exit quietly if perl is not available.
  • Update to check script checktsmsched.sh to exit quietly if perl is not available.
  • Update to check script checktsmbackup.sh to exit quietly if perl is not available.
  • Update to check script checksupportpassword.sh to exit quietly if perl is not available.
  • Update to check script checksudoerspassword.sh to exit quietly if perl is not available.
  • Update to check script checkoraclepassword.sh to exit quietly if perl is not available.
  • Update to check script checkmanagerpassword.sh to exit quietly if perl is not available.
  • Update to check script checketchostsfile.sh to exit quietly if perl is not available.
  • Update to check script checketchostsdups.sh to exit quietly if perl is not available.
  • Update to check script checketchosts.sh to check for the existence of the /bin/hostname command before proceeding.
  • Update to check script checkneedsrestarting.sh to avoid incorrectly reporting that a restart is required.
Version: v23.07.18
  • New check script checkdmesgerrors.sh to check for any errors reported by the dmesg command.
Version: v23.02.13
  • Update to check script checkuserpassword.sh to allow it to work correctly with Python v3 which has a different syntax for the crypt method.
  • Update to check script checksudoerspassword.sh to allow it to work correctly with Python v3 which has a different syntax for the crypt method.
  • Update to check script checkpostfixsmtp.sh to account for a SMTP port being configured in /etc/postfix/main.cf.
  • Update to check script checkpostfixsmtpconnection.sh to account for non-standard SMTP ports used.
  • Update to check script checkinterface.sh to avoid reporting an issue on a missing configuration file in /etc/sysconfig/network-scripts, when NetworkManager is used.
  • Update to the description of checkrngd.sh to remove a space.
  • Update to check script checkdnsdomain.sh to check for the nslookup binary before running it.
  • Update to check script checkbootgrub2grubcfgperms.sh to recommend mode 600 for /boot/grub2/grub.cfg.
  • Update to check script checkall.sh to improve the determination of the IPv4 method of assigning IP addresses.
Version: v23.02.13
  • Update to the description of check script checktraceroute.sh to fix a typo.
Version: v22.07.20
  • Update to check script checkoslevel.sh to update the preferred Operating System level for Oracle Linux to 9.0.
Version: v22.06.11
  • Update to check script checketchosts.sh to avoid checking commented entries in /etc/hosts.
Version: v22.06.07
  • Update to check script checkoslevel.sh to update the preferred Operating System level for Alma Linux to 9.0.
  • Update to check script checksubscriptionmanager.sh to ignore Alma Linux 9.0 by checking /etc/almalinux-release.
Version: v22.05.23
  • Update to check script checkpathfolders.sh to also check for important folders to be part of PATH, such as /usr/bin and /usr/sbin.
Version: v22.05.22
  • Update to check script checkusrsbinsestatusperms.sh to allow for a larger range of file sizes of binary sestatus on Red Hat Enterprise Linux 9.
  • Update to check script checkmailroot.sh to avoid reporting messages from s-nail on Red Hat Enterprise Linux 9.
Version: v22.05.21
  • Update to check script checkmcelog.sh to exclude additional entries from mcelog to avoid an error code situation.
  • Update to check script checksharutils.sh to indicate which repo to enable when installing sharutils.
  • Update to check script checkctrlaltdel.sh to avoid alerting when ctrl-alt.del.target is aliased to reboot.target.
  • Update to check script checkusrsbinsestatusperms.sh to check /usr/bin/sestatus instead on Red Hat Enterprise Linux 9.
  • Update to check script checkmailxinstalled.sh to avoid running this check on Red Hat Enterprise Linux 9 as mailx was replaced with s-nail.
  • Update to check script checklogrotate.sh to check logrotate.timer instead of /etc/cron.daily/logrotate on Red Hat Enterprise Linux 9.
  • Update to check script checkinterface.sh to check files in folder /etc/NetworkManager/system-connections/ instead of /etc/sysconfig/network-scripts on Red Hat Enterprise Linux 9.
  • Update to check script checketcrcdperms.sh to no longer check on Red Hat Enterprise Enterprise Linux 9, as this functionality was removed.
  • Update to check script checketclogrotatedsyslog.sh to check file rsyslog instead of syslog in Red Hat Enterprise Linux 9.
  • Update to check script checkdevconsole.sh to account for the new permissions of /dev/console in Red Hat Enterprise Linux 9.
  • Update to check script checkabrtinstalled.sh to avoid running on Red Hat Enterprise Linux 9 and up, as the ABRT tool has been removed in this version.
  • Update to check script checkcleanetcssh.sh to exclude reporting on folder /etc/ssh/sshd_config on Red Hat Enterprise Linux 9 and up.
Version: v22.05.20
  • Update to check script checkoslevel.sh to recommend newer levels for CentOS Stream, Rocky Linux, Alma Linux and Red Hat Enterprise Linux.
  • Update to check script checklvmconfbackup.sh to avoid warning for unset settings on RHEL 8.6 and up because several settings are now defaults if not configured.
  • Update to check script checkcleanupkernels.sh to provide a command to remove unncessary kernels.
  • Update to check script checkcleanupkernels.sh to ignore a message from yum repoquery that my inadvertently cause the script to alert.
  • Update to the description of check script checksystemctldegraded.sh to indicate that the kdump service may fail if there is less than 2 GB memory allocated on the system.
  • Update to check script checkmemoryminsize.sh to improve determination if memory is reported in MB or GB.
  • Update to check script checkhostname.sh to correct an issue with checking /etc/hostname.
  • Update to check script checkmcelog.sh to update the yum command to install mcelog.
  • Update to the description of check script checkauditrules.sh to remove a typo.
Version: v22.05.03
  • Update to check script checketcfstabfilesystems.sh to avoid reporting on file systems of type squashfs.
  • Update to check script checkinodeusage.sh to avoid reporting on file systems of type squashfs.
Version: v22.04.26
  • Update to check script checkvsftpdanonymous.sh to avoid reporting on commented entries in vsftpd.conf file.
Version: v22.03.09
  • New check script checketcfstabuuid.sh to check if the correct UUIDs are listed in /etc/fstab.
Version: v22.02.18
  • New check script checkbootpartition.sh to check if the /boot folder is located on a separate partition.
  • New check script checklsinitrd.sh to check if all the initramfs files in the /boot folder are valid.
  • New check script checkcleanupkernels.sh to check if old kernels are properly removed.
  • New check script checkkernelmatchinginitramfs.sh to check if a matching initramfs is available for each installed kernel.
Version: v21.11.17
  • Update to check script checkyumcheckupdate.sh to only alert about possible updates when yum update also indicates that packages would be installed during a system update.
Version: v21.11.15
  • Fixed a typo in the output of check script checkctrlaltdel.sh.
  • Update to check script checkrngd.sh to remove the -y option for the yum install command.
  • Update to check script checkkdumpctl.sh to redirect stderr to stdout for the kdumpctl command, to allow for a proper check of the kdump status.
  • Update to check script checksharutils.sh to allow for a different command to install sharutils on CentOS.
  • Update to check script checksharutils.sh to allow for a different command to install sharutils on Rocky Linux.
  • Disabled check script checkvmlinuxfirmware.sh to avoid unnecessary alerts when the linux-firmware package is installed on a VM.
  • Update to check script checkoslevel.sh to recommend version 8.5.2111 of CentOS, as well as updates for Rocky Linux and AlmaLinux.
Version: v21.10.11
  • Update to check script checkspectremeltdown.sh to upgrade the script from version 3.1 to version 3.3 (latest).
Version: v21.10.03
  • Update to check script checkfsdirwrite.sh to exclude file systems of type efivarfs.
  • Update to check script checkgrub2cfg.sh to avoid running on UEFI based systems.
  • Update to check script checkmemvscpu.sh to account for systems not reporting memory via dmidecode -t memory.
  • Update to check script checkoslevel.sh to recommend version 8.4.2105 of CentOS to be installed.
Version: v21.08.18
  • Update to check script checksubscriptionmanager.sh to allow it to work correctly on Rocky Linux.
  • Update to check script checkcleanetcsysconfig.sh to allow it to work correctly on Rocky Linux.
Version: v21.08.17
  • Support added for Alma Linux and Rocky Linux.
  • Update to check script checkall.sh to allow it to work correctly on Rocky Linux.
  • Update to check script checkl1tf.sh to allow it to work correctly on Rocky Linux.
  • Update to check script checklastlogperms.sh to allow it to work correctly on Rocky Linux.
  • Update to check script checkvarlogbtmpperms.sh to allow it to work correctly on Rocky Linux.
  • Update to check script checkyumconfperms.sh to allow it to work correctly on Rocky Linux.
  • Update to check script checkyumutils.sh to allow it to work correctly on Rocky Linux.
Version: v21.05.05
  • Support added for CentOS Stream.
  • Update to check script checkyumutils.sh to test for both packages yum-utils and dnf-utils on systems with version 8 and up.
Version: v21.05.03
  • Update to check script checkall.sh to indicate that UNIX Health Check for Red Hat Enterprise Linux is suitable only for specific operating systems only.
  • Update to check script checkrngd.sh to correctly discover if rngd is active on the system.
  • Update to check script checkoslevel.sh to adapt it for CentOS Stream.
  • Update to check script checksharutils.sh to use the dnf command on CentOS 8 and up to install the sharutils command using the PowerTools repository.
Version: v21.04.01
  • Update to check script checklastlogperms.sh to allow it to work correctly on AlmaLinux.
  • Update to check script checkvarlogbtmpperms.sh to allow it to work correctly on AlmaLinux.
  • Update to check script checkyumconfperms.sh to allow it to work correctly on AlmaLinux.
  • Update to check script checkyumutils.sh to allow it to work correctly on AlmaLinux.
  • Update to check script checkhisttimeformat.sh to correct the output shown.
Version: v21.03.31
  • Update to check script checkall.sh to enable it for AlmaLinux.
  • Update to check script checkfsdirwrite.sh to exclude tracefs type file systems.
  • Update to check script checkfsmounted.sh to properly exclude swap mounts.
  • Update to check script checkl1tf.sh to allow it to work correctly on AlmaLinux.
Version: v21.01.18
  • Update to check script checkdfsummary.sh to avoid counting duplicate mounted file systems.
Version: v20.12.18
  • Update to check script checkoslevel.sh to recommend version 8.3 for CentOS, Red Hat Enterprise Linux and Oracle Linux.
Version: v20.11.30
  • Update to check script checkrpm.sh to clean up temporary files used by the script.
Version: v20.11.18
  • Update to check script checkhomedirs.sh to avoid reporting errors on empty lines in /etc/passwd.
Version: v20.11.13
  • Update to check script checkcleansshdir.sh to allow the config file within the ~root/.ssh folder.
  • Update to check script checkcleansshdiroracle.sh to allow the config file within the ~oracle/.ssh folder.
Version: v20.11.12
  • New check script checksentinelone.sh to check the SentinelOne agent, if installed on the system.
Version: v20.11.11
  • Update to check script checkhostnamevsdns.sh to ensure any multiple DNS entries are printed out as part of the output.
  • Update to check script checkmodelname.sh to also attempt to use lshw, if installed, to determine the system model.
  • Update to check script checkmodelname.sh to display the IBM Model in case the system is running Linux on Power hardware.
  • Update to check script checkall.sh to also attempt to use lshw, if installed, to determine the system model.
  • Update to check script checkoslevel.sh to recommend updating to version 7.9 of Red Hat Enterprise Linux and Scientific Linux and/or version 8.2 of Red Hat Enterprise Linux, CentOS, and Oracle Linux.
  • Update to check script checkrpmv.sh to list only the first 100 entries, in case there are more than 100 entries shown by the rpm -Va command.
Version: v20.11.10
  • New check script checkmounts.sh to check the number of file system mount points on the system.
  • Update to check script checkmount.sh to only display the first 100 entries of the output of the mount command.
  • Update to check script checkhostnamevsdns.sh to work correctly if there are multiple DNS entries present for the IP address of the system.
  • Update to check script checkpatrollevel.sh to check for version 11.3 of BMC Patrol Agent or higher.
Version: v20.11.08
  • Update to the description of the check script checkcpucount.sh to include information about the nproc command.
Version: v20.09.28
  • Update to check script checkemcpowerpathlevel.sh to recommend updating Dell EMC PowerPath to version 7.2.
Version: v20.08.28
  • New check script checkfritzfrog.sh to check if there are any indicators for the FritzFrog malware.
  • Update to check script checkuptime.sh to update the category of the check script.
Version: v20.08.26
  • New check script checksg3utils.sh to check if the sg3_utils RPM is installed.
Version: v20.08.24
  • Update to check script checklvmpoolusage.sh to clean up the temporary file used.
Version: v20.08.17
  • New check script checklvmpoolusage.sh to check the usage of LVM pools.
Version: v20.08.10
  • Update to the description of check script checkbios.sh, to explain the information provided by this check script on virtual infrastructure.
Version: v20.07.29
  • New check script checklast.sh to check the owner and permissions of /usr/bin/last.
  • Update to check script checktemperature.sh to improve cpu core temperature monitoring.
Version: v20.07.16
  • Update to check script checksubscriptionmanagerinstalled.sh to avoid reporting the message on non-Red Hat Enterprise Linux systems when podman is installed as well.
Version: v20.07.09
  • New check script checkentropy.sh to check the available entropy (randomness) on the system.
  • New check script checkrngd.sh to check if rngd is running.
Version: v20.06.26
  • Update to check script checksyslogdremote.sh to correct a typo in a comment.
Version: v20.06.22
  • New check script checkvarrunpid.sh to check for any pid files in /var/run without a running program.
Version: v20.06.15
  • Update to check script checkemcpowerpathlevel.sh to recommend version 7.1 of Dell EMC PowerPath.
Version: v20.05.26
  • Update to check script checkall.sh to include MB for the paging space size of the system.
  • Update to check script checkbondlink.sh to indicate when a bonded network interface is configured on the system without any slave interfaces.
  • Update to check script checkmemoryminsize.sh to account for huge memory sizes (1 TB and up).
  • Update to check script checkoraclepassword.sh to correctly check for passwords on Oracle Linux 6.10.
  • Update to check script checkadminpassword.sh to correctly check for passwords on Oracle Linux 6.10.
  • Update to check script checkhaltpassword.sh to correctly check for passwords on Oracle Linux 6.10.
  • Update to check script checkmanagerpassword.sh to correctly check for passwords on Oracle Linux 6.10.
  • Update to check script checkshutdownpassword.sh to correctly check for passwords on Oracle Linux 6.10.
  • Update to check script checksupportpassword.sh to correctly check for passwords on Oracle Linux 6.10.
  • Update to check script checkuidzeropassword.sh to correctly check for passwords on Oracle Linux 6.10.
  • Update to check script checkrpm.sh to output the issues found by the rpm -V command.
  • Update to check script checkthreadsperuser.sh to find the bc utility in the correct folder on Oracle Linux 6.10.
  • Update to check script checkifconfig.sh to correctly report the network interface configuration on Oracle Linux 6.10 with bonded network interfaces.
Version: v20.05.24
  • Update to check script checknfsnodename.sh to exclude checking entries that are commented out in /etc/fstab.
Version: v20.04.26
  • Update to check script checkoslevel.sh to recommend new releases.
  • Update to check script checknroffilesinfilesystems.sh to only report on local file systems.
  • New check script checknfsutils.sh to check if the nfs-utils RPM package has been installed on the system.
  • Update to check script checkcleanetc.sh to exclude checking for file /etc/nsswitch.conf.bak.
Version: v20.04.25
  • Update to check script checkexports.sh to avoid reporting on entries that start with a dash and to improve detection of duplicate entries.
Version: v20.04.24
  • Update to checkall.sh to allow for files to be excluded within an external file with both short and full path file names.
  • Update to check script checkvarspoolperms.sh to update the text of the output generated.
  • Update to check script checkvarspoolmqueueperms.sh to update the text of the output generated.
  • Update to check script checketcsecurityperms.sh to update the text of the output generated.
  • Update to check script checkrhsmconfperms.sh to update the text of the output generated.
  • Update to check script checkusrbincrontabperms.sh to update the text of the output generated.
  • Update to check script checkusrperms.sh to update the text of the output generated.
  • Update to check script checkusrsbincrondperms.sh to update the text of the output generated.
  • Update to check script checkvarempty.sh to update the text of the output generated.
  • Update to check script checkvarspoolclientmqueueperms.sh to update the text of the output generated.
  • Update to check script checkvarspoolcronperms.sh to update the text of the output generated.
  • Update to check script checkvarspoollpdperms.sh to update the text of the output generated.
  • Update to check script checkvartmpperms.sh to update the text of the output generated.
  • Update to check script checkusernetrc.sh to update the text of the output generated.
  • Update to check script checkuserbashrc.sh to update the text of the output generated.
  • Update to check script checksudoersusers.sh to exclude all empty lines of lines that start with a space, but are commented out.
  • Update to check script checksudoersduplicates.sh to remove a typo.
  • Update to check script checkcrontabcommands.sh to ignore lines starting with spaces and/or tabs in front of a comment character.
  • Update to check script checkcrontabcommandsexec.sh to ignore lines starting with spaces and/or tabs in front of a comment character.
  • Update to check script checkcrontabdups.sh to ignore lines starting with spaces and/or tabs in front of a comment character.
Version: v20.03.25
  • Update to checkall.sh to allow providing text files listing scripts for both the -s (to include check scripts) and the -E (to exclude check scripts) options.
Version: v20.03.20
  • Update to check script checkpoodle.sh to avoid generating an error when port 443 is used for something else than HTTPS.
Version: v20.01.27
  • New check script checkhomeroot.sh to check the root home directory.
  • Update to check script checkall.sh to set a default for the output width in case stty -a reports 0 colums - which may happen on the console of a system.
Version: v20.01.26
  • Update to check script checkall.sh to require sendmail to be installed before running checkall.sh, which is no longer included by default on RHEL 8, but is however still available for installation.
  • Update to check script checksendmail.sh to alert if RPM package sendmail has not been installed.
Version: v20.01.24
  • Update to check script checkall.sh to correct a typo.
Version: v20.01.22
  • Update to check script checkall.sh to ensure that the output of virt-what is printed correctly on oVirt.
  • Update to check script checkvm.sh to ensure that the output of virt-what is printed correctly on oVirt.
Version: v20.01.18
  • Update to check script checkcleansshdir.sh to avoid reporting file known_hosts.old as a file to be removed.
Version: v20.01.08
  • Update to check script checkbusydisks.sh to avoid reporting both disks and device mapper devices.
  • Update to check script checklsblka.sh to include additional columns that show more information about available block devices on the system.
Version: v20.01.02
  • Update to check script checkbusydisks.sh to correctly report disk utilization when disks are busy.
Version: v19.12.28
  • Update to check script checkexports.sh to exclude entries in /etc/exports that are commented out.
Version: v19.12.23
  • Update to check script checkall.sh to include the BIOS vesion and the BIOS release date in the system configuration section.
  • New check script checkbios.sh to display the installed BIOS version and the BIOS release date.
Version: v19.12.21
  • Update to check script checktemperature.sh to improve the output generated by the script.
Version: v19.12.20
  • New check script checktemperature.sh to check the temperature of the system.
Version: v19.12.19
  • Update to check script checkrpmv.sh to no longer report file mode differences on the /sys folder as suggested by rpm -Va.
  • Update to check script checkntpdate.sh to account for a different format of output of the ntpdate command on Oracle Linux 6.10.
Version: v19.12.14
  • New check script checkcryptoutils.sh to check if the crypto-utils package has been installed.
Version: v19.12.12
  • Update to check script checkemcinq.sh to ensure the script doesn't hang when there is a faulty fibre channel adapter.
Version: v19.12.09
  • Update to check script checkcrontabcommandsexec.sh to avoid reporting an error if a command within a crontab file starts with a non-alphanumeric character.
Version: v19.11.21
  • Update to check script checksplunkthpdisabled.sh to ensure it works correctly in case RHEL versions 7 or higher are used.
Version: v19.11.13
  • New check script checkirqbalance.sh to check if the irqbalance RPM is installed.
Version: v19.11.11
  • Functionality of UNIX Health Check for RHEL 8.1 validated.
  • Update to check script checketchosts.sh to recommend using DNS when there are many entries in /etc/hosts.
Version: v19.11.06
  • Update to check script checkrpmqahistory.sh to ensure all entries are printed on individual lines.
  • Update to check script checkrpmqa.sh to ensure the output is printed correctly.
Version: v19.10.24
  • Update to check script checkrpmv.sh to exclude an additional item for Mozilla Firefox.
Version: v19.10.23
  • Update to check script checkcrontabs.sh to improve excluding the root user from the list of users to check.
  • Update to check script checksudoersusers.sh to exclude netgroups (starting with a plus sign) in /etc/sudoers.
Version: v19.10.22
  • New check script checketchostsnohostname.sh to check for entries in /etc/hosts that only list the IP address, and no hostname.
  • New check script checketchostsvsdns.sh to check for entries in /etc/hosts that are also known in DNS.
  • New check script checketchostsequiv.sh to check if there are NO entries in /etc/hosts.equiv.
  • New check script checketchostsduplicates.sh to check for more than 1 entry in /etc/hosts for the hostname.
  • New check script checketchostscharacters.sh to check for any non alpha-numeric characters in /etc/hosts.
  • New check script checketchostsdups.sh to list any duplicate entries in the /etc/hosts file.
  • New check script checketchostsfile.sh to display the contents of the /etc/hosts file.
Version: v19.10.18
  • Update to check script checkrpmqahistory.sh to correctly display the list of installed RPM packages.
  • Update to check script checksudoprivilegeescalation.sh to avoid running it on CentOS and RHEL 8, as the script is not designed for these systems.
  • Update to the description of check script checksharutils.sh to explain how to enable the PowerTools repo for CentOS 8.0, before installing the sharutils package.
  • Update to check script checkyumutils.sh to ensure it works properly for CentOS 8.0.
  • Update to the description of check script checkrsyslogforwarding.sh to explain that the rsyslog daemon needs to be restarted after updating the configuration file(s) for rsyslog.
Version: v19.10.13
  • Update to check script checkoslevel.sh to recommend version 8.0 of CentOS.
  • Update to check script checkneedsrestarting.sh to correct a typo in the dnf command.
  • Update to check script checkcleanetcssh.sh to avoid reporting the /etc/ssh_config.d directory.
  • Update to check script checkvarlogbtmpperms.sh to adjust the script for CentOS 8.0.
  • Update to check script checketchostsallow.sh to adjust the script for CentOS 8.0.
  • Update to check script checketchostsallowperms.sh to adjust the script for CentOS 8.0.
  • Update to check script checketchostsdeny.sh to adjust the script for CentOS 8.0.
  • Update to check script checketchostsdenyperms.sh to adjust the script for CentOS 8.0.
  • Update to check script checklastlogperms.sh to adjust the script for CentOS 8.0.
  • Update to check script checkl1tf.sh to adjust the script for CentOS 8.0.
Version: v19.10.12
  • Update to check script checkvim.sh to print out the recommended version of vim to use.
  • Update to check script checkyumconfperms.sh to adjust the script for CentOS 8.0.
Version: v19.09.18
  • Update to check script checkoslevel.sh to recommend level 7.7.1908 (Core) of CentOS to be installed.
  • Update to check script checkcleanetc.sh to exclude any files with the .rpmnew extension from being reported.
Version: v19.09.05
  • Update to check script checkoslevel.sh to recommend version 7.7 of Red Hat Enterprise Linux, Oracle Linux and Scientific Linux.
Version: v19.09.04
  • Update to check script checkswapminsize.sh to add a missing word in the output.
Version: v19.08.09
  • New check script checkiotop.sh to check if the iotop package has been installed.
  • New check script checkcrashkernel.sh to check for the crashkernel entry in /etc/default/grub.
  • New check script checkcrash.sh to check for any kernel dumps present on the system.
  • New check script checkkdumpctl.sh to check that the kdumpctl status command says that kdump is operational.
  • New check script checketckdumpconfperms.sh to check the permissions, owner and group of /etc/kdump.conf.
  • New check script checkkdump.sh to check that the kdump daemon is both started and enabled at system boot.
Version: v19.08.01
  • Update to check script checkcleansystem.sh to remove checking folder /var/tmp, as that folder is already checked through check script checkvartmp.sh.
Version: v19.07.25
  • New check script checkext2.sh to check for any ext2 file systems on the system.
  • New check script checklostfoundsize.sh to check the size of the lost+found subfolders for XFS file systems.
Version: v19.07.23
  • New check script checkmcelog.sh to check if mcelog reports any machine check exceptions (hardware errors).
  • New check script checksystemctllistjobs.sh to check for any systemd unit jobs still running as listed by the systemctl list-jobs command.
  • New check script checkgrub2cfg.sh to check if the GRUB2 configuration file /boot/grub2/grub.cfg has valid contents.
  • New check script checkaudit.sh to check that the audit daemon is both started and enabled at system boot.
  • New check script checkauditrules.sh to check that rules are indeed defined for the audit system.
  • New check script checkauditperms.sh to check if the permissions of the /etc/audit folder are correctly set.
Version: v19.07.18
  • New check script checkpermitemptypasswords.sh to check if the PermitEmptyPasswords entry in /etc/ssh/sshd_config is either commented out or set to no.
  • New check script checksshpubkeyauthentication.sh to check if the PubkeyAuthentication entry in /etc/ssh/sshd_config is either commented out or set to yes.
  • New check script checksshhostbasedauthentication.sh to check if the HostBasedAuthentication entry in /etc/ssh/sshd_config is either commented out or set to no.
  • New check script checksshignorerhosts.sh to check if the IgnoreRhosts entry in /etc/ssh/sshd_config is either commented out or set to yes.
  • New check script checksshmaxauthtries.sh to check if the MaxAuthTries entry in /etc/ssh/sshd_config is either commented out or set within the range 3 to 6.
  • Update to check script checkctrlaltdel.sh to also include a check for the Systemd target ctrl-alt-del, to ensure it is disabled.
  • Update to check script checkvim.sh to also display the recommended version of Vim to be upgraded to.
Version: v19.07.17
  • New check script checketcsecurettyperms.sh to check the permissions of /etc/securetty.
  • Update to check script checketcmotdperms.sh to also check the permissions of folder /etc/motd.d on a RHEL 8 system.
  • New check script checkcleanetcssh.sh to check for any files in /etc/ssh that can be cleaned up.
  • New check script checksshbanner.sh to check the Banner entry in sshd_config.
  • New check script checkpuppetconf.sh to check the configuration of the Puppet agent.
  • New check script checkpuppetconfperms.sh to check the permissions of /etc/puppet/puppet.conf.
  • New check script checkpuppetenabled.sh to check if the Puppet agent is enabled to start at boot.
  • New check script checkpuppetactive.sh to check if the Puppet agent is running.
Version: v19.07.16
  • New check script checksplunkenabled.sh to check if the Splunk forwarder agent is enabled to start at boot.
  • New check script checksplunkactive.sh to check if the Splunk forwarding agent is active.
  • Update to check script checketchostsnonnumeric.sh to correct an issue with checking the correct IP address format, as awk acts differently on RHEL 6, compared to RHEL 7 and RHEL 8.
  • New check script checkrsyslogforwarding.sh to check if the rsyslog messages are forwarded to a central logging server.
Version: v19.07.15
  • New check script checkvim.sh to check for the correct level of vim in regards to RHSA-2019:1619.
  • New check script checklibssh2.sh to check for the correct level of libssh2 in regards to RHSA-2019:1652.
  • Update to check script checkyumutils.sh to update the command to install the dnf-utils package.
  • Update to check script checkneedsrestarting.sh to allow the check script to work correctly on RHEL 8, now that the -r option for needs-restarting has been removed in RHEL 8.
Version: v19.07.14
  • Update to check script checkcleansystem.sh to avoid checking folders in use for either Docker or Podman container storage.
Version: v19.07.09
  • Update to check script checkrpmv.sh to add the --nomtime option for rpm -Va to reduce the amount of CPU used to verify the RPM file integrity.
  • New check script checkrpmdatabase.sh to check for the integrity of the RPM database.
  • Update to check script checkall.sh to update the message in case a check script takes too long too run.
  • Update to check script checkusershell.sh to avoid messages on a system configured with LDAP authentication.
  • Update to check script checkiddsapub.sh to correctly check for the group of file id_dsa.pub.
  • Update to check script checkfswrite.sh to check if a mount point is a directory before attempting to create a file in it.
  • Update to check script checkfsdirwrite.sh to check if a mount point is a directory before attempting to create a folder in it.
  • Update to check script checkexpireduseraccounts.sh to avoid reporting an error if the password_days attribute is not set in /etc/shadow.
  • Update to check script checketcshadowused.sh to avoid checking entries in place for LDAP authentication.
  • Update to check script checketcnamedconfperms.sh to avoid checking the permissions of /etc/named.conf if it is a link to another file.
  • Update to check script checkcleanetc.sh to find several old copies of configuration files in the /etc folder.
Version: v19.07.05
  • Update to check script checkadapterlink.sh to avoid generating errors when Docker interfaces are used on the system.
Version: v19.06.06
  • New check script checkdevurandom.sh to check if device /dev/urandom exists.
  • New check script checkdevurandom.sh to check if the device /dev/urandom exists.
Version: v19.05.28
  • Update to check script checkmemoryutilization.sh to correctly calculate the memory usage both on RHEL6 and RHEL7 systems.
Version: v19.05.22
  • New check script checkpatrolpukserver.sh to check if there's a process pukserver.xpc active using a large amount of CPU.
  • New check script checkpatrolpukremote.sh to check if there's a process pukremotexec.xpc active using a large amount of CPU.
  • New check script checkpatrollevel.sh to check the level of the BMC Patrol Agent.
  • New check script checkpatrolfilesystem.sh to check if /opt/bmc is set up in a separate file system for BMC's Patrol Agent.
  • New check script checkpatrolagent.sh to check if BMC's PatrolAgent is using a lot of CPU.
Version: v19.05.16
  • New check script checkemcpowerpathunlicensed.sh to check for any unlicensed paths for EMC PowerPath.
  • New check script checkemcpowerpathlicense.sh to check if the powerpath license isn't expired or expring.
  • New check script checkemcpowerpathlevel.sh to check the PowerPath level, if installed.
  • New check script checkemcpowerpathdeadpaths.sh to check if there are any EMC PowerPath dead/degraded/failed paths.
  • New check script checkemcpowermttrespass.sh to check for any EMC PowerPath devices that are trespassed.
  • New check script checkemcpowermtpathsvsadapters.sh to check if at least 4 fibre channel adapter ports are used, if available, for EMC PowerPath.
  • New check script checkemcpowermtpaths.sh to check the number of paths for each fibre adapter, in use for EMC storage.
  • New check script checkemcpowermt.sh to run EMC's PowerPath command powermt, if possible.
  • New check script checkemcpowermtafm.sh to check for the array failover mode through powermt.
  • New check script checkemcinq.sh to run the inq utility of EMC, if present on the system.
Version: v19.05.14
  • Update to check script checkoslevel.sh to update comment for RHEL 8.0.
Version: v19.05.13
  • Completed testing of UNIX Health Check for Red Hat Enterprise Linux 8.0.
  • Update to check script checkbusydisks.sh to only list disks and not device mapper logical volume devices.
  • Update to check script checkyumcron.sh to not have this check script run on RHEL 8.0.
  • Update to the description of check script checksharutils.sh to add information on how to install sharutils on RHEL 8.0.
  • Update to check script checketcnsswitchconfperms.sh to check the correct nsswitch.conf file on RHEL 8.0.
Version: v19.04.17
  • Update to check script checksystemid.sh to avoid generating an error when RPM package bind-utils is not installed on the system.
  • Update to check script checkswapusage.sh to alert if no swap space is defined.
  • Update to check script checkrootpassword.sh to allow it to work correctly if no password has been set for user root at all.
Version: v19.04.04
  • New check script checkpostfixsmtpdbanner.sh to check if a proper smtpd_banner is listed in /etc/postfix/main.cf.
Version: v19.04.03
  • New check script checkvarfilesystem.sh to check if /var is a separate file system.
  • New check script checketcissueperms.sh to check the permissions of /etc/issue.
Version: v19.04.02
  • New check script checketchostsnonnumeric.sh to check for non-numeric entries in /etc/hosts.
Version: v19.03.26
  • Update of the package to allow for an RPM build of UNIX Health Check for Red Hat Enterprise Linux.
Version: v19.03.22
  • Update to check script checkenvironment.sh to allow the EXTENDED_HISTORY entry in /etc/environment.
Version: v19.03.21
  • New check script checkchronyservers.sh to check if the configured servers in /etc/chrony.conf can be used for time synchronization.
  • New check script checkntpservers.sh to check if the configured NTP servers can be used for time synchronization.
  • New check script checkextendedhistory.sh to check if environment variable EXTENDED_HISTORY is set to ON in /etc/environment.
  • New check script checkrsh.sh to check if the rsh RPM is not installed.
  • New check script checkrshserver.sh to check if the rsh-server RPM is not installed.
  • New check script checketclogindefsduplicates.sh to check for any duplicate entries in /etc/login.defs.
Version: v19.03.14
  • Update to check script checkusershell.sh to list users with a non-existing shell underneath each other instead of next to each other.
  • Update to check script checkpamunix.sh to recommend changing to the SHA512 algorithm only once, even if it isn't set in both /etc/pam.d/system-auth and in /etc/pam.d/password-auth.
  • Update to check script checkdefaultusersettings.sh to correct a typo in the SHA512 recommendation setting.
  • Update to check script checkcrontabcommands.sh to allow it to work correctly if a crontab file owned by a user that has a home directory in a file system other than /home.
  • Update to check script checkmachineid.sh to correctly display the machine ID for Red Hat Enterprise Linux version 6 (and below) systems.
Version: v19.03.11
  • New check script checktree.sh to check if the tree RPM package has been installed on the system.
  • Addition of the LICENSE file to the package.
Version: v19.03.07
  • Update to check script checksshdirfiles.sh to also allow stricter permissions for ~root/.ssh/known_hosts.
Version: v19.02.25
  • New check script checkuserchars.sh to check for user accounts that use special characters in the user name.
Version: v19.02.03
  • Update to check script checkpacemakerclusterstatus.sh to avoid writing an empty file called "1", due to an error in acommand redirecting stderr to stdout.
Version: v19.01.29
  • Update to check script checkemptyvg.sh to redirect any errors of LVM commands to /dev/null.
  • Update to check script checklvunavailable.sh to redirect any errors of LVM commands to /dev/null.
Version: v19.01.28
  • New check script checklvmconfbackup.sh to check for the correct backup and archive settings in /etc/lvm/lvm.conf.
Version: v19.01.23
  • New check script checkbusydisks.sh to check for any disks that are more than 20% busy on average and currently.
Version: v19.01.18
  • New check script checkguestagent.sh to check if the Guest Agent and drivers have been installed on a Red Hat Virtulization hosted Virtual Machine.
Version: v19.01.17
  • Update to check script checkvarlogbtmpperms.sh to correctly report the permissions on /var/log/btmp on Red Hat Enterprise Linux version 8.
Version: v19.01.02
  • Update to check script checkpostfixmyorigin.sh to avoid alerting if myorigin in the Postfix main.cf configuration file is set to part of the domain name.
  • Update to check script checkfswrite.sh to avoid checking CIFS mounted file systems.
  • Update to check script checkfsdirwrite.sh to avoid checking CIFS mounted file systems.
  • Update to check script checketcfstabfilesystems.sh to avoid reporting a file system, which is actually a file system mounted on top of a LVM snapshot.
  • Update to check script checkvarlogbtmpperms.sh to correctly report the permissions on /var/log/btmp on Red Hat Enterprise Linux version 8.
Version: v18.12.30
  • Update to check script checkcleansystem.sh to exclude .cache/imsettings/log.bak files in home directories from being reported.
Version: v18.12.23
  • Update to check script checketcfstabfilesystems.sh to avoid reporting an error when a file system is NFS mounted through autofs.
  • Update to check script checkhomesize.sh to avoid checking the size of the /home file system, if the file system is auto-mounted through NFS.
Version: v18.12.22
  • Update to check script checkntpdate.sh to avoid reporting any errors when chronyd is active instead of ntpd.
  • Update to check script checkntpoptions.sh to avoid reporting any errors when chronyd is active instead of ntpd.
  • Update to check script checkntpslewing.sh to avoid reporting any errors when chronyd is active instead of ntpd.
  • Update to check script checkntpsteptickers.sh to avoid reporting any errors when chronyd is active instead of ntpd.
  • Update to check script checkntpsynchwclock.sh to avoid reporting any errors when chronyd is active instead of ntpd.
  • Update to check script checkfirewallstate.sh to avoid reporting a color coded error, as generated by the firewall-cmd, when the firewalld has an error status.
  • New check script checkhomedirperms.sh to check the permissions, owner and group of the home directory of root.
  • Update to check script checkroothomedir.sh to exit if the home directory of user root does not exist.
Version: v18.12.21
  • Update to check script checkfswrite.sh to avoid alerting on file systems mounted through autofs.
  • New check script checkdebugshell.sh to check if the debug-shell service is active and/or enabled.
  • New check script checkfirewallpermanent.sh to check the current vs the permanent settings of the firewall daemon.
  • New check script checkfirewallzone.sh to display the default zone used bye the firewall daemon.
  • New check script checkfirewallstate.sh to check the current state of the firewall daemon.
  • New check script checksystemctlgetdefault.sh to display the default target configured on the system.
Version: v18.12.17
  • New check script checklsof.sh to check if the lsof tool has been installed on the system.
  • New check script checksubscriptionmanagerinstalled.sh to check if the subscription-manager tools are installed.
  • Removed check script checkkernel.sh, as it is a duplicate of check script checkkernelrelease.sh.
  • New check script checkrsync.sh to check if the rsync tool has been installed on the system.
Version: v18.12.16
  • Update to check script checksubscriptionmanager.sh to add additional text to explain the status of the subscription.
Version: v18.12.14
  • New check script checkdevconsole.sh to check if /dev/console exists and is not a regular file, and has the correct permissions.
  • New check script checkdfhang.sh to check for any hanging df commands.
  • New check script checkpoodle.sh to check if this system is vulnerable for the known Poodle vulnerability in SSLv3.
Version: v18.12.13
  • New check script checkfirewallenabledentries.sh to display the enabled and added entries in the firewall, if the firewalld daemon is running.
  • New check script checkfirewalld.sh to display the the current status of the firewalld daemon.
  • New check script checkyumrepolist.sh to display the enabled repositories on the system.
  • Update to check script checkfswrite.sh to exclude any Docker overlay file systems from checking.
  • Update to check script checketcfstabfilesystems.sh to exclude any Docker overlay file systems from checking.
  • Update to check script checkpvunallocatable.sh to include information on how to add a LVM2 type disk to a volume group.
Version: v18.12.12
  • New check script checkuid.sh to check if all UIDs are not negative and not greater than 2147483646, in response to CVE-2018-19788.
Version: v18.12.11
  • Update to check script checkhighcpu.sh to ensure an error is reported if processes with high CPU usage are detected.
Version: v18.12.10
  • New check script checknfsnodename.sh to check if the nodename for any NFS file system can be pinged.
  • New check script checknfsconfig.sh to display the NFS configuration (exported and mounted NFS file systems)
  • New check script checkemptyvg.sh to check if a volume group is empty.
  • New check script checkpsmisc.sh to check if the psmisc RPM package is installed.
  • New check script checkhighcpu.sh to check if there are any processes using more than 20% of CPU.
  • Update to check script checkpostfix.sh to alert if Postfix is not installed on the system.
  • New check script checktar.sh to check if the tar RPM package is installed.
Version: v18.12.07
  • Update to check script checkoslevel.sh to add an additional check for Red Hat Enterprise Linux version 8.
  • Update to check script checkchronyd.sh to allow it to work with pools of NTP servers as well instead of NTP servers only in /etc/chronyd.conf.
  • Update to check script checkvirshnodeinfo.sh to redirect any errors of the virsh command to /dev/null to avoid reporting any errors.
  • Update to check script checkvirshlist.sh to redirect any errors of the virsh command to /dev/null to avoid reporting any errors.
  • Update to check script checkcrondenyperms.sh to ensure it works on CentOS, Scientific Linux and Oracle Linux.
  • Update to check script checklastlogperms.sh to ensure it works on CentOS, Scientific Linux and Oracle Linux.
  • Update to check script checkvarlogbtmpperms.sh to ensure it works on CentOS, Scientific Linux and Oracle Linux.
  • Update to check script checkyumconfperms.sh to ensure it works on CentOS, Scientific Linux and Oracle Linux.
Version: v18.12.06
  • Update to check script checkcrondenyperms.sh to take into consideration the permissions differences on RHEL 8.0 for /etc/cron.deny.
  • Update to check script checkfsdirwrite.sh to exclude file system mount type bpf from checking.
  • Update to check script checkl11tf.sh to avoid running the check script on RHEL 8.0, as the script was not designed for this version.
  • Update to check script checklastlogperms.sh to take into consideration the permissions and group ownership differences on RHEL 8.0.
  • Update to check script checklocalhost.sh to allow it to work on systems using IPv6.
  • Update to check script checkrhsmcertd.sh to ensure it will run without generating errors on RHEL 8.0.
  • Update to check script checksudoprivilegeescalation.sh to avoid running it on RHEL 8 as the script does not support that version.
  • Update to check script checksyslogconfvsrsyslogconf.sh to avoid alerting on first run of rsyslog.
  • Update to check script checksyslogdactive.sh to ensure it will run without generating errors on RHEL 8.0.
  • Update to check script checksyslogdremote.sh to ensure it will run without generating errors on RHEL 8.0.
  • Update to check script checkusrsbinsestatusperms.sh to avoid alerting on the size of /sbin/sestatus on RHEL 8.0.
  • Update to check script checkvarlogbtmpperms.sh to check for the correct file permissions on RHEL 8.0, which are different compared to earlier versions.
  • Update to check script checkyumconfperms.sh to check for file /etc/dnf/dnf.conf instead of /etc/yum.conf on RHEL 8.0.
  • Update to check script checkyumcron.sh to allow the script to determine the correct operating system level on RHEL 8.0.
Version: v18.12.05
  • New check script checkdnsdomain.sh to determine the domain name of the system through DNS.
  • New check script checkdevrandom.sh to check if devices /dev/random and /dev/urandom exist.
  • New check script checkfsperms.sh to display the file system permissions.
  • New check script checkfsdirwrite.sh to check if a directory can be created within each file system.
  • New check script checkfsmountpoint.sh to check if the mount point for each file system exists.
Version: v18.12.04
  • New check script checknobody.sh to check if user and group nobody exists.
  • New check script checknameservers.sh to display the contents of /etc/resolv.conf.
  • New check script checkmntperms.sh to check if the permissions of the /mnt folder are correctly set.
  • New check script checkrootfolders.sh to check if important folders in the root directory are located in the root file system.
  • Update to check script checklvs.sh to add the -v option which also displays the LV UUID.
  • Update to check script checkpvs.sh to add the -v option which also displays the PV UUID.
  • Update to check script checkvgs.sh to add the -v option which also displays the VG UUID.
  • New check script checkkernel to display the kernel version in use on the system.
  • Support has been added for Red Hat Enterprise Linux 7.6, Scientific Linux 7.6, Oracle Linux 7.6 and Centos 7.6.1810.
  • Update to check script checkoslevel.sh to recommend level 7.6 for Scientific Linux, and level 7.6.1810 for CentOS.
  • Update to check script checksyslogconfvsrsyslogconf.sh to avoid any errors reported by xargs, by redirecting errors of xargs to /dev/null.
Version: v18.12.03
  • New check script checkchangedfilesinetc.sh to check for any changed files in /etc within the last 24 hours.
  • New check script checknetworkadapters.sh to list all the network adapters on the system.
  • New check script checkadapterlink.sh to check if the network adapters that are in use for active network interfaces, and which are not configured in a bond, have an established link.
  • New check script checkmotd.sh to check the contents of /etc/motd.
  • New check script checknroffilesinfilesystems.sh to check for a large number of files in file systems.
  • Update to check script checkpvs.sh to redirect any errors of the pvs command to /dev/null.
  • Update to check script checkpvunallocatable.sh to redirect any errors of the pvs command to /dev/null.
  • Update to check script checkpathfolders.sh to exclude folder /root/bin from checking, as that folder usually does not exist and is already within the protected root directory.
Version: v18.12.02
  • New check script checkpatroluser.sh to check if the BMC Patrol Agent user patagt exists.
  • New check script checkpathfolders.sh to check if all the folders in the $PATH variable exist on the server.
  • New check script checkoradiag.sh to check if there are any oradiag_username folders in home directories of users.
  • New check script checkoratabpaths.sh to check for the existence of paths mentioned in /etc/oratab.
  • New check script checkauthorizedkeysentriesoracle.sh to check for any invalid entries in the authorized keys files for user oracle.
  • New check script checkauthorizedkeysentries.sh to check for any invalid entries in the authorized keys files for user root.
  • New check script checkauthorizedkeysdups.sh to check for duplicate entries or empty lines in the authorized_keys file for user root.
  • New check script checkauthorizedkeysdupsoracle.sh to check for duplicate entries or empty lines in the authorized_keys file for user oracle.
  • New check script checkoratab.sh to display the contents of /etc/oratab, if it exists.
Version: v18.12.01
  • New check script checkostype.sh to check the OS type (AIX, Linux, HP-UX, etcetera).
Version: v18.11.30
  • New check script checkpwd.sh to check if there is a large number of pwd processes running.
  • New check script checkrhosts.sh to display the contents of the ~root/.rhosts file.
  • New check script checkrootrhosts.sh to check the permissions of the rhosts file of root.
  • New check script checkpathperiod.sh to check if there's a period in the $PATH variable.
  • New check script checkrootprofile.sh to check the .profile of user root.
Version: v18.11.29
  • New check script checkroothomesize.sh to check if the home directory of user root is at least 1 GB.
  • New check script checkregularfilesinhome.sh to show if there are any regular files in /home.
  • New check script checksbinperms.sh to check if the permissions, owner, group and link target of the /sbin folder are correctly set.
  • New check script checklvunavailable.sh to check if any logical volumes are unavailable.
  • New check script checkpvunallocatable.sh to check if any physical volumes are un-allocatable.
  • Update to check script checkpacemakerclusterstatus.sh to improve the reporting of any stopped resources.
Version: v18.11.28
  • Update to check script checkusersloggedonlongtime.sh to avoid reporting on user unknown, which is the result of a known GDM bug, which makes the who command report an unkown user account.
Version: v18.11.27
  • New check script checkshadowfile.sh to check if there's a passwd shadow file /etc/shadow.
  • New check script checkscript.sh to check if there are any script processes active without a parent process.
  • New check script checksimpanaactive.sh to check if the simpana client is active.
  • New check script checksimpanalevel.sh to show the level of the CommVault Simpana client.
  • New check script checksimpanastatus.sh to show the status of the CommVault Simpana client.
  • New check script checksudoersusers.sh to check if all users, that are referenced in /etc/sudoers, indeed exist in /etc/passwd. This check script will also very if all referenced groups are known in /etc/group.
  • New check script checkstricthostkeychecking.sh to check if StrictHostKeyChecking isn't disabled in /etc/ssh/ssh_config.
Version: v18.11.26
  • New check script checksudopermissions.sh to check if the owner and permissions of sudo are correctly set.
  • New check script checksudolog.sh to check if the log file is set in /etc/sudoers.
  • New check script checksudovisudopermissions.sh to check if the owner and permissions of visudo are correctly set.
  • New check script checksystemid.sh to check if a one-line system ID can be determined.
  • New check script checksysteminstall.sh to check when the system was installed.
Version: v18.11.25
  • New check script checktsmdsmfiles.sh to check if dsm.opt or dsm.sys files are present when no TSM / IBM Spectrum Protect software is installed.
  • New check script checkyumcorruptdb.sh to check if the yum database is corrupt.
  • Update to check script checktsmlevel.sh to redirect any errors of the rpm command to /dev/null.
  • New check script checktsmtdpoconf.sh to run tdpoconf showenv, to show the TSM / IBM Spectrum Protect TDP for Oracle configuration, if installed.
  • New check script checktsmtdpoerrorlog.sh to check the size of tdpoerror.log, if Tivoli Data Protection for Oracle is used.
  • New check script checkvnbbackup.sh to check the backup by Veritas NetBackup.
  • New check script checkvnbexclude.sh to check the exclude list for Veritas NetBackup.
  • New check script checkvnblogging.sh to check if client logging is enabled for Veritas NetBackup.
  • New check script checkvnbserver.sh to check the server name in use for Veritas NetBackup.
  • New check script checkvnbversion.sh to check the version of Veritas NetBackup, if installed.
  • New check script checkenvironment.sh to check the contents of /etc/environment.
Version: v18.11.23
  • Update to check script checkyumcron.sh to indicate how to enable the optional repository for Oracle Linux 7.
  • Update to check script checksharutils.sh to indicate how to enable the optional repository for Oracle Linux 7.
  • Update to check script checkcleansystems.sh to exclude file /etc/nsswitch.conf.bak from being reported by the script.
  • Update to check script checkhostnamevsdns.sh to check if a fully qualified domain name can be determined through DNS.
  • Update to check script checkrunlevel.sh to avoid running on Scientific Linux as it does not display any runlevel.
Version: v18.11.22
  • Update to check script checkspectremeltdown.sh to update the script to version 3.1 of the the Spectre Meltdown diagnosis script.
  • Update to check script checkrunlevel.sh to correct a typo.
  • Update to check script checkcleansystem.sh to avoid reporting duplicate items.
  • Update to check script checkall.sh to improve the HTML output of the report - better consistency of the fonts used; better readability on mobile devices, and better scaling within Microsoft Outlook.
Version: v18.11.21
  • Update to check script checkenv.sh to exclude the output of the LS_COLORS variable, to avoid messing up the HTML output because of this lenghty variable.
Version: v18.11.20
  • Update to check script checkleapvulnerability.sh to avoid writing a file when testing for the correct year.
Version: v18.11.20
  • Update to check script checkhistcontrol.sh to include a check to determine if the script is run within a terminal session or not.
  • Update to check script checkhistsize.sh to include a check to determine if the script is run within a terminal session or not.
  • Update to check script checkhisttimeformat.sh to include a check to determine if the script is run within a terminal session or not.
  • Update to check script checkcoredumps.sh to redirect errors of the df command to /dev/null.
  • Update to check script checkall.sh to redirect errors of the df command to /dev/null.
  • Update to check script checkdf.sh to redirect errors of the df command to /dev/null.
  • Update to check script checkdfsummary.sh to redirect errors of the df command to /dev/null.
  • Update to check script checkfilesystemnumber.sh to redirect errors of the df command to /dev/null.
  • Update to check script checkfreespaceinfs.sh to redirect errors of the df command to /dev/null.
  • Update to check script checkfsdeviceandmountpoint.sh to redirect errors of the df command to /dev/null.
  • Update to check script checkhomesize.sh to redirect errors of the df command to /dev/null.
  • Update to check script checkinodeusage.sh to redirect errors of the df command to /dev/null.
  • Update to check script checkroothomedir.sh to redirect errors of the df command to /dev/null.
  • Update to check script checktmpmounts.sh to redirect errors of the df command to /dev/null.
  • Update to check script checkrootsize.sh to redirect errors of the df command to /dev/null.
  • Update to check script checktmpsize.sh to redirect errors of the df command to /dev/null.
  • Update to check script checktmpusage.sh to redirect errors of the df command to /dev/null.
  • Update to check script checkvarsize.sh to redirect errors of the df command to /dev/null.
  • Update to check script checketcfstabfilesystems.sh to redirect errors of the df command to /dev/null.
  • New check script checkdftransportendpoint to check for a transport endpoint message in the output of df.
Version: v18.11.19
  • Update to check script checkall.sh to ensure the IP address of the system is correctly discovered on Oracle Linux 7.6.
  • Update to check script checkinterface.sh to ensure the IP address of the system is correctly discovered on Oracle Linux 7.6.
  • Update to check script checkoslevel.sh to recommend version 6.10 for RHEL 6.
  • Update to check script checksestatus.sh to avoid printing an empty line when the sestatus command fails.
  • Update to checkoslevel.sh to recommend Red Hat Enterprise Linux 7.6 and Oracle Linux 7.6.
  • New check script checkmemoryminsize.sh to check the minimum amount of memory required for the operating system.
Version: v18.11.17
  • Update to the description of check script checkrpmv.sh to provide additional information on how to determine which package to reinstall, if a certain file has been identified with an issue.
  • Update to check script checkswapusagevsmemory.sh to check if the bc command is available before continuing.
  • New check script checklvm2.sh to check if RPM package lvm2 has been installed on the system.
  • Update to check script checkall.sh to define additional path variables in case the checkall.sh script is run from cron - in which case a different PATH variable may be defined.
  • Update to check script checkhostname.sh to correct a check that matches the contents of /etc/sysconfig/network with the hostname setting.
  • Update to check script checkssb.sh to update the script to version 1.3 of the diagnose script for the Speculative Store Bypass vulnerability.
Version: v18.11.16
  • Update to check script checkall.sh to include the kernel version in the system configuration section.
  • Update to check script checklsscsi.sh to allow it to work on RHEL 6.9.
  • Update to check script checkumask.sh to allow it to work on RHEL 6.9.
  • Update to check script checksystemjournalpermanent.sh to avoid running the script on RHEL 6 and earlier verions.
  • Update to check script checkntpd.sh to provide the correct command to enable ntpd depending on the RHEL version used.
  • Update to check script checkntpdatentppool.sh to account for the sed command to be in a different folder on RHEL 6.
  • Update to check script checkhostname.sh to redirect any errors from the hostname --fqd command to /dev/null, so it won't generate an error when running on RHEL version 6 and earlier.
  • Update to the description of check script checksshsyslogfacility.sh to indicate the commands used to restart sshd and rsyslog on RHEL 7.
  • Update to check script checketchosts.sh to allow a greater number of locally defined entries in /etc/hosts.
  • Update to the description of check script checksystemctldegrades.sh on how to handle failed services that can no longer be found on the system.
  • Update to check script checksubscriptionmanager.sh to check for a true Red Hat system first, before continuing.
  • Update to check script checksubscriptionmanageridentity.sh to check for a true Red Hat system first, before continuing.
Version: v18.11.15
  • Update to check script checksnmputils.sh to remove the -y option for the yum command as suggested command to run.
  • Update to check script checklogrotatedfiles.sh to avoid alerting on log files which are actually directories.
  • Update to check script checkchronyvsntp.sh to recommend starting and enabling chronyd.
  • Update to check script checkntpd.sh to ignore all errors and warnings if chronyd is installed and active.
  • Update to check script checkntpstat.sh to ignore all errors and warnings if chronyd is installed and active.
  • Update to check script checkhostnamevsdns.sh to correct a variable which will result in the script properly identify a difference between the local FQDN versus the name registered in DNS.
Version: v18.11.01
  • New check script checkbondlink.sh to check if all links are up on the configured bonded network interfaces.
  • New check script checkbond.sh to list the bonded network interfaces on this system.
Version: v18.10.29
  • New check script checkthreadsperuser.sh to alert if a user is using a high number of processes and/or threads on the system, and is close to the soft nproc limit.
  • Update to the description of check script checkthreads.sh to indicate how to see the number of threads on the system, and how to increase the soft limit for the number of processes on the system.
Version: v18.10.24
  • Update of the demo version to include the first 100 check scripts of the full version.
Version: v18.10.21
  • Update to the description of check script checkwirelesstools.sh to indicate that the EPEL repository needs to be enabled first before it is possible to install the RPM package wireless-tools on a Red Hat Enterprise Linux system.
Version: v18.10.19
  • Update to check script checkchronydsystemclockoffset.sh to avoid alerting on negative clock offsets.
  • Update to check script checkall.sh to improve determining the fully qualified domain name of the system.
  • Update to check script checksendmailsmtpconnection.sh to prefer the domain entry over the search entry in /etc/resolv.conf for determining the fully qualified domain name.
  • Update to check script checkpostfixsmtpconnection.sh to prefer the domain entry over the search entry in /etc/resolv.conf for determining the fully qualified domain name.
  • Update to check script checkhostnamevsdns.sh to prefer the domain entry over the search entry in /etc/resolv.conf for determining the fully qualified domain name.
  • Update to check script checkresolvconf.sh to prefer the domain entry over the search entry in /etc/resolv.conf for determining the fully qualified domain name.
  • Update to check script checkhostname.sh to prefer the domain entry over the search entry in /etc/resolv.conf for determining the fully qualified domain name.
  • New check script checkswapusagevsmemory.sh to check the swap space usage versus the memory assigned to the system.
  • Update to the description of check script checkyumcron.sh to indicate that the optional RPMs repository may need to be enabled on RHEL systems, before the yum-cron package can be installed.
  • Update to the description of check script checksharutils.sh to indicate that the optional RPMs repository may need to be enabled on RHEL systems, before the sharutils package can be installed.
  • Update to check script checklsusb.sh to avoid alerting if the USB module is not loaded.
Version: v18.10.18
  • New check script checkmemoryutilization.sh to display the current memory utilization of the system, and to warn or alert if the memory is too high or is critical.
  • New check script checktop20memoryprocs.sh to list the top 20 memory using processes.
  • New check script checkwirelesstools.sh to verify if the wireless-tools RPM pacakage is installed, if the system is equipped with wireless devices.
  • New check script checkiwconfig.sh to display the output of the iwconfig command, if wireless devices are installed on the system.
  • New check script checkcleansystem.sh to check if there are any files on the system that can be removed.
  • New check script checkyumcron.sh to check if the yum-cron RPM package is installed and the yum-cron service is enabled.
  • New check script checktmpmount.sh to check if /tmp is in either an actual file system of tmpfs file system.
Version: v18.10.14
  • New check script checklshw.sh to check if the lshw RPM package is installed on the system, and if so, to display the output of lshw -short.
  • New check script checklsscsi.sh to check if the lsscsi RPM package is installed on the system, and if so, to display the output of lsscsi --long --size.
  • New check script checklsusb.sh to check if the usbutils RPM package is installed on the system, and if so, to display the output of lsusb.
Version: v18.10.10
  • Update to check script checksestatu.sh to allow both the enforcing and permissive status of SELinux.
  • New check script checkchronydsystemclockoffset.sh to check the system clock offset reported by the Chrony time service.
  • Renamed check script checktelnet.sh to checktelnetserver, as the script is responsible for checking the telnet server.
  • New check script checktelnet.sh to determine if the telnet tool is installed on the system.
  • New check script checktraceroute.sh to determine if the traceroute RPM package is installed on the system.
  • Update to check script checkpostfixsmtp.sh to allow it work if an IP address was entered in the Postfix main.cf file instead of a hostname.
  • Update to checks cript checksystemjournalpermanent.sh to recommend the correct system group setting for the /var/log/journal directory.
Version: v18.10.04
  • Update to check script checkifconfig.sh to retrieve network information using the ip command instead of ifconfig, if ifconfig is not installed.
  • Update to check script checkoslevel.sh to test if a newer OS level is installed before reporting an issue.
  • Update to check script checkpostfixsmtp.sh to test if the nslookup command is available before checking the DNS entry.
  • Completed testing of UNIX Health Check for Red Hat Enterprise Linux on Red Hat 7.6 beta 1.
  • Update to check script checksendmailsmtp.sh to avoid checking for a DNS entry for the SMTP server, if brackets are used in the DS entry in /etc/sendmail.cf, as using brackets in the DS entry results in sendmail not doing any DNS verification of the SMTP server.
Version: v18.10.03
  • Update to check script checkl1tf.sh to update the script to version 1.3, as released by Red Hat. This check script checks for the L1 Terminal Fault vulnerability.
Version: v18.09.18
  • Update to the description of check script checkopenvmtools.sh to include information available from Red Hat on the open-vm-tools package for VMWare systems.
Version: v18.09.04
  • New check script checkl1tf.sh to check for the L1 Terminal Fault vulnerability.
Version: v18.08.22
  • Update to check script checkall.sh to include the -t check script time-out option.
  • New check script checkdellidracservicemodule.sh to check if the Dell iDRAC Service Module has been installed, enabled and started on Dell PowerEdge systems.
  • New check script checkdelldsufirmware.sh to check if DSU indicates that there are firmware updates available for Dell PowerEdge systems.
  • New check script checkdelldsu.sh to check if DSU (Dell System Update) has been installed on Dell PowerEdge systems.
  • New check script checkomreportchassis.sh to check the chassis component status of Dell PowerEdge systems through OpenManage System Administrator, if installed.
  • New check script checkrpmv.sh to check RPM package consistency.
  • Update to check script checkall.sh to avoid reporting an error on incomplete RPM pacakges installed, if some of the files are expected to be modified.
  • Update to check script checkdellomsa.sh to indicate the commands needed to install Dell OpenManage System Administrator, if not installed on Dell PowerEdge systems.
Version: v18.08.16
  • Update to check script checkall.sh to include the type of virtualization in the configuration section.
  • Update to check script checkvm.sh to include the type of virtualization in the output.
Version: v18.08.14
  • Update to check script checkbindutils.sh to include the command to install the bind-utils RPM package.
Version: v18.08.08
  • Update to check script checkomreportvdisk.sh to include the full name of the omreport command, in case it can't be found within the PATH variable.
  • Update to check script checkomreportpdisk.sh to include the full name of the omreport command, in case it can't be found within the PATH variable.
  • Update to check script checkdellomsa.sh to include a better description of the Dell OpenManage System Administrator in the output.
  • Update to check script checkomreportpdisk.sh to include a listing of the virtual disks known for each controller.
Version: v18.07.30
  • Update to check script checksestatus.sh to correctly indicate if SELinux is in either disabled, permissive or enforcing mode and how to resolve any issues found.
  • New check script checkusrsbinsestatusperms.sh to check the owner, group, permissions and file size of /usr/sbin/sestatus.
  • New check script checketcselinuxconfigperms.sh to check the owner, group and permissions of file /etc/selinux/config.
  • New check script checketcselinuxconfig.sh to display the contents of file /etc/selinux/config, the configuration file for SELinux (Security Enhanced Linux).
Version: v18.07.24
  • Update to check script checkpostfix.sh to provide the command needed to enable Postfix at system boot time.
  • New check script checkrootforward.sh to check if email of user root is forwarded.
Version: v18.07.13
  • Update to check script checkall.sh to allow check scripts to run for 180 seconds instead of 120 seconds.
  • New check script checkabrtdactive.sh to check if the abrtd daemon is running and enabled at boot time if abrt is installed.
  • New check script checkabrtinstalled.sh to check if the abrt RPM package for the Automatic Bug Reporting Tool is installed on the system.
  • Update to check script checksambaactive.sh to check if both the smb and nmb daemons are enabled at system boot time.
  • Update to check script checkklogdactive.sh to check if klogd is enabled at system boot time on RHEL versions 4 and 5.
  • New check script checkabrtconfperms.sh to check the permissions of /etc/abrt/abrt.conf.
Version: v18.07.06
  • New check script checksssdconf.sh to display the contents of file /etc/sssd/sssd.conf.
  • New check script checksssdconfperms.sh to check the permissions, owner and group of /etc/sssd/sssd.conf.
Version: v18.07.03
  • Update to check script checkifconfig.sh to avoid reporting warning messages no the use of the grep command in some configurations.
  • Update to check script checkifconfig.sh to account for possible double quotation marks in /etc/sysconfig/ifcfg-interface files.
Version: v18.06.11
  • New check script checkrhsmconfperms.sh to check the owner, group and permissions of /etc/rhsm/rhsm.conf.
Version: v18.05.30
  • Update to check script checkpacemakerclusterstatus.sh to also display the Pacemaker cluster configuration.
Version: v18.05.29
  • New check script checksnmpd.sh to check if snmpd is running, and enabled at boot.
Version: v18.05.28
  • New check script checksnmpdconfperms.sh to check if the permissions, owner and group of /etc/snmp/snmpd.conf are correctly set and alert if the file is missing or empty.
  • New check script checksnmputils.sh to check if RPM package net-snmp-utils is installed if net-snmp is installed.
  • New check script checksnmp.sh to display a warning if it is possible to retrieve system information through SNMP.
  • New check script checksensorsalarm.sh to display the output of the sensors command, and alert if any temperature is too high.
  • New check script checksensors.sh to check if the lm_sensors RPM is installed.
Version: v18.05.27
  • New check script checksambatestparm.sh to run Samba's testparm utility to check the correctness of the the Samba configuration file.
Version: v18.05.22
  • New check script checkrpm.sh to check if the rpm utility is installed.
  • New check script checkssb.sh to check for the Speculative Store Bypass vulnerability.
Version: v18.05.21
  • Update to check script checkoslevel.sh to check for the 7.5 releases of CentOS, Scientific Linux and Oracle Linux.
  • Update to check script checksystemjournalpermanent.sh to include the chown command recommendation when /var/log/journal folder does not exist.
  • Update to check script checksupportpassword.sh to check if a password has been set before proceeding with the rest of the checks.
  • Update to check script checkshutdownpassword.sh to check if a password has been set before proceeding with the rest of the checks.
  • Update to check script checkrootpassword.sh to check if a password has been set before proceeding with the rest of the checks.
  • Update to check script checkadminpassword.sh to check if a password has been set before proceeding with the rest of the checks.
  • Update to check script checkhaltpassword.sh to check if a password has been set before proceeding with the rest of the checks.
  • Update to check script checkmanagerpassword.sh to check if a password has been set before proceeding with the rest of the checks.
  • Update to check script checkoraclepassword.sh to check if a password has been set before proceeding with the rest of the checks.
  • Update to the description of check script checkntpsynchhwclock.sh to remove a typo.
  • Update to check script checkhostname.sh to also allow a dash in the hostname.
  • Update to check script checkfswrite.sh to exclued GVFS type file systems from checking.
  • Update to check script checkspectremeltdown.sh to update the script to version 2.5 of Red Hat's detection script.
Version: v18.05.20
  • New check script checkavahiactive.sh to check if the Avahi daemon has been disabled.
  • New check script checknozeroconf.sh to check if NOZEROCONF=yes is present in /etc/sysconfig/network.
Version: v18.05.06
  • New check script checksambasmbconf.sh to display the contents of the smb.conf configuration file of Samba.
  • New check script checksambaactive.sh to check if the Samba smb and nmb daemons are running if Samba is installed.
  • New check script checksambastatus.sh to show the status of Samba.
  • New check script checksambasmbconfperms.sh to check the permissions of /etc/samba/smb.conf.
Version: v18.05.04
  • New check script checkbrctlshow.sh to display the virtual Ethernet bridge configuration.
  • Update to check script checketcdefaultuseraddperms.sh to allow a different set of permissions on file /etc/default/useradd in later releases of RHEL/CentOS.
Version: v18.04.26
  • Update to check script checkfswrite.sh to avoid reporting an issue on type fuse file systems.
  • Update to check script checkomreportstoragebattery.sh to exclude any non-critical alerts.
Version: v18.04.25
  • New check script checkfindmnt.sh to display the output of the findmnt command to show all mounted file systems.
  • Update to the description of check script checkshowmount.sh to add information on the use of the showmount and netstat commands.
Version: v18.04.12
  • Update to check script checkcoredumps.sh to improve the damocles function.
  • Update to check script checkmailq.sh to improve the damocles function.
  • Update to check script checkmissingowners.sh to improve the damocles function.
  • Update to check script checksuid.sh to improve the damocles function.
  • Update to check script checkyumcheckupdate.sh to improve the damocles function.
  • Update to the description of check script checkwheel.sh to remove a typo.
  • Update to check script checkwheel.sh to avoid reporting on the new cloud-user account introduced in RHEL 7.5.
  • Update to check script checkifconfig.sh to avoid reporting an error if the IP address is configured through DHCP.
  • Update to check script checksudoersincludedir.sh to improve checking of the permissions of files in /etc/sudoers.d.
Version: v18.04.11
  • Update to the description of check script checktopcpuusers.sh to include information on how to list the top 20 most CPU using processes.
  • New check script checkbeta.sh to check if a beta release has been installed.
  • Update to check script checkall.sh to redirect the output of the rpm -V command to avoid printing errors.
  • Update to check script checkadmgroup.sh to avoid reporting an error on the cloud-user account known in RHEL 7.5.
  • Update to checkoslevel.sh to recommend level 7.5 of Red Hat Enterprise Linux.
Version: v18.04.10
  • Update to check script checkdnslookup to improve discovery of DNS IP addresses.
  • Update to check script checkchronyc.sh to remove a typo.
  • Update to check script checkresolvconf.sh to include testing the time it takes to perform a nslookup command.
Version: v18.04.09
  • New check script checkcrontabs.sh to check crontabs without existing owners.
  • New check script checkcrontabdups.sh to check if duplicate entries in crontab files exist.
  • New check script checkcrontabcommands.sh to check if the commands that are referenced in crontab files exist.
  • New check script checkcrontabcommandsexec.sh to check if the commands in crontab files are executable.
  • New check script checkcronsystemcronfiles.sh to check if all the files in system cron folders are executable.
  • New check script checkcronsystemfolderperms.sh to check the permissions, owner and group of the system crontab folders.
Version: v18.04.08
  • New check script checkdevperms.sh to check the permissions, owner and group of /dev.
  • New check script checkatd.hs to check if the at daemon is installed and running.
  • New check script checkatallowperms.sh to check the permissions of /etc/at.allow.
  • New check script checkatdenyperms.sh to check the permissions of /etc/at.deny.
  • New check script checkcronallowperms.sh to check the permissions of /etc/cron.allow.
  • New check script checkcrondenyperms.sh to check the permissions of /etc/cron.deny.
  • New check script checkcrond.sh to check if the cron daemon is installed and running.
  • New check script checkcronallowdeny.sh to display the contents of the cron.allow, cron.deny, at.allow and at.deny files.
  • New check script checkcronallow.sh to check the users in /etc/cron.allow.
  • New check script checkcrondeny.sh to check the users in /etc/cron.deny.
  • New check script checkcrontab.sh to display the contents of all the crontab files.
  • New check script checkcrontabsunused.sh to check crontabs that are not used.
Version: v18.04.07
  • New check script checkatl.sh to check if there's a queue of at jobs.
  • New check script checkatallow.sh to check the users in /etc/at.allow.
  • New check script checkatdeny.sh to check the users in /etc/at.deny.
Version: v18.04.06
  • Update to check script checkcoredumps.sh to improve checking for the kernel.core_uses_pid sysctl option.
  • Update to check script checkall.sh to indicate in the System Configuration section if the server is a virtual machine or not.
  • New check script checkvm.sh to check if the server is running as a virtual machine or not.
  • New check script checkvmlinuxfirmware.sh to check if the linux-firmware package is installed on physical systems only.
Version: v18.04.04
  • Update to check script checksudoerrors.sh to ensure it properly removes it's own temporary file from /tmp.
  • Update to check script checkblkid.sh to sort the output.
  • New check script checkrootlinks.sh to check if the links in / exist with the proper owner, group, permissions and targets.
  • New check script checkfstabdevicenames.sh to check if no physical or virtual device names are used in /etc/fstab.
  • New check script checkmlocate.sh to check if the mlocate package has been installed.
  • New check script checkmlocatecron.sh to check if the mlocate cron entry is present.
  • Update to check script checkall.sh to allow for virtualization category check scripts to be run separately.
  • New check script checkvirshlist.sh to display all configured virtual machines.
  • New check script checkvirshnodeinfo.sh to display the node info of the virtualization host, if configured.
Version: v18.04.03
  • Update to check script checknetstat.sh to provide a more descriptive output, and to add the output of the ss command to show TCP sockets.
  • New check script checknmcliconshow.sh to display the active network connections using nmcli.
  • New check script checknmclidevshow.sh to display the network devices using nmcli.
  • Update to the description of check script checksudosh.sh to improve the description.
  • Update to check script checkifconfig.sh to avoid reporting possible errors on bonded network interfaces.
  • New check script checkchronyvsntp.sh to check if either Chrony or NTP is being used for the time service.
Version: v18.04.02
  • New check script checksshpermitrootlogin.sh to check the PermitRootLogin entry in sshd_config.
  • New check script checksshdirfiles.sh to check the file permissions and ownership of files in ~root/.ssh.
  • New check script checksshconfig.sh to display the contents of file /etc/ssh/ssh_config.
  • New check script checksshx11forward.sh to check if X11Forwarding is set to yes in sshd_config.
  • New check script checksshprotocol.sh to check if Protocol is set to 2 in sshd_config.
  • New check script checksshlogingracetime.sh to check if LoginGraceTime is set to 2m (120 seconds) in sshd_config.
  • New check script checksshd.sh to check if user sshd exists.
  • New check script checksshallowusers.sh to check the AllowUsers entry in sshd_config.
  • New check script checkvarlogperms.sh to check if the permissions of the /var/log folder are correctly set.
  • Update to check script checketclogrotatedperms.sh to check as well that folder /etc/logrotate.d exists.
  • New check script checketclogrotatedsyslog.sh to check the existence and permissions of /etc/logrotate.d/syslog.
  • New check script checksystemjournalpermanent.sh to check if the system journal has been set up to be permanent.
  • New check script checktimedatectlntpenabled.sh to check if the timedatectl command reports that ntp is enabled.
  • Update to check script checkntpd.sh to avoid reporting an error if ntp is not installed.
  • Update to check script checkntp.sh to only report an issue when NTP is not installed on RHEL 6 or lower.
  • New check script checkchrony.sh to check if the chrony RPM package is installed.
  • New check script checketcchronyconfperms.sh to check the permissions of /etc/chrony.conf.
  • New check script checkchronyconf.sh to display the contents of /etc/chrony.conf.
  • New check script checkchronyd.sh to check the chronyd time service.
  • New check script checkchronyc.sh to display the output of the chronyc command.
  • Update to check script checktimezone.sh to improve the output of the check script.
Version: v18.03.31
  • New check script checksuid.sh to check for files that have the SUID or GUID bit set, allowing others to run files as a specific user and/or group.
  • New check script checkrootroot.sh to check if the primary group of user root is root.
  • Update to check script checkhomedirs.sh to improve checking the ownership of someone's home directory.
Version: v18.03.30
  • New check script checkrootpwreset.sh to check if the root password has been changed within the last 90 days.
  • New check script checkexpireduseraccounts.sh to list any user accounts that have expired.
  • New check script checkroothomedir.sh to check if the root home directory is /root.
  • New check script checkhomedirswritable.sh to check if all home directories are writeable for their owners, and not for group members or others.
  • New check script checkhomedirssize.sh to check for home directories that contain more than 1 GB of data.
  • New check script checkhomedirs.sh to check for any user home directories without a correct owner.
Version: v18.03.12
  • New check script checkiscsiadmmodesession.sh to display the iscsi session records.
  • New check script checkfsmounted.sh to check if any file systems aren't mounted.
Version: v18.03.11
  • New check script checketcsysconfigperms.sh to check the permissions of folder /etc/sysconfig.
Version: v18.03.10
  • New check script checkcleanetcsysconfig.sh to check for any files in /etc/sysconfig that can be cleaned up.
Version: v18.03.08
  • Update to check script checkmultipathconfperms.sh to allow multiple different permissions to be set for /etc/multipath.conf.
Version: v18.03.06
  • Update to check script checknmapportscan.sh to add a --host-timeout option to the nmap command to avoid running for a long time.
  • Update to check script checkifconfig.sh to display additional details about the IP configuration of the host.
  • Update to check script checkall.sh to add a warning to the logfile output if a check script takes longer than 120 seconds to complete.
  • Update to check script checksystemctldegraded.sh to display any failed services if systemctl is in a degraded status.
  • Update to check script checkntpdate.sh to avoid reporting an error if a network connectivity issue is preventing the ntpdate command to complete successfully.
  • Update to check script checkntpd.sh to avoid reporting an error if a network connectivity issue is preventing the ntpstat command to complete successfully.
Version: v18.03.05
  • Update to check script checkyumcheckupdate.sh to avoid a hang situation when multiple default gateways are configured on different network interfaces.
  • Update to check script checkdefaultgateway.sh to report duplicate default gateways on different network interfaces properly.
Version: v18.03.02
  • Update to check script checkall.sh to list the location and deployment type of the server in the system configuration section, if set.
  • Update to check script checkyumcleanyumreposd.sh to avoid reporting on the total line in the ls command.
  • Update to check script checksysfsutils.sh to add information on how to install the sysfsutils package.
  • Update to check script checkhistappend.sh to correct a typo in the suggested entries to add to /etc/bashrc.
  • Update to check script checkdellomsaactive.sh to add an additional method to check the port that Dell OMSA is listening on.
  • Update to check script checketchosts.sh to check for uppercase listed hostnames in /etc/hosts as well.
  • Update to check script checkhostname.sh to work correctly if uppercase hostnames are used in /etc/hosts.
Version: v18.03.01
  • Update to new computing environment.
Version: v18.02.26
  • Update to the description of check script checkfchostwwpn.sh to correct a typo.
Version: v18.02.22
  • New check script checkethtool.sh to display the output of the ethtool command for all available network interfaces.
  • New check script checketcresolvconf.sh to display the contents of /etc/resolv.conf.
  • Update to check script checknetstat.sh to include the output of ip route and ip neigh.
  • Update to check script checkipaddress.sh to properly list the IP addresses configured on the system.
  • New check script checkiplink.sh to display the link status of the interfaces.
  • Update to check script checklspci.sh to include the -nn option with the lspci code, to also include the vendor and device codes in the output.
Version: v18.02.13
  • Update of check script checkspectremeltdown.sh to update it to version 2.1 of the Spectre and Meltdown detection script provided by Red Hat.
Version: v18.02.08
  • Update of check script checkoslevel.sh to check for the correct level of Oracle Linux Server to be installed as well.
Version: v18.01.26
  • Calculate MD5 has of UNIX Health Check for Red Hat Enterprise Linux pacakage automatically.
Version: v18.01.15
  • New check script checkspectremeltdown.sh to check if the system is vulnerable for the Spectre and Meltdown threats.
Version: v18.01.01
  • New check script checkusersloggedon.sh to display the users that are currently logged on.
Version: v17.12.31
  • New check script checkdellomsaactive.sh to check if Dell OpenManage Server Administrator is active, if it is installed.
  • New check script checketcrclocallink.sh to check if /etc/rc.local is a symbolic link to /etc/rc.d/rc.local.
  • New check script checketcrclocal.sh to display the contents of /etc/rc.local.
Version: v17.12.24
  • Update to the description of check script checkhistfile.sh to explain in detail why HISTFILE should be set explicitly.
  • Update to check script checkdmidecode.sh to change it to a non-inventory check script.
  • Update to check script checkzip.sh to check for an additional location of the zip command on older versions of RHEL.
  • Update to check script checkvmwaretools.sh to check through an additional method to determine the vendor of the system if demidecode is not available.
  • Update to check script checkresolvconf.sh to correctly report an error when no name server has been defined on the system.
Version: v17.12.23
  • New check script checkdeployment.sh to check the deployment status of the system, and to warn if it is not set.
  • New check script checklocation.sh to check the location of the system, and to warn if it is not set.
Version: v17.12.21
  • New check script checkmailxinstalled.sh to check if the mailx RPM package is installed.
  • New check script checkperlinstalled.sh to check if perl is installed.
  • Update to the description of check script checksharutils.sh to indicate how to install the sharutils RPM pacakage, if it is not installed.
  • Update to check script checkifconfig.sh to allow it to work even if /bin/netstat (part of RPM package net-tools) is not installed.
  • New check script checknfsaccess.sh to check if any NFS mounted file systems can be accessed.
Version: v17.12.20
  • Update to check script checkfswrite.sh to avoid testing writing to file system /sys/firmware/efi/efivars.
  • Update to check script checkusersloggedonlongtime.sh to exit if perl is not available.
  • Update to check script checkuserpassword.sh to exit if perl is not available.
  • Update to check script checksudoerspassword.sh to exit if perl is not available.
  • Update to check script checkshutdownpassword.sh to exit if perl is not available.
  • Update to check script checkrootpassword.sh to exit if perl is not available.
  • Update to check script checkhaltpassword.sh to exit if perl is not available.
Version: v17.12.19
  • Update to the description of check script checksestatus.sh to describe how to disable Selinux, if necessary.
Version: v17.12.15
  • New check script checkpacemakerclusterstatus.sh to check if the status of a Pacemaker cluster, if installed.
Version: v17.12.11
  • Update to the description of check script checklastlogsize.sh to explain how to empty file /var/log/lastlog, if the file is larger than 50 MB.
Version: v17.12.08
  • Update to check script checkfsreadonly.sh to correct an error that may not identify any read-only file systems.
Version: v17.12.07
  • New check script checkvmwaretools.sh to check if VMware Tools is installed on a VMware based system.
  • Update to the description of checkdefaultgateway.sh explaining how to resolve an issue with having multiple default gateways defined on a system.
Version: v17.11.08
  • Update to check script checkifconfig.sh to allow it work correctly even if the same default gateway has been configured more than once.
Version: v17.10.03
  • New check script checksudoshversion.sh to check if sudosh is installed, and if so, what version.
  • New check script checksudosh.sh to check settings for sudosh, if installed.
  • Update to check script checkoslevel.sh to check for the latest level of Scientific Linux, version 7.4.
Version: v17.09.26
  • New check script checkpacketloss.sh to check if packet loss can be detected when pinging the default gateway.
  • Update to check script checknmapportscan.sh to avoid reporting RTTVAR messages if the host has a high load.
Version: v17.09.20
  • Update to check script checkoslevel.sh to check for CentOS 7.4.
  • Update to check script checkntpstat.sh to avoid reporting errors and to indicate if ntpd is inactive.
Version: v17.09.19
  • Update to the UNIX Health Check for Red Hat Enterprise Linux package to align with the update of the website to https instead of http.
Version: v17.08.23
  • Update to check script checktsmlevel.sh to add an extra method to check the TSM / IBM Spectrum Protect server level.
  • Update to check script checkxivhaklevel.sh to recommend version 2.8.0 of the IBM Storage Host Attachment Kit to be installed.
  • Update to check script checkgangliagmetadlevel.sh to recommend the latest version of Ganglia gmetad to be installed, version 3.7.2.
  • Update to check script checkgangliagmondlevel.sh to recommend the latest version of Ganglia gmond to be installed, version 3.7.2.
Version: v17.08.21
  • Update to check script checktsmbackup.sh to add the full path to the dsm.sys file in the output presented by the script.
Version: v17.08.20
  • Update to check script checkmultipathd.sh to check the status of multipathd through systemctl instead of service, when running on RHEL 7 and up.
Version: v17.08.16
  • Update to check script checkleapvulnerability.sh to update to version 1.0.5 of Red Hat's leap_second_issue_detector.sh script.
Version: v17.08.15
  • New check script checkbindutils.sh to check if the bind-utils package is installed.
  • Update to check script checkoslevel.sh to recommend Red Hat Enterprise Linux 7.4.
  • Update to check script checkhostnamevsdns.sh to use ip route get 1 to provide a more accurate way of determining the main IP address configured on the system.
  • Update to check script checkinterface.sh to use ip route get 1 to provide a more accurate way of determining the main IP address configured on the system.
  • Update to check script checkall.sh to use ip route get 1 to provide a more accurate way of determining the main IP address configured on the system.
  • Update to check script checkipaddress.sh to use ip route get 1 to and hostname -I to provide a more accurate list of IP addresses on the system.
  • Update to check script checkhostnamevsdns.sh to avoid checking when the system has multiple IP addresses configured.
  • Update to check script checksysctla.sh to check if /usr/sbin/sysctl is installed before displaying any output, and also re-directing any errors to stdout.
  • Update to check script checktelnet.sh to redirect any errors of the netstat command to /dev/null.
  • Update to check script checkopennfsexports.sh replacing the host with the ip route get 1 command to ensure a more reliable way of determining the main IP address.
  • Update to check script checknetstat.sh to check if the netstat command is available on the system before displaying any output. Similar updates have been made to the script for the ip and ifconfig commands.
  • Update to check script checkmailroot.sh to check if /bin/mail is available on the system, before checking for any email for the root user account.
  • Update to check script checkifconfig.sh to redirect errors in case netstat is not installed on the system.
  • New check script checkmachineid.sh to display the machine ID of the system.
  • New check script checkntpdatentppool.sh to check the time offset of the server versus a stratum 2 internet time server.
  • Update to check script checkntpdate.sh to only query the NTP offset status, and not attempt to change it.
Version: v17.07.19
  • New check script checkrpmduplicates.sh to check for any RPM packages that were installed multiple times.
Version: v17.06.08
  • Update to check script checkall.sh to avoid displaying a line in the header field of each check script, when using HTML output in Microsoft Outlook 2016.
  • Update to the package for the new release of website unixhealthcheck.com.
Version: v17.06.06
  • Update to check script checkhostname.sh to also check files /etc/sysconfig/network and /etc/hostname for the correct hostname setting.
  • New check script checketcosreleaseexists.sh to check if file /etc/os-release exists.
  • New check script checketcosrelease.sh to display the output of /etc/os-release if the file exists.
  • Update to check script checkhostnamelocalhost.sh to look at the short name instead of the fully qualified domain name.
  • New check script checksudoprivilegeescalation.sh to check if the system has a sudo version installated that is vulnerable for CVE-2017-1000367.
Version: v17.06.03
  • Update to check script checkzip.sh to add the command required to install the zip RPM package.
  • Update to check script checkusrlibperms.sh to allow two different sets of permissions on folder /usr/lib.
  • Update to check script checkall.sh to mention the hostname at the start of the log file output.
  • Update to check script checketcredhatrelease.sh to allow it to display the correct Operating System version when running on Oracle Linux.
  • Update to check script checkall.sh to allow the configuration section to display the correct Operating System version when running on Oracle Linux.
Version: v17.06.02
  • Update to check script checksubscriptionmanagerlist.sh to only alert of Red Hat Enterprise Linux systems, and not alert on CentOS, Scientific Linux and Oracle Linux.
  • Update to check script checkrhsmcertd.sh to only alert of Red Hat Enterprise Linux systems, and not alert on CentOS, Scientific Linux and Oracle Linux.
  • Update to check script checkresolvconf.sh to improve upon the way the output is presented.
  • Update to check script checkmultipleipinetchosts.sh to exit out of the script if the hostname has not been set.
  • Update to check script checkinterface.sh to resolve an issue with determining the correct IP address if the hostname has not been set.
  • Update to check script checkall.sh to resolve an issue with determining the correct IP address if the hostname has not been set.
  • Update to check script checkall.sh to verify up front if RPM packages net-tools (for netstat), mailx (for mail) and bind-utils (for host) is installed.
  • Update to check script checkzip.sh to allow it to work properly on Oracle Linux.
Version: v17.06.01
  • Update to check script checkall.sh to remove duplicate spaces in comma separated output.
  • Update to check script checkblankpassword.sh to remove a typo in the output generated.
  • Update to check script checkall.sh to ensure replacing special characters in XML formatted output works.
  • Update to check script checkpvs.sh to add a summary line of the total storage attached to the Linux system.
  • Update to check script checkpostfixsmtpconnection.sh to also check for a connected message to determine if the remote SMTP server is avaialable.
  • Update to check script checksendmailsmtpconnection.sh to also check for a connected message to determine if the remote SMTP server is avaialable.
Version: v17.05.31
  • Update to check script checkcoredumps.sh to find core dump files that include a PID in the filename, if the system is configured to dump cores with PIDs.
Version: v17.05.30
  • Update to check script checkftpanonymous.sh to redirect stderr of the which command to /dev/null.
Version: v17.05.26
  • New check script checkvsftpdanonymous.sh to check if the vsftp FTP server may allow anonymous login.
  • Update to check script checkftpanonymous.sh to check if the ftp client is installed before attempting to run ftp.
  • Update to check script checkyumreposdfiles.sh to exclude empty lines from the output that is generated.
  • Update to check script checkrsyslogfiles.sh replacing the while loop with a for loop to ensure proper end return code status.
  • Update to check script checkntpsteptickers.sh to check if /etc/ntp/step-tickers only has empty lines or comments before recommending to empty it.
  • Update to check script checkmemvscpu.sh to correct an issue when dmidecode reports memory in GB instead of MB.
  • Update to check script checkexports.sh to avoid reporting the same error on duplicate entries in /etc/exports.
  • Update to check script checketcsecuritypwqualityconfperms.sh to only alert about a missing /etc/pwquality.conf file on RHEL7 and higher.
  • Update to check script checkresolvconf.sh to check for IP addresses listed for the search and domain entries in /etc/resolv.conf.
  • Update to check script checkall.sh to filter out any IP addresses when the domain entry is determined from /etc/resolv.conf.
  • Update to check script checkdefaultusersettings to check first if settings can be found in /etc/login.defs before starting to compare them.
  • New check script checkpasswd.sh to display the contents of /etc/passwd.
  • New check script checkgroup.sh to display the contents of /etc/group.
  • Update to check script checketcgroupperms.sh to also check if file /etc/group exists and is not empty.
  • Update to check script checketcpasswdperms.sh to also check if file /etc/passwd exists and is not empty.
  • New check script checkrpmqahistory to display the list of installed RPM packages by date.
Version: v17.05.25
  • Update to check script checkall.sh to change certain echo commands to printf to improve the generated copyright message.
  • Update to check script checkgeoc.sh to change the error to a warning message.
Version: v17.05.24
  • New check script checkyumutils.sh to check if the yum-utils package has been installed.
  • New check script checkneedsrestarting.sh to check if the needs-restarting command indicates that a reboot is required.
Version: v17.05.23
  • Update to check script checkall.sh to also allow it to run on Scientific Linux systems.
Version: v17.05.22
  • Update to check script checkall.sh to include the model architecture in the system configuration section.
  • New check script checkarchitecture.sh to check the model architecture.
Version: v17.05.21
  • New check script checkldapconf.sh to display the contents of /etc/ldap.conf, if present.
  • New check script checkpampasswordhistory.sh to check if password history checking is enabled through PAM pam_unix.so or pam_pwhistory.so.
  • New check script checkpamunix.sh to check pam_unix.so in /etc/pam.d.
Version: v17.05.19
  • New check script checkoracleage.sh to check if password aging for user oracle is disabled.
  • New check script checkrootage.sh to check if password aging for root is disabled.
  • New check script checkdevnull.sh to check if /dev/null exists and is not a regular file.
  • New check script checkblankpassword.sh to check if there are any users with blank passwords.
  • New check script checkpamnullok.sh to check if there is no nullok argument listed for pam_unix.so allowing a user without a password to log in to the system.
  • New check script checkpampwquality.sh to check if pam_pwquality.so is used, and if so, with the correct entries.
  • New check script checkmissingowners.sh to check for files that have no owner or group.
  • New check script checketcsecuritypwqualityconfperms.sh to check the permissions of /etc/security/pwquality.conf.
Version: v17.05.18
  • New check script checkpamcracklib.sh to check if pam_cracklib.so is used, and if so, with the correct entries.
  • New check script checkpamdother.sh to check if the proper pam_deny.so entries are present in /etc/pam.d/other.
Version: v17.05.17
  • New check script checkdefaultusersettings.sh to check if the default user settings in /etc/login.defs are correctly set.
  • New check script checketcshadowused.sh to check if /etc/shadow is used for storing passwords.
  • New check script checketcdefaultuseraddinactive.sh to check the INACTIVE item in file /etc/default/useradd.
  • New check script checketcdefaultuseraddperms.sh to check if the permissions of /etc/default/useradd are correctly set.
  • New check script checketcdefaultperms.sh to check the permissions of folder /etc/default.
  • New check script checkiddsapuboracle.sh to check if the id_dsa.pub file for user oracle indeed has been generated on this host.
  • New check script checkiddsapub.sh to check if the id_dsa.pub file of user root indeed has been generated on this host.
  • New check script checkidrsapuboracle.sh to check if the id_rsa.pub file for user oracle indeed has been generated on this host.
  • New check script checkidrsapub.sh to check if the id_rsa.pub file of user root indeed has been generated on this host.
  • New check script checkdotsshperms.sh to check if the permissions of the .ssh folder for eaach user are correctly set.
Version: v17.05.09
  • Update to check script checksubscriptionmanagerlist.sh to also check for partially subscribed systems.
Version: v17.04.28
  • New check script checksockets.sh to display the number of cores and sockets per system.
  • New check script checktrlaltdel.sh to check if entry ctrlaltdel in /etc/inittab is not present.
  • New check script checklastlogsize.sh to check the size of the /var/log/lastlog file.
  • New check script checklastlog.sh to display the output of the lastlog command.
  • New check script checkfchostwwpn.sh to show the world wide port name of each fibre channel adapter on the system.
  • New check script checklastlogperms.sh to check the permissions of /var/log/lastlog.
  • New check script checkinstallonlylimit.sh to check if the installonly_limit in /etc/yum.conf is correctly set to 3.
  • New check script checkoslevel.sh to check for the latest level of Red Hat Enterprise Linux or CentOS installed.
  • Update to check script checkusersloggedonlongtime.sh to avoid reporting users twice, and to generate a proper return code.
  • Update to check script checkcleanetc.sh to exclude any alerts about /etc/ntp.conf.rpmnew.
  • Update to check script checketchosts.sh to update the output provided by the script.
  • Update to check script checkcleanetcmail.sh to exclude any alerts about /etc/mail/sendmail.cf.rpmsave.
  • New check script checketcnamedconf.sh to display the contents of /etc/named.conf.
  • New check script checketcnamedconfperms.sh to check the permissions of /etc/named.conf.
  • New check script checkhostnamectlvshostname.sh to check if the hostname command provides the same output as the hostnamectl command.
  • New check script checkhostnamectl.sh to display the output of the hostnamectl command.
  • New check script checkusrbintimedatectl.sh to check if the permissions of /usr/bin/timedatectl are correctly set.
  • New check script checkusrbinhostnamectl.sh to check if the permissions of /usr/bin/hostnamectl are correctly set.
  • New check script checkhostnamevsdns.sh to check if the hostname and the name known in DNS match.
  • New check script checktopcpuusers.sh to list the top CPU using processes.
  • Update to check script checktsmnodenameindsmsys.sh to check only for the short hostname.
  • Update to check script checktsmbackup.sh to allow it to work independently of the location of the grep and egrep commands.
  • Update to check script checksudoerspassword.sh to ensure no error is produced with too many arguments.
  • New check script checkcleansshdiroracle.sh to check for any files in ~oracle/.ssh that can be cleaned up.
  • New check script checkcleansshdir.sh to check for any files in ~root/.ssh that can be cleaned up.
  • New check script checkcleanroot.sh to check for any files in root directory that can be cleaned up.
  • New check script checkpama.sh to display the files /etc/pam.conf - if it exists - and any files in /etc/pam.d.
  • New check script checketcpamdperms.sh to check the permissions of /etc/pamd.d.
  • New check script checkpamdsuauth.sh to check if there is not a sufficient entry in /etc/pam.d/su for the auth activity and the pam_permit.so module.
  • New check script checkcleanetc.sh to check for any files in /etc that can be cleaned up.
  • New check script checksendmailopenrelay.sh to check if sendmail is configured for open relay.
  • New check script checkcleanetcmail.sh to check for any files in /etc/mail that can be cleaned up.
  • New check script checkdellomsa.sh to check if the OMSA tools of Dell are installed on Dell PowerEdge systems.
  • New check script checkomreportvdisk.sh to check the status of the virtual disks in the system.
  • New check script checkomreportpdisk.sh to check the status of the phyiscal disks in the system.
  • New check script checkomreportcontroller.sh to check the status of the controller in the system.
  • Update to check script checkleapvulnerability.sh to check for the 2016 leap second.
  • New check script checkmultipleipinetchosts.sh to check for multiple different IP addresses for the hostname in /etc/hosts.
  • New check script checkdnslookupmultipleip.sh to check if a host is registered in DNS with multiple IP addresses.
  • New check script checkinterface.sh to check if the network interface file is present.
  • New check script checkncpa.sh to check if the Nagios Cross Platform Agent is installed and running.
  • New check script checkresolvconfparse.sh to check if parsing of /etc/resolv.conf is successful.
  • New check script checkadminpassword.sh to check if we can guess the password for user admin, if that user exists.
  • New check script checksupportpassword.sh to check if we can guess the password for user admin, if that user exists.
  • New check script checkmanagerpassword.sh to check if we can guess the password for user admin, if that user exists.
  • New check script checkdirtycow.sh to check for the Dirty Cow vulnerability, CVE-2016-5195.
  • New check script checkdfsummary.sh to display a summary of file system space allocated, used and available in gigabytes.
  • New check script checkenv.sh to display the shell environment.
  • New check script checkcpuspeed.sh to display the speed of the CPUs.
  • New check script checketcsecuritylimitsconfperms.sh to check the permissions of /etc/security/limits.conf.
  • New check script checksysctla.sh to display the output of sysctl -a to show the kernel parameters.
  • New check script checktop20swapusers.sh to list the top 20 swap space using processes.
  • New check script checkutillinux.sh to check if RPM package util-linux or util-linux-ng is installed.
  • New check script checkhyperthreading.sh to check if Hyper-Threading is enabled.
  • New check script checksystemboottime.sh to check when the system was booted.
  • New check script checketcpasswdoraclename.sh to check if the name of user oracle is correct in /etc/passwd.
  • New check script checketcpasswdrootname.sh to check if the name of user root is correct in /etc/passwd.
  • New check script checkgrouplength.sh to check if the group name is not longer than 256 characters.
  • New check script checketcpasswdcomments.sh to check for any comments in /etc/passwd.
  • New check script checketcgroupcomments.sh to check for any comments in /etc/group.
  • New check script checknobodygroup.sh to check for the correct members of the nobody group.
  • New check script checksysgroup.sh to check for the correct members of the sys group.
  • New check script checkbingroup.sh to check for the correct members of the bin group.
  • New check script checkadmgroup.sh to check for the correct members of the adm group.
  • New check script checkrootgroup.sh to check for the correct members of the root group.
  • New check script checksubscriptionmanageridentity.sh to check the subscription-manager identity.
  • New check script checksystemuuid.sh to display the system UUID.
  • New check script checkthreads.sh to check if there are more than 40,000 threads on the system.
  • New check script checktmpexecutables.sh to check for any executable files in /tmp and /var/tmp.
  • New check script checktmout.sh to check if a shell timeout has been set.
  • New check script checktmpusage.sh to check if there's more than 1 GB in /tmp.
  • New check script checkgidunique.sh to check if all GIDs are unique.
  • New check script checkuidunique.sh to check if all UIDs are unique.
  • New check script checkuidzero.sh to check if only one UID 0 exists in /etc/passwd.
  • New check script checkumask.sh to check if the default umask is set to 0002.
  • New check script checkunzip.sh to check if the unzip RPM is installed.
  • New check script checkupdate.sh to check if there are any old update processes active.
  • New check script checkuserknownhostsfile.sh to check if UserKnownHostsFile isn't configured in /etc/ssh/ssh_config.
  • New check script checkusernameunique.sh to check if all user names are unique.
  • New check script checkusernetrc.sh to check the owner and the permissions of the .netrc file of every user.
  • New check script checketcpasswdpasswords.sh to check if any passwords are present in /etc/passwd.
  • New check script checkusernopassword.sh to check if there are user accounts that have no password set.
  • New check script checketcshadowperms.sh to check the owner and mode of /etc/shadow.
  • New check script checkuidzeropassword.sh to check if we can guess the password for user accounts with UID zero (excluding root).
  • New check script checkhaltpassword.sh to check if we can guess the password for user halt.
  • New check script checkoraclepassword.sh to check if we can guess the password for user oracle.
  • New check script checkrootpassword.sh to check if we can guess the password for user root.
  • New check script checkshutdownpassword.sh to check if we can guess the password for user shutdown.
  • New check script checkuserpassword.sh to check if we can guess passwords of users.
  • New check script checkuserbashrc.sh to check the owner and the permissions of the .bashrc of every user.
  • New check script checkusershell.sh to check if all users have a valid, existing shell.
  • New check script checkusersloggedonlongtime.sh to display the users that are currently logged on for a long time.
  • New check script checkusrbincrontabperms.sh to check the permissions of /usr/bin/crontab.
  • New check script checkusrbin.sh to check the correct owner and mode for /bin and /usr/bin.
  • New check script checkusrbinlinks.sh to check if the targets for links in /usr/bin exist.
  • New check script checkusrlibperms.sh to check if the permissions of the /usr/lib folder are correctly set.
  • New check script checkusrliblinks.sh to check if the targets for links in /usr/lib exist.
  • New check script checkusrsbincrondperms.sh to check the permissions of /usr/sbin/crond.
  • New check script checkvarempty.sh to check if /var/empty exists, with the proper permissions and owner, and is indeed empty.
  • New check script checkvarpreserve.sh to check for a large amount of data in /var/preserve.
  • New check script checkvartmp.sh to check for any old files in /var/tmp that may be deleted.
  • New check script checkvmstat.sh to check if vmstat is available on the server, and if so, display vmstat output.
  • New check script checkvmstats.sh to run vmstat -s to display paging statistics since boot time.
  • New check script checkzip.sh to check if the zip RPM is installed.
  • New check script checkwget.sh to check if wget is installed.
  • New check script checkwtmpsize.sh to check the size of the /var/log/wtmp file.
  • New check script checkrootsize.sh to check if the size of / is at least 1 GB.
  • New check script checkoptbmcsize.sh to check if the size of /opt/bmc is at least 2 GB.
  • New check script checkoptperms.sh to check if the permissions of the /opt folder are correctly set.
  • New check script checknoatime.sh to check if noatime has been set for any file systems.
  • New check script checknmapportscan.sh to run a nmap port scan on localhost, if nmap is installed, to discover any open ports.
  • New check script checkbinftpperms.sh to check the permissions of /bin/ftp.
  • New check script checkdefaultgateway.sh to check if a default gateway is present.
  • New check script checkipv6properlydisabled.sh to check if IPv6 is properly disabled, if disabled.
  • New check script checkpostfixipv6support.sh to check if postfix reports an error on IPv6 having been disabled improperly.
  • New check script checksystemctldegraded.sh to check if systemctl reports a degraded status.
  • New check script checkvncserverpidfile.sh to check if the directory for the pidfile of the VNC server exists.
  • New check script checkbincpioperms.sh to check the permissions of /bin/cpio.
  • New check script checkbindmesgperms.sh to check the permissions of /bin/dmesg.
  • New check script checkbinenvperms.sh to check the permissions of /bin/env.
  • New check script checkbindfperms.sh to check the permissions of /bin/df.
  • New check script checkbindateperms.sh to check the permissions of /bin/date.
  • New check script checkbincutperms.sh to check the permissions of /bin/cut.
  • New check script checkbinchgrpperms.sh to check the permissions of /bin/chgrp.
  • New check script checkbinbashperms.sh to check the permissions of /bin/bash.
  • New check script checkbinbasenameperms.sh to check the permissions of /bin/basename.
  • New check script checkbinddperms.sh to check the permissions of /bin/dd.
  • New check script checkbinechoperms.sh to check the permissions of /bin/echo.
  • New check script checkbinfindperms.sh to check the permissions of /bin/find.
  • New check script checkbinhostnameperms.sh to check the permissions of /bin/hostname.
  • New check script checkbinkillperms.sh to check the permissions of /bin/kill.
  • New check script checkbinlnperms.sh to check the permissions of /bin/ln.
  • New check script checkbinlsperms.sh to check the permissions of /bin/ls.
  • New check script checkbinmountperms.sh to check the permissions of /bin/mount.
  • New check script checkbinumountperms.sh to check the permissions of /bin/umount.
  • New check script checkbinpingperms.sh to check the permissions of /bin/ping.
  • New check script checkbinpsperms.sh to check the permissions of /bin/ps.
  • New check script checkbinpwdperms.sh to check the permissions of /bin/pwd.
  • New check script checkbintarperms.sh to check the permissions of /bin/tar.
  • New check script checkbintouchperms.sh to check the permissions of /bin/touch.
  • New check script checketcenvironmentperms.sh to check the permissions of /etc/environment.
  • New check script checketcgroupperms.sh to check the owner and mode of /etc/group.
  • New check script checketcpasswdperms.sh to check the owner and mode of /etc/passwd.
  • New check script checketcrcdperms.sh to check the permissions of all folders in /etc/rc.d.
  • New check script checketcrcdrcperms.sh to check the permissions of /etc/rc.d/rc.
  • New check script checketcrc.sh to check if /etc/rc is a link to /etc/rc.d/rc.
  • New check script checketcshellsperms.sh to check the permissions of /etc/shells.
  • New check script checketcmotdperms.sh to check the permissions of /etc/motd.
  • New check script checketcprotocols.sh to check the permissions of /etc/protocols.
  • New check script checkusrbinsarperms.sh to check the permissions of /usr/bin/sar.
  • New check script checkusrbinsftpperms.sh to check the permissions of /usr/bin/sftp.
  • New check script checkusrbinscpperms.sh to check the permissions of /usr/bin/scp.
  • New check script checketcsecurityperms.sh to check the permissions of folder /etc/security.
  • New check script checketcservicesperms.sh to check the permissions of /etc/services.
  • New check script checkusrbinsshperms.sh to check if the permissions of /usr/bin/ssh are correctly set.
  • New check script checkbinsuperms.sh to check if the permissions of /bin/su are correctly set.
  • New check script checkusrbinawkperms.sh to check the permissions of /usr/bin/tee.
  • New check script checkbinawkperms.sh to check the permissions of /bin/awk.
  • New check script checkbincatperms.sh to check the permissions of /bin/cat.
  • New check script checkbinchmodperms.sh to check the permissions of /bin/chmod.
  • New check script checkbinchownperms.sh to check the permissions of /bin/chown.
  • New check script checkbincpperms.sh to check the permissions of /bin/cp.
  • New check script checkusrbinftpperms.sh to check the permissions of /usr/bin/ftp.
  • New check script checkbinegrepperms.sh to check the permissions of /bin/egrep.
  • New check script checkbingrepperms.sh to check the permissions of /bin/grep.
  • New check script checkbinksh93perms.sh to check the permissions of /bin/ksh93, if it exists.
  • New check script checkusrbinheadperms.sh to check the permissions of /usr/bin/head.
  • New check script checkusrbintailperms.sh to check the permissions of /usr/bin/tail.
  • New check script checkbinkshperms.sh to check the permissions of /bin/ksh.
  • New check script checkbinmkdirperms.sh to check the permissions of /bin/mkdir.
  • New check script checkbinrmdirperms.sh to check the permissions of /bin/rmdir.
  • New check script checkusrbinlessperms.sh to check the permissions of /usr/bin/less.
  • New check script checkbinmoreperms.sh to check the permissions of /bin/more.
  • New check script checkbinmvperms.sh to check the permissions of /bin/mv.
  • New check script checkusrbinpasswdperms.sh to check the permissions of /usr/bin/passwd.
  • New check script checkbinrmperms.sh to check the permissions of /bin/rm.
  • New check script checkbinsedperms.sh to check the permissions of /bin/sed.
  • New check script checkbinviperms.sh to check the permissions of /bin/vi.
  • New check script checkusrperms.sh to check the permissions of /usr.
  • New check script checkvarspoolcronperms.sh to check the permissions of /var/spool/cron.
  • New check script checkvarspoollpdperms.sh to check the permissions of /var/spool/lpd.
  • New check script checkvarspoolperms.sh to check the permissions of /var/spool.
  • New check script checkvartmpperms.sh to check the permissions of /var/tmp.
  • New check script checkswapminsize.sh to check if the minimum recommended swap space is available.
  • New check script checkbc.sh to check if the bc package is installed.
  • New check script checkswapsize.sh to check the swap space size.
  • New check script checklscpu.sh to display information about the CPU architecture using the lscpu command.
  • New check script checkmemvscpu.sh to check if the ratio for CPU vs Memory is less then 1:1.
  • New check script checkboottarget.sh to display the boot target of the system.
  • New check script checkinittaberrs.sh to check for any processes started from inittab with an exit code other than 0.
  • New check script checkinittabcomments.sh to check commented items in /etc/inittab.
  • New check script checkinittabcommands.sh to check if the commands in the /etc/inittab file actually exist.
  • New check script checkinittabcommandexec.sh to check if the commands in the /etc/inittab file are executable.
  • New check script checkinittabduplicates.sh to check for any duplicate entries in /etc/inittab.
  • New check script checkinodeusage.sh to check the inode usage of all file systems.
  • New check script checkdavfsnetdev.sh to check if a _netdev option is added for each davfs entry in /etc/fstab.
  • New check script checkcifsnetdev.sh to check if a _netdev option is added for each cifs entry in /etc/fstab.
  • New check script checknfsnetdev.sh to check if a _netdev option is added for each NFS entry in /etc/fstab.
  • New check script checkinittabrunlevels.sh to check if the runlevel entry exists in /etc/inittab.
  • New check script checkinittab.sh to display the contents of /etc/inittab.
  • New check script checkinittabperms.sh to check the permissions of /etc/inittab.
  • New check script checkrunlevel.sh to check the runlevel.
  • New check script checkbootgrub2perms.sh to check the permissions of /boot/grub2.
  • New check script checkbootgrubperms.sh to check the permissions of /boot/grub.
  • New check script checkbootperms.sh to check the permissions of /boot.
  • New check script checkbootgrub2grubcfgperms.sh to check the permissions of /boot/grub2/grub.cfg.
  • New check script checketcgrub2cfg.sh to display the contents of /etc/grub2.cfg.
  • New check script checksubscriptionmanager.sh to check the status of subscription-manager and see if a valid Red Hat license is registered.
  • New check script checkfreespaceinfs.sh to check if there's any space left in the file systems.
  • New check script checketcnsswitchconf.sh to display the contents of /etc/nsswitch.conf.
  • New check script checketcnsswitchconfperms.sh to check the permissions of /etc/nsswitch.conf.
  • New check script checketchostsallow.sh to display the contents of /etc/hosts.allow.
  • New check script checketchostsdeny.sh to display the contents of /etc/hosts.deny.
  • New check script checketchostsallowperms.sh to check the permissions of /etc/hosts.allow.
  • New check script checketchostsdenyperms.sh to check the permissions of /etc/hosts.deny.
  • New check script checkopennfsexports.sh to list any NFS exports that are open to everyone.
  • New check script checkexportperms.sh to check the permissions of /etc/exports.
  • New check script checkvnc.sh to check if the vnc-server RPM is installed.
  • New check script checkexorts.sh to check if directories in /etc/exports actually exist, and if no duplicate entries in /etc/exports are present.
  • New check script checktelnet.sh to check if telnet is disabled.
  • New check script checkcpuload.sh to check the CPU load of the system.
  • New check script checkswapusage.sh to check the usage of the swap space on the system.
  • New check script checktmpmounts.sh to check for any file systems mounted in /tmp.
  • New check script checklocalhost.sh to check if localhost resolves to 127.0.0.1.
  • New check script checklvmdiskscan.sh to display the LVM physical volumes on the system.
  • New check script checkswapon.sh to display the swap spaces, their sizes and the usage.
  • New check script checklsblka.sh to display all the block devices on the system.
  • New check script checketcautomaster.sh to display the contents of the /etc/auto.master file.
  • New check script checketccrypttabperms.sh to check the permissions of /etc/crypttab.
  • New check script checketccrypttab.sh to display the contents of /etc/crypttab file if that file is not empty.
  • New check script checkklogdactive.sh to check if klogd is active on RHEL versions 4 or 5.
  • New check script checklimits.sh to display the current user limits set in /etc/security/limits.conf or any configuration file in /etc/security/limits.d.
  • New check script checketcfstabfilesystems.sh to check if mounted file systems are present in /etc/fstab.
  • New check script checkclusterrhcsclustat.sh to display the status of the Red Hat Cluster Suite, if installed.
  • New check script checknetstat.sh to display the output of nestat.
  • New check script checkifcfg.sh to display the contents of the network scripts.
  • New check script checkfcporthostspeed.sh to check the port speed of any fibre channel host adapter.
  • New check script checksystoolfchost.sh to display the output of the fibre channel configuration using systool.
  • New check script checksysfsutils.sh to check if the sysfsutils package is installed.
  • New check script checkfcporthoststate.sh to check the port state of any fibre channel host adapter.
  • New check script checkmultipathdshowpaths.sh to display the output of the multipathd show paths command, which displays the paths known to multipathd.
  • New check script checkmultipathdshowconfig.sh to display the output of the multipathd show config command, which displays the multipath configuration.
  • New check script checkipaddressshow.sh to show the output of ip address show to display the IP configuration of the system.
  • New check script checketcgrubconfentries.sh to check the entries in /etc/grub.conf for correctness.
  • New check script checkcoredumps.sh to check for any core dumps on the system.
  • New check script checkhistfile.sh to check if the HISTFILE is set in /etc/bashrc to something different than the default .bash_history.
  • New check script checkhistfileexists.sh to check if the history file for user root exists.
  • New check script checkpatrolrunning.sh to check if the BMC Patrol Agent is active.
  • New check script checkpatrolstart.sh to check if BMC's PatrolAgent is started at system boot time, if installed.
  • New check script checkcupsdconf.sh to display the contents of /etc/cups/cupsd.conf, if present.
  • New check script checkveritasvxdmpadmlistenclosure.sh to list all the enclosures available to Veritas Dynamic Multi-Pathing.
  • New check script checkveritasvxdmpadmlistctlr.sh to list all the HBA controllers available to Veritas Dynamic Multi-Pathing.
  • New check script checkveritasvxdmpadmgetdmpnode.sh to list all the nodes of Veritas Dynamic Multi-Pathing.
  • New check script checkveritasvxdmpadm.sh to list all the paths of Veritas Dynamic Multi-Pathing.
  • New check script checkveritasvxdiskpath.sh to list all paths of Veritas Dynamic Multi-Pathing.
  • New check script checksplunkthpdisabled.sh to check if Transparent Huge Pages (THP) are disabled on systems running Splunk.
  • New check script checksplunkulimit.sh to check if the limit for open files for user account splunk has been increased to at least 8192.
  • New check script checkdrown.sh to check if a system is vulnerable to the DROWN OpenSSL attack.
  • New check script checkhomefilesystem.sh to check if /home is a separate file system.
  • New check script checkhostnamelocalhost.sh to check if the hostname is localhost.
  • New check script checkhostname.sh to check if the hostname and the output of uname -n match.
  • Update to all check scripts to include the correct copyright message.
  • New check script checkmemorysize.sh to display the memory size.
  • New check script checkipaddress.sh to display the IP address of the system.
  • New check script checkkernelrelease.sh to display the kernel release.
  • New check script checkgetconf.sh to run the getconf -a command to display the configuration values.
  • New check script checkserialno.sh to display the serial number.
  • New check script checkclusterveritaslevel.sh to display the level of the Veritas Cluster Server, if installed.
  • New check script checkclusterrhcslevel.sh to display the level of the Red Hat Cluster Suite, if installed.
  • New check script checkbit.sh to check if the system is running a 32 or 64 bit kernel.
  • New check script checkusernumber.sh to check the number of users logged in.
  • New check script checkcpu.sh to display processor information.
  • New check script checkcpucount.sh to display the amount of CPUs.
  • New check script checkprocessnumber.sh to check the number of processes active.
  • New check script checkprocesslist.sh to list all the running processes.
  • Update to check script checketcredhatrelease.sh to also check if RPM redhat-release is properly installed.
  • New check script checkfilesystemnumber.sh to check the number of file systems present on a Linux system.
  • New check script checkgecos.sh to check if each user account has a GECOS field completed.
  • New check script checksudoerspassword.sh to check if we can guess the password for any user in /etc/sudoers.
  • New check script checksudoers.sh to display the sudo configuration.
  • New check script checksudoersgroups.sh to check if any groups defined in /etc/sudoers or any files in /etc/sudoers.d aren't set to primary groups of users.
  • New check script checksudoersenvreset.sh to check if env_reset is disabled in /etc/sudoers or any file in /etc/sudoers.d.
  • New check script checksudoersduplicates.sh to check if duplicate entries in /etc/sudoers and any files in /etc/sudoers.d exist.
  • New check script checksudoersdefaults.sh to check if the necessary defaults have been set in /etc/sudoers.
  • New check script checksudoerrors.sh to check for any errors reported by the sudo command.
  • New check script checksudoersdfilespermissions.sh to check if the owner and permissions of any files in folder /etc/sudoers.d are correctly set.
  • New check script checksudoersdpermissions.sh to check if the owner and permissions of folder /etc/sudoers.d are correctly set.
  • New check script checksudoerspermissions.sh to check if the owner and permissions of /etc/sudoers are correctly set.
  • New check script checksharutils.sh to check if the sharutils package has been installed.
  • New check script checkrsshconf.sh to display the contents of /etc/rssh.conf.
  • New check script checkkrb5confperms.sh to check the permissions of /etc/krb5.conf.
  • New check script checkkrb5conf.sh to display the contents of /etc/krb5.conf for Kerberos authentications, if the file exists.
  • New check script checkmultipathstatus.sh to check for any errors in the output of multipath.
  • New check script checkxivsyslist.sh to display the output of the xiv_syslist command.
  • New check script checkxiviscsiadminstoragesystem.sh to display the details of the XIV storage systems that are currently attached via iSCSI through the XIV Host Attachment Kit.
  • New check script checkxiviscsiadminitiator.sh to display the iSCSI initiator name and alias name recognized by the XIV Host Attachment Kit.
  • New check script checkxivhakvsnoxivdevices.sh to check if the XIV Host Attachment Kit is installed, but no XIV devices have been attached.
  • New check script checkxivhaklevel.sh to check the level of the XIV Host Attachment Kit installed.
  • New check script checkxivfcadminwwpn.sh to display the world-wide port number (WWPN) of host bus adapters (HBAs) installed on this host and recognized by the XIV Host Attachment Kit.
  • New check script checkxivfcadminstoragesystem.sh to display the details of the XIV storage systems that are currently attached via Fibre Channel through the XIV Host Attachment Kit.
  • New check script checkxivdevlist.sh to display the output of the xiv_devlist command.
  • New check script checkxivdevlisterrors.sh to check for any errors reported by the xiv_devlist command.
  • New check script checkmultipathconfperms.sh to check the permissions of /etc/multipath.conf.
  • New check script checkiscsiconfperms.sh to check the permissions of /etc/iscsi/iscsid.conf.
  • New check script checkifconfig.sh to show the ifconfig settings.
  • New check script checklspci.sh to run lspci to display a list with information about PCI devices in the system.
  • New check script checkveritasvxdglist.sh to display listing and state information of all Veritas disk groups.
  • New check script checkdiskbypath.sh to list the paths to all the disks and partitions.
  • New check script checkveritasvxdisklist.sh to list all disks used by Veritas (VX).
  • New check script checkiscsiinitiatorname.sh to display the contents of /etc/iscsi/initiatorname.iscsi, if present.
  • New check script checkiscsiadmmodenode.sh to display the iscssi node records.
  • New check script checkiscsidconf.sh to display the contents of /etc/iscsi/iscsid.conf, if present.
  • New check script checkfind.sh to check if there are long running find processes on the system.
  • New check script checkcrond.sh to check if there are more than 10 crond processes.
  • New check script checkvarlogbtmpperms.sh to check the permissions of /var/log/btmp.
  • New check script checkvvarrunutmpperms.sh to check the permissions of /var/run/utmp.
  • New check script checkvarlogwtmpperms.sh to check if the owner and permissions of /var/log/wtmp are correctly set.
  • New check script checksushi.sh to check for a known backdoor called sushi of vendor Sunquest.
  • New check script checkcifsnodename.sh to check if the nodename for any CIFS file system can be pinged.
  • New check script checkcifsaccess.sh to check if any CIFS mounted file systems can be accessed.
  • New check script checkgangliagmondrunning.sh to check if the Ganglia gmond process is running, if it is installed.
  • New check script checkgangliagmondlevel.sh to check the level of the gmond for Ganglia, if installed.
  • New check script checkgangliagmondconf.sh to check the configuration file for gmond of Ganglia.
  • New check script checkgangliagmetadrunning.sh to check if the Ganglia gmetad process is running, if it is installed.
  • New check script checkgangliagmetadlevel.sh to check the level of the gmetad for Ganglia, if installed.
  • New check script checkgangliagmetadconf.sh to check the configuration file for gmetad.
  • New check script checkpostfixsmtpconnection.sh to check if a connection can be made to the SMTP server defined for Postfix.
  • New check script checksendmailsmtpconnection.sh to check if a connection can be made to the SMTP server defined for Sendmail.
  • New check script checkpostfixsmtp.sh to display the SMTP server for Postfix, and warn if the relay host is not configured properly in DNS.
  • New check script checkpostfixsendmail.sh to check if both Postfix and Sendmail are installed.
  • New check script checklinklocal.sh to display any link-local network addresses configured.
  • New check script checkpostfix.sh to check if Postfix is running.
  • New check script checksendmail.sh to check if sendmail is running.
  • New check script checksendmailprivacyoptions.sh to check the privacy options for sendmail to be set to the most private settings.
  • New check script checksendmailgreetingmessage.sh to check the SMTP greeting message of Sendmail to ensure no unnecessary information is provided.
  • New check script checketclogrotatedperms.sh to check the permissions of /etc/logrotate.d.
  • New check script checklogrotateconf.sh to display the contents of /etc/logrotate.conf.
  • New check script checklogrotate.sh to check if logrotate is installed.
  • New check script checklogrotatedfiles.sh to check if the log files that are being rotated actually exist.
  • New check script checkpostfixmyorigin.sh to check if a myorigin entry is not present in /etc/postfix/main.cf.
  • New check script checkpostfixmydomain.sh to check if a mydomain entry is present in /etc/postfix/main.cf.
  • New check script checkpostfixmyhostname.sh to check if a myhostname entry is present in /etc/postfix/main.cf.
  • New check script checkpostfixrelayhost.sh to check if a relay host is present in /etc/postfix/main.cf.
  • New check script checkmailqac.sh to check the client mail queue for Sendmail.
  • New check script checkmailq.sh to check the mail queue.
  • New check script checksendmailaliasesfile.sh to check if the aliases file, as referred to in /etc/mail/sendmail.cf, actually exists.
  • New check script checkpostfixaliasesfile.sh to check if the aliases file, as referred to in /etc/postfix/main.cf, actually exists.
  • New check script checklogrotatedfilesperms.sh to check the permissions of files in /etc/logrotate.d.
  • New check script checkpostfixipv4support.sh check if postfix has been enabled for all inet_protocols, but only ipv4 is supported.
  • New check script checkvarspoolclientmqueueperms.sh to check the permissions of /var/spool/clientmqueue.
  • New check script checkvarspoolclientmqueue.sh to check for a large number of files and old files in /var/spool/clientmqueue.
  • New check script checkrootfs.sh to check the file permissions and ownership of the root file system.
  • New check script checketcmailsendmailcfperms.sh to check the permissions of /etc/mail/sendmail.cf.
  • New check script checketcpostfixmaincfperms.sh to check the permissions of /etc/postfix/main.cf.
  • New check script checketcpostfixperms.sh to check the permissions of /etc/postfix.
  • New check script checketcmailperms.sh to check the permissions of /etc/mail.
  • New check script checketcperms.sh to check the permissions of /etc.
  • New check script checkvarspoolmqueueperms.sh to check the permissions of /var/spool/mqueue.
  • New check script checkvarspoolmqueue.sh to check for a large number of files and old files in /var/spool/mqueue.
  • New check script checksendmailsmtp.sh to display the SMTP server for sendmail.
  • New check script checkvarspoolmailperms.sh to check the permissions of /var/spool/mail.
  • New check script checkvarspoolmail.sh to check for any files or folders that don't belong in /var/spool/mail.
  • New check script checklogrotatecontrolm.sh to check for any control-M characters in /etc/logrotate.d.
  • New check script checkincrontablist.sh to list any incrontab entries.
  • New check script checketcmailrc.sh to check if entries are correctly commented out in /etc/mail.rc.
  • New check script checkmailroot.sh to check if there are any emails for user root.
  • New check script checkmailboxsize.sh to check for mailboxes with a large size.
  • New check script checkmailboxowners.sh to check for mailboxes without any owner.
  • New check script checkmailbox.sh to check for mailboxes with a large number of emails waiting.
  • New check script checkvcsgroups.sh to check the status of the resource groups managed by Veritas Cluster.
  • New check script checkpostfixpostconf.sh to display the postfix configuration using the postconf command.
  • New check script checktzdata.sh to check if package tzdata is up-to-date and any tzdata-java package is the same level as tzdata.
  • New check script checketclocaltime.sh to check if /etc/localtime is a proper copy of a timezone file.
  • New check script checkntpoffset.sh to check if the offset of ntp servers is too large.
  • New check script checkntpstat.sh to display the output of the ntpstat command.
  • New check script checkblkid.sh to display the available block devices on the system.
  • New check script checkleapvulnerability.sh to check if the system is vulnerable to the 2015 leap second.
  • New check script checkomreportstoragebattery.sh to check the status of storage controller batteries in Dell systems.
  • New check script checkomreportchassisbatteries.sh to check the status of CMOS battery in Dell systems.
  • New check script checksudocommands.sh to check if the commands in /etc/sudoers file actually exist.
  • New check script checksudoersinclude.sh to check if any files included in /etc/sudoers using the #include directive actually exist on the system.
  • New check script checksudoersincludedir.sh to check if any folders included in /etc/sudoers using the #includedir directive actually exist on the system.
  • New check script checksudocommandsexec.sh to check if the commands in /etc/sudoers file have the execute bit enabled.
  • New check script checkhomesize.sh to check if the size of /home is at least 1 GB.
  • New check script checkhomefs.sh to check the owner and group of the /home file system.
  • New check script checktmpauthorization.sh to check the authorizations of the /tmp folder.
  • New check script checktmpsize.sh to check if the size of /tmp is at least 1 GB.
  • New check script checktmp.sh to check if the permissions of the /tmp folder are correctly set.
  • New check script checkvarsize.sh to check if the size of /var is at least 1 GB.
  • New check script checkvar.sh to check if the permissions of the /var folder are correctly set.
  • New check script checkvcsversion.sh to check the version of Veritas Cluster Server, if installed.
  • New check script checkvcshastatus.sh to check the status of Veritas Cluster Server, if installed.
  • New check script checkauthconsistency.sh to run pwck to check for any issues.
  • New check script checkgroupconsistency.sh to run grpck to check for any issues.
  • New check script checketclogindefs.sh to display the contents of /etc/login.defs.
  • New check script checketclogindefsperms.sh to check the permissions of /etc/login.defs.
  • New check script checkfsdeviceandmountpoint.sh to check if the device and mountpoint of all file systems exist.
  • New check script checkfswrite.sh to check if a file can be written to each file system.
  • New check script checkprocpartitions.sh to display the block allocation information by listing /proc/partitions.
  • New check script checkunamea.sh to display the system information by running the uname -a command.
  • New check script checkdf.sh to display the output of the df command.
  • New check script checkshowmount.sh to run showmount to display a list of all clients that have remotely mounted file systems.
  • New check script checkmount.sh to display the output of the mount command.
  • New check script checkfree.sh to display the memory and swap space usage.
  • New check script checkwheel.sh to check for any members of the wheel group.
  • New check script checketcsysconfigntpdperms.sh to check the permissions of /etc/sysconfig/ntpd.
  • New check script checktemperatureibm.sh to check the temperature of IBM devices.
  • New check script checktsmservername.sh to check the TSM server name.
  • New check script checktsmschedprusize.sh to check the size of the dsmsched.pru file.
  • New check script checktsmschedules.sh to list any TSM schedules that this client is on.
  • New check script checktsmschedlogsize.sh to check the size of the sched log file.
  • New check script checktsmsched.sh to check if the TSM scheduler or acceptor daemon is active, check if the scheduler or acceptor daemon is started at system boot time, check if the scheduler is started after an update to dsm.sys.
  • New check script checktsmret.sh to check if retention entries are present in the dsm.sys file for both the schedlog and errorlog entries.
  • New check script checktsmprepostcmnds.sh to check for any pre or post schedule commands that are run through TSM as defined in dsm.sys.
  • New check script checktsmnodenameindsmsys.sh to check it the nodename in dsm.sys is correct.
  • New check script checktsmlevel.sh to check the level of the TSM client installed.
  • New check script checktsminclexcl.sh to display the included and excluded file systems and files for the TSM backup.
  • New check script checktsmfilesystems.sh to display the last backup dates of file systems in TSM.
  • New check script checktsmerrorlogsize.sh to check the size of the TSM error log file.
  • New check script checktsmdsmsysperms.sh to check the permissions of the dsm.sys file of TSM.
  • New check script checktsmdsmoptperms.sh to check the permissions of the dsm.opt file of TSM.
  • New check script checktsmconfig.sh to display the configuration of the TSM config files.
  • New check script checktsmbackup.sh to check if the most recent TSM backup was successful or not.
  • New check script checkyumreposdfiles.sh to display the contents of any repository files in /etc/yum.repos.d.
  • New check script checkyumcleanyumreposd.sh to check for any files in /etc/yum.repos.d that should not be there.
  • New check script checkyumreposdperms.sh to check the permissions of /etc/yum.repos.d.
  • New check script checkyumconfperms.sh to check the permissions of /etc/yum.conf.
  • New check script checkyumconf.sh to display the contents of /etc/yum.conf.
  • New check script checkrootshell.sh to check if the shell of user root is set to /bin/bash.
  • New check script checksestatus.sh to display the status of SELinux by running the sestatus command.
  • New check script checkmultipathd.sh to check the status of the multipathd daemon.
  • New check script checkmultipathconf.sh to display the contents of /etc/multipath.conf.
  • New check script checkmultipathv2.sh to check for any known errors in the output of multipath -v2.
  • New check script checkmultipathll.sh to display the output of the multipath -ll command, which shows the multipath topology from all available information.
  • New check script checkrhsmcertd.sh to check if the rhsmcertd service is running and activated at boot time.
  • New check script checksubscriptionmanagerlist.sh to check the Red Hat subscribtion manager status.
  • New check script checklspcivt.sh to run lspci -vt to display a tree like list with information about PCI buses in the the system and devices connected to them.
  • Update to check script checkntpdate.sh to check if the ntpdate service is enabled at system boot time - for RHEL6 and later only.
  • Update to check script checkntpd.sh to check if NTP is enabled at system boot time.
  • New check script checkntpsynchwclock.sh to check if the synchronization of the hardware clock has been enabled.
  • New check script checktimezone.sh to collect and display the timezone configured on the server.
  • New check script checkntpdate.sh to check ntpdate offset to see if the time is properly synchronized.
  • New check script checkntpoptions.sh to check if the correct options are present in /etc/sysconfig/ntpd for the NTP daemon.
  • New check script checkntpsteptickers.sh to check if /etc/ntp/step-tickers is empty, so ntpdate will use a time server from /etc/ntp.conf.
  • New check script checkntpconf.sh to display the contents of /etc/ntp.conf.
  • New check script checkntpbroadcastclient.sh to check if the broadcastclient option in ntp.conf is commented out.
  • New check script checketcntpconfperms.sh to check the permissions of /etc/ntp.conf.
  • Update to check script checkntpd.sh to test using ntpstat if ntpq -p fails to determine the NTP synchronization status.
  • New check script checketchosts.sh to check the contents and permissions of /etc/hosts.
  • New check script checketcntpconflocalclock.sh to check if a local clock (127.127.1.0) is properly configured.
  • Update to check script checkntpd.sh to check for duplicate entries in /etc/ntp.conf.
  • New check script checkdst.sh to display when time changes will occur this year due to daylight saving time.
  • Update to check script checkresolvconf.sh to ensure it also works on IBM Netezza systems that use the nzresolv service instead.
  • New check script checkresolvconf.sh to check serveral items for file /etc/resolv.conf, to ensure proper name resolving works.
  • Update to check script checkdnslookup.sh to exclude checking entries in /etc/resolv.conf that start with a semi-colon or a hash mark, as both of these are considered comments in /etc/resolv.conf in RHEL.
  • New check script checkmodelname.sh to check the brand and model name of the server.
  • New check script checkfstabperms.sh to check the permissions of /etc/fstab.
  • New check script checketcredhatreleaseperms.sh to check the permissions of /etc/redhat-release.
  • New check script checketcredhatrelease.sh to display the contents of /etc/redhat-release.
  • New check script checkanacondakscfgperms.sh to check the permissions of /root/anaconda-ks.cfg.
  • New check script checkanacondakscfg.sh to display the contents of /root/anaconda-ks.cfg.
  • New check script checkvsftpdconfperms.sh to check the permissions of /etc/vsftpd/vsftpd.conf.
  • New check script checkbootgrubgrubconfperms.sh to check the permissions of /boot/grub/grub.conf.
  • New check script checketcsysctlconfperms.sh to check the permissions of /etc/sysctl.conf.
  • New check script checketcsysctlconf.sh to display the contents of /etc/sysctl.conf.
  • New check script checkuptime.sh to check if the uptime is over 6 months.
  • New check script checkrpmqa.sh to display the output of the rpm -qa.
  • New check script checkfdiskl.sh to display the output of the fdisk -l.
  • New check script checkftpanonymous.sh to check if anonymous FTP is properly disabled.
  • New check script checkvsftpdconf.sh to display the contents of vsftpd.conf, if FTP server vsftpd is installed.
  • New check script checkvsftpd.sh to check if ftp server vsftpd is installed, and if so, if it is running.
  • New check script checketcgrubconf.sh to display the contents of /etc/grub.conf.
  • New check script checksyslogdremote.sh to check if the syslogd or rsyslogd accepts remote messages.
  • New check script checksyslogdactive.sh to check if the syslogd or rsyslogd process is active.
  • New check script checksshsyslogfacility.sh to check if SyslogFacility is enabled in /etc/ssh/sshd_config.
  • New check script checkrsyslogfiles.sh to check if the files for the rsyslog facility exist.
  • New check script checksbinsyslogdperms.sh to check the permissions of /sbin/syslogd.
  • New check script checksbinrsyslogdperms.sh to check the permissions of /sbin/rsyslogd.
  • New check script checksyslogfiles.sh to check if the files for the syslog facility exist.
  • New check script checketcsyslogconf.sh to display the contents of /etc/syslog.conf.
  • New check script checketcrsyslogconf.sh to display the contents of /etc/rsyslog.conf.
  • New check script checketcrcdrclocalperms.sh to check if the permissions of file /etc/rc.d/rc.local are correctly set.
  • New check script checkksh.sh to check if ksh is installed.
  • New check script checkchkconfig.sh to run the chkconfig command to display all the active system services.
  • New check script checklvdisplay.sh to display the attributes of logical volumes on the system by running the lvdisplay command.
  • New check script checklvs.sh to display information about logical volumes on the system by running the lvs command.
  • New check script checkvgdisplay.sh to display attributes of volume groups on the system by running the vgdisplay command.
  • New check script checkvgs.sh to display information about volume groups on the system by running the vgs command.
  • New check script checkpvdisplay.sh to display physical volume information by running the pvdisplay command.
  • New check script checkpvs.sh to display the physical volumes attached to this system by running the pvs command.
  • New check script checksysstat.sh to check if the sysstat package has been installed.
  • New check script checkdnslookup.sh to check if we can do a nslookup of the hostname.
  • New check script checketcrsyslogconfperms.sh to check the permissions of /etc/rsyslog.conf.
  • New check script checketcsyslogconfperms.sh to check the permissions of /etc/syslog.conf.
  • New check script checksyslogconfvsrsyslogconf.sh to check if the correct conf file exists with the correct syslog service.
  • New check script checkdmidecode.sh to run the dmidecode command to display all hardware related information.
  • New check script checksos.sh to check if the sos pacakage is installed.
  • New check script checketcfstab.sh to display the contents of the /etc/fstab file.
  • New check script checksambavulnerability.sh to check if the installed Samba level is vulnerable, CVE-2015-0240.
  • New check script checkghost.sh to check if the system is vulnerable to GHOST, CVE-2015-0235.
  • New check script checkzombies.sh to check for more than 10 active zombie processes.
  • New check script checkfsreadonly.sh to check if there are any file systems read-only.
  • New check script checkyumsqlite.sh to check if old sqlite files are filling up /var/cache/yum.
  • New check script checkntpd.sh to check various items of the Time Serving daemon, ntpd.
  • New check script checkyumcheckupdate.sh to check if there are any updates to be installed through yum.