{"results":[{"id":"bash-default-shell-rhel9","text":"The default shell in RHEL 9 is /bin/bash. Users access a shell prompt via terminal emulators, virtual consoles (Ctrl+Alt+F1-F6), or SSH.","truth_value":"IN","justification_count":0,"dependent_count":0,"challenges":[],"last_reviewed":null,"review_result":null},{"id":"bpf-jit-always-on-rhel9","text":"BPF JIT compilation is always enabled in RHEL 9 (`CONFIG_BPF_JIT_ALWAYS_ON=y`); BPF programs are compiled to native code, not interpreted.","truth_value":"IN","justification_count":0,"dependent_count":0,"challenges":[],"last_reviewed":null,"review_result":null},{"id":"bpf-restricted-privileged-default-rhel9","text":"BPF is restricted to privileged users by default in RHEL 9 (`unprivileged_bpf_disabled=2`); values are 0=allowed, 1=disabled, 2=disabled but admin can change.","truth_value":"IN","justification_count":0,"dependent_count":0,"challenges":[],"last_reviewed":null,"review_result":null},{"id":"io-uring-disabled-by-default-rhel9","text":"io_uring is disabled by default in RHEL 9 via `kernel.io_uring_disabled=2`; values are 0=all users, 1=privileged only, 2=disabled for all.","truth_value":"IN","justification_count":0,"dependent_count":0,"challenges":[],"last_reviewed":null,"review_result":null},{"id":"kickstart-install-command-removed-rhel9","text":"The `install` Kickstart command has been removed in RHEL 9; installation source commands (`cdrom`, `url`, `nfs`, etc.) are used directly.","truth_value":"IN","justification_count":0,"dependent_count":0,"challenges":[],"last_reviewed":null,"review_result":null},{"id":"ktls-tech-preview-rhel92","text":"Kernel TLS (KTLS) is a Technology Preview in RHEL 9.2, appearing in both security (gnutls acceleration) and networking (kernel-level TLS offload) contexts.","truth_value":"IN","justification_count":0,"dependent_count":0,"challenges":[],"last_reviewed":null,"review_result":null},{"id":"nested-kvm-tech-preview-rhel9","text":"Nested KVM virtualization is a Technology Preview in RHEL 9, working on Intel, AMD64, and IBM Z hosts.","truth_value":"IN","justification_count":0,"dependent_count":0,"challenges":[],"last_reviewed":null,"review_result":null},{"id":"nic-teaming-deprecated-rhel9","text":"NIC teaming (`team=`) is deprecated in RHEL 9; network bonding is the recommended alternative.","truth_value":"IN","justification_count":0,"dependent_count":0,"challenges":[],"last_reviewed":null,"review_result":null},{"id":"rhel8-to-rhel9-inplace-upgrade-leapp","text":"In-place upgrade from RHEL 8 to RHEL 9 is supported using the Leapp tool; Convert2RHEL handles conversions from CentOS/Alma/Rocky/Oracle Linux.","truth_value":"IN","justification_count":0,"dependent_count":0,"challenges":[],"last_reviewed":null,"review_result":null},{"id":"rhel9-ad-integration-stack","text":"RHEL 9 provides a complete AD integration stack: realmd orchestrates domain join, SSSD serves as default authentication backend, with a defined set of required packages.","truth_value":"IN","justification_count":0,"dependent_count":0,"challenges":[],"last_reviewed":null,"review_result":null},{"id":"rhel9-ad-integration-two-methods","text":"RHEL 9 supports two methods for direct Active Directory integration: SSSD and Samba Winbind.","truth_value":"IN","justification_count":0,"dependent_count":0,"challenges":[],"last_reviewed":null,"review_result":null},{"id":"rhel9-ad-join-packages-sssd","text":"Required packages for SSSD-based AD join: sssd, realmd, oddjob, oddjob-mkhomedir, adcli, samba-common-tools.","truth_value":"IN","justification_count":0,"dependent_count":0,"challenges":[],"last_reviewed":null,"review_result":null},{"id":"rhel9-ad-msa-no-domain-join","text":"Managed Service Accounts (MSA) allow access to AD resources without full domain membership on RHEL 9.","truth_value":"IN","justification_count":0,"dependent_count":0,"challenges":[],"last_reviewed":null,"review_result":null},{"id":"rhel9-aide-config-and-db-paths","text":"AIDE configuration is at `/etc/aide.conf` and the default database location is `/var/lib/aide/aide.db.gz`.","truth_value":"IN","justification_count":0,"dependent_count":0,"challenges":[],"last_reviewed":null,"review_result":null},{"id":"rhel9-aide-config-file-path","text":"AIDE configuration is controlled by `/etc/aide.conf`, which defines monitored paths and tracked attributes.","truth_value":"IN","justification_count":0,"dependent_count":0,"challenges":[],"last_reviewed":null,"review_result":null},{"id":"rhel9-aide-database-rename-required","text":"After `aide --init` or `aide --update`, the output file `/var/lib/aide/aide.db.new.gz` must be renamed to `/var/lib/aide/aide.db.gz` before it becomes active.","truth_value":"IN","justification_count":0,"dependent_count":0,"challenges":[],"last_reviewed":null,"review_result":null},{"id":"rhel9-aide-detection-only","text":"AIDE is a detection-only tool that identifies filesystem changes after they occur but does not prevent them; IMA provides both detection and prevention.","truth_value":"IN","justification_count":0,"dependent_count":0,"challenges":[],"last_reviewed":null,"review_result":null},{"id":"rhel9-aide-detection-only-not-prevention","text":"AIDE is a detection-only tool that identifies filesystem changes but does not prevent them; IMA provides both detection and prevention.","truth_value":"IN","justification_count":0,"dependent_count":0,"challenges":[],"last_reviewed":null,"review_result":null},{"id":"rhel9-aide-file-integrity-commands","text":"AIDE file integrity checking uses `aide --init` to initialize the database, `aide --check` to detect changes, and `aide --update` to update the database after review.","truth_value":"IN","justification_count":0,"dependent_count":0,"challenges":[],"last_reviewed":null,"review_result":null},{"id":"rhel9-aide-integrity-workflow","text":"AIDE provides a complete file integrity monitoring workflow: three operations (init/check/update), mandatory database rename after generation, AppStream package source, with the critical caveat that it is detection-only.","truth_value":"IN","justification_count":0,"dependent_count":0,"challenges":[],"last_reviewed":null,"review_result":null}],"count":365,"limit":20,"offset":0}