<?xml version='1.0' encoding='utf-8'?>
<ns0:oval_definitions xmlns:ns0="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:ns2="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:ns3="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" xmlns:ns4="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" xmlns:ns5="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd  http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd  http://oval.mitre.org/XMLSchema/oval-definitions-5#independent independent-definitions-schema.xsd  http://oval.mitre.org/XMLSchema/oval-definitions-5#unix unix-definitions-schema.xsd  http://oval.mitre.org/XMLSchema/oval-definitions-5#linux linux-definitions-schema.xsd">
  <ns0:generator>
    <ns2:product_name>Script combine_ovals.py from SCAP Security Guide</ns2:product_name>
    <ns2:product_version>ssg: [0, 1, 80], python: 3.10.12</ns2:product_version>
    <ns2:schema_version>5.11.2</ns2:schema_version>
    <ns2:timestamp>2026-01-21T21:18:05</ns2:timestamp>
  </ns0:generator>
  <ns0:definitions>
    <ns0:definition id="bootc" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title />
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>Bootable container or bootc system</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="kernel is installed" test_ref="bootc_platform_test_kernel_installed" />
        <ns0:criterion comment="rpm-ostree is installed" test_ref="bootc_platform_test_rpm_ostree_installed" />
        <ns0:criterion comment="bootc is installed" test_ref="bootc_platform_test_bootc_installed" />
        <ns0:criteria operator="OR">
          <ns0:criterion comment="/run/ostree-booted exists, suggesting that we are in a running bootc environment" test_ref="bootc_platform_test_run_ostree_booted_exists" />
          <ns0:criterion comment="/ostree symlink exists, suggesting that we are in a bootc environment being built and hardened" test_ref="bootc_platform_test_ostree_symlink_exists" />
        </ns0:criteria>
        <ns0:criterion comment="openshift-kubelet is not installed" test_ref="bootc_platform_test_openshift_kubelet_removed" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_OS_is_alinux2" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Alibaba Cloud Linux 2</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:reference ref_id="cpe:/o:Alibaba Cloud Linux:2" source="CPE" />
        <ns0:description>The operating system installed on the system is Alibaba Cloud Linux 2</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:extend_definition comment="Installed OS is part of the Unix family" definition_ref="installed_OS_is_part_of_Unix_family" />
        <ns0:criterion comment="Alibaba Cloud Linux 2 is installed" test_ref="test_alinux2" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_OS_is_alinux3" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Alibaba Cloud Linux 3</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:reference ref_id="cpe:/o:Alibaba Cloud Linux:3" source="CPE" />
        <ns0:description>The operating system installed on the system is Alibaba Cloud Linux 3</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:extend_definition comment="Installed OS is part of the Unix family" definition_ref="installed_OS_is_part_of_Unix_family" />
        <ns0:criterion comment="Alibaba Cloud Linux 3 is installed" test_ref="test_alinux3" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_OS_is_anolis8" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Anolis OS 8</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:reference ref_id="cpe:/o:Anolis OS:8" source="CPE" />
        <ns0:description>The operating system installed on the system is Anolis OS 8</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:extend_definition comment="Installed OS is part of the Unix family" definition_ref="installed_OS_is_part_of_Unix_family" />
        <ns0:criterion comment="Anolis OS 8 is installed" test_ref="test_anolis8" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_OS_is_debian11" version="3" class="inventory">
      <ns0:metadata>
        <ns0:title>Debian Linux 11</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:reference ref_id="cpe:/o:debian:debian_linux:11" source="CPE" />
        <ns0:description>The operating system installed on the system is Debian 11</ns0:description>
      </ns0:metadata>
      <ns0:criteria comment="Debian Linux is version 11" operator="AND">
        <ns0:extend_definition comment="Debian is installed" definition_ref="installed_OS_is_debian" />
        <ns0:criterion comment="Debian11 is installed" test_ref="test_debian_11" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_OS_is_debian12" version="3" class="inventory">
      <ns0:metadata>
        <ns0:title>Debian Linux 12</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:reference ref_id="cpe:/o:debian:debian_linux:12" source="CPE" />
        <ns0:description>The operating system installed on the system is Debian 12</ns0:description>
      </ns0:metadata>
      <ns0:criteria comment="Debian Linux is version 12" operator="AND">
        <ns0:extend_definition comment="Debian is installed" definition_ref="installed_OS_is_debian" />
        <ns0:criterion comment="Debian12 is installed" test_ref="test_debian_12" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_OS_is_debian13" version="3" class="inventory">
      <ns0:metadata>
        <ns0:title>Debian Linux 13</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:reference ref_id="cpe:/o:debian:debian_linux:13" source="CPE" />
        <ns0:description>The operating system installed on the system is Debian 13</ns0:description>
      </ns0:metadata>
      <ns0:criteria comment="Debian Linux is version 13" operator="AND">
        <ns0:extend_definition comment="Debian is installed" definition_ref="installed_OS_is_debian" />
        <ns0:criterion comment="Debian13 is installed" test_ref="test_debian_13" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_app_is_rhv4" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Red Hat Virtualization 4</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:reference ref_id="cpe:/a:redhat:virtualization:4" source="CPE" />
        <ns0:description>The application installed on the system is
      Red Hat Virtualization 4.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Red Hat Virtualization Manager (RHVM)" test_ref="test_rhevm4_version" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_env_has_grub2_package" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Package grub2 is installed</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:reference ref_id="cpe:/a:grub2" source="CPE" />
        <ns0:description>Checks if package grub2-common is installed.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Package grub2-common is installed" test_ref="test_env_has_grub2_installed" />
        <ns0:criteria operator="OR">
          <ns0:criterion negate="true" comment="Test for ppcle64 architecture" test_ref="test_system_info_architecture_ppcle_64" />
          <ns0:criterion negate="true" comment="Test if OPAL is not used" test_ref="test_system_using_opal" />
        </ns0:criteria>
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_env_has_login_defs" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Package providing /etc/login.defs is installed</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:reference ref_id="cpe:/a:login_defs" source="CPE" />
        <ns0:description>Checks if package providing /etc/login.defs and is installed.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Package providing /etc/login.defs is installed" test_ref="test_env_has_login_defs_installed" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_env_has_no_ovirt" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Check if the system doesn't act as an oVirt host or manager</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>Check if the system has neither ovirt-host nor ovirt-engine installed.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:extend_definition negate="true" comment="Package ovirt-host is not installed" definition_ref="installed_env_has_ovirt" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_env_has_ovirt" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Check if the system acts as an oVirt host or manager</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:reference ref_id="cpe:/a:ovirt-host" source="CPE" />
        <ns0:description>Check if the system has ovirt-host or ovirt-engine installed</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="OR">
        <ns0:criterion comment="Package ovirt-host is installed" test_ref="test_env_has_ovirt-host_installed" />
        <ns0:criterion comment="Package ovirt-engine is installed" test_ref="test_env_has_ovirt-engine_installed" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_env_has_wifi_interface" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>WiFi interface is present</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:reference ref_id="cpe:/a:wifi-iface" source="CPE" />
        <ns0:description>Checks if any wifi interface is present.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="WiFi interface is present" test_ref="test_proc_net_wireless_exists" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_env_is_a_container" version="2" class="inventory">
      <ns0:metadata>
        <ns0:title>Check if the scan target is a container</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:reference ref_id="cpe:/a:container" source="CPE" />
        <ns0:description>Check for presence of files characterizing container filesystems.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="OR">
        <ns0:criterion comment="Check if /.dockerenv exists" test_ref="test_installed_env_is_a_docker_container" />
        <ns0:criterion comment="Check if /run/.containerenv exists" test_ref="test_installed_env_is_a_podman_container" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_env_is_a_machine" version="2" class="inventory">
      <ns0:metadata>
        <ns0:title>Check if the scan target is a machine</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:reference ref_id="cpe:/a:machine" source="CPE" />
        <ns0:description>Check for absence of files characterizing container filesystems.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:extend_definition negate="true" comment="If environment is not a container, it is machine" definition_ref="installed_env_is_a_container" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="kernel_uek" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>System runs on UEK kernel</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:reference ref_id="cpe:/a:kernel-uek" source="CPE" />
        <ns0:description>Check if System is running on UEK kernel.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Runing kernel is UEK" test_ref="test_kernel_uek" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="krb5_server_older_than_1_17_18" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Kerberos server is older than 1.17-18</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:reference ref_id="cpe:/a:krb5_server_older_than_1_17-18" source="CPE" />
        <ns0:description>Check if version of Kerberos server is lesser than 1.17-18
            </ns0:description>
      </ns0:metadata>
      <ns0:criteria comment="Kerberos server version is lesser than 1.17-18" operator="OR">
        <ns0:criterion comment="Check if version of Kerberos server is lesser than 1.17-18" test_ref="test_krb5_server_version_1_17_18" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="krb5_workstation_older_than_1_17_18" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Kerberos workstation is older than 1.17-18</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:reference ref_id="cpe:/a:krb5_workstation_older_than_1_17-18" source="CPE" />
        <ns0:description>Check if version of Kerberos workstation is lesser than 1.17-18
            </ns0:description>
      </ns0:metadata>
      <ns0:criteria comment="Kerberos workstation version is lesser than 1.17-18" operator="OR">
        <ns0:criterion comment="Check if version of Kerberos workstation is lesser than 1.17-18" test_ref="test_krb5_workstation_version_1_17_18" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="nfs_mount_defined" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Remote NFS file system mount is defined</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:reference ref_id="cpe:/a:nfs_mount_defined" source="CPE" />
        <ns0:description>At least one remote NFS file system mount is defined in  /etc/fstab</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="remote nfs filesystem exist" test_ref="test_nfs_mount_exists" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="proc_sys_kernel_osrelease_arch_aarch64" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Test that the architecture is aarch64</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>Check that architecture of kernel in /proc/sys/kernel is aarch64</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Architecture is aarch64" test_ref="test_proc_sys_kernel_osrelease_arch_aarch64" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="proc_sys_kernel_osrelease_arch_not_aarch64" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Test for different architecture than aarch64</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>Check that architecture of kernel in /proc/sys/kernel/osrelease is not aarch64</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:extend_definition negate="true" comment="Architecture is not aarch64" definition_ref="proc_sys_kernel_osrelease_arch_aarch64" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="proc_sys_kernel_osrelease_arch_not_s390x" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Test for different architecture than s390x</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>Check that architecture of kernel in /proc/sys/kernel/osrelease is not s390x</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:extend_definition negate="true" comment="Architecture is not s390x" definition_ref="proc_sys_kernel_osrelease_arch_s390x" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="proc_sys_kernel_osrelease_arch_ppc64le" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Test that the architecture is ppc64le</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>Check that architecture of kernel in /proc/sys/kernel is ppc64le</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Architecture is ppc64le" test_ref="test_proc_sys_kernel_osrelease_arch_ppc64le" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="proc_sys_kernel_osrelease_arch_s390x" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Test that the architecture is s390x</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>Check that architecture of kernel in /proc/sys/kernel is s390x</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Architecture is s390x" test_ref="test_proc_sys_kernel_osrelease_arch_s390x" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="proc_sys_kernel_osrelease_arch_x86_64" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Test that the architecture is x86_64</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>Check that architecture of kernel in /proc/sys/kernel is x86_64</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Architecture is x86_64" test_ref="test_proc_sys_kernel_osrelease_arch_x86_64" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="runtime_kernel_fips_enabled" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Running kernel has fips mode enabled</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:reference ref_id="cpe:/a:runtime-kernel-fips-enabled" source="CPE" />
        <ns0:description>Check if sysctl crypto.fips_enabled = 1</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="check if sysctl crypto.fips_enabled = 1" test_ref="test_runtime_kernel_fips_enabled" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="secure_boot_enabled" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Secure Boot status check</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:reference ref_id="cpe:/a:secure-boot" source="CPE" />
        <ns0:description>Check if System has Secure Boot enabled.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:extend_definition comment="Pass if System boot mode is UEFI" definition_ref="system_boot_mode_is_uefi" />
        <ns0:criterion comment="Scure Boot is enabled" test_ref="test_secure_boot_enabled" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="selinux_is_enabled" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>SELinux status check</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:reference ref_id="cpe:/a:selinux" source="CPE" />
        <ns0:description>Check if System has SELinux enabled.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="enforce is disabled" test_ref="test_etc_selinux_configured" />
        <ns0:criterion comment="/sys/fs/selinux is present" test_ref="test_selinux_sys_fs_exist" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="sssd_conf_uses_ldap" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>SSSD is configured to use LDAP</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:reference ref_id="cpe:/a:sssd-ldap" source="CPE" />
        <ns0:description>Identification provider is not set to ad within /etc/sssd/sssd.conf</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Identification provider is set to ldap within /etc/sssd/sssd.conf" test_ref="test_id_provider_is_set_to_ldap" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="system_boot_mode_is_non_uefi" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Non-UEFI system boot mode check</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:reference ref_id="cpe:/a:non-uefi" source="CPE" />
        <ns0:description>Check if System boot mode is non-UEFI.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:extend_definition negate="true" comment="Pass if System boot mode is non-UEFI" definition_ref="system_boot_mode_is_uefi" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="system_boot_mode_is_uefi" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>UEFI system boot mode check</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:reference ref_id="cpe:/a:uefi" source="CPE" />
        <ns0:description>Check if system boot mode is UEFI.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="check if /sys/firmware/efi folder exists" test_ref="test_efi_dir_existence" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="system_with_kernel" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title />
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>The kernel is installed</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="OR">
        <ns0:criterion comment="kernel is installed" test_ref="inventory_test_kernel_installed" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="accounts_password_pam_faillock" version="1" class="compliance">
      <ns0:metadata>
        <ns0:title>Check pam_faillock Existence in system-auth</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>Check that pam_faillock.so exists in system-auth</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Conditions for pam_faillock are satisfied" test_ref="test_accounts_password_pam_faillock" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="accounts_password_pam_pwquality" version="1" class="compliance">
      <ns0:metadata>
        <ns0:title>Check pam_pwquality Existence in system-auth</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>Check that pam_pwquality.so exists in system-auth</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Conditions for pam_pwquality are satisfied" test_ref="test_password_pam_pwquality" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="audit_rules_auditctl" version="1" class="compliance">
      <ns0:metadata>
        <ns0:title>Test if auditctl is in use for audit rules</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>Test if auditctl is in use for audit rules.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="audit auditctl" test_ref="test_audit_rules_auditctl" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="audit_rules_augenrules" version="1" class="compliance">
      <ns0:metadata>
        <ns0:title>Test if augenrules is enabled for audit rules</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>Test if augenrules is enabled for audit rules.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="audit augenrules" test_ref="test_audit_rules_augenrules" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="audit_rules_networkconfig_modification_domainname" version="1" class="compliance">
      <ns0:metadata>
        <ns0:title>Record Events that Modify the System's Network Environment</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>The network environment should not be modified by anything other than
      administrator action. Any change to network parameters should be audited.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="OR">
        <ns0:criteria operator="AND">
          <ns0:extend_definition comment="audit augenrules" definition_ref="audit_rules_augenrules" />
          <ns0:criterion comment="audit augenrules 32-bit setdomainname" test_ref="test_32bit_setdomainname_augenrules" />
          <ns0:criteria operator="OR">
            <ns0:extend_definition negate="true" comment="64-bit system" definition_ref="system_info_architecture_64bit" />
            <ns0:criterion comment="audit augenrules 64-bit setdomainname" test_ref="test_64bit_setdomainname_augenrules" />
          </ns0:criteria>
        </ns0:criteria>
        <ns0:criteria operator="AND">
          <ns0:extend_definition comment="audit auditctl" definition_ref="audit_rules_auditctl" />
          <ns0:criterion comment="audit auditctl 32-bit setdomainname" test_ref="test_32bit_setdomainname_auditctl" />
          <ns0:criteria operator="OR">
            <ns0:extend_definition negate="true" comment="64-bit system" definition_ref="system_info_architecture_64bit" />
            <ns0:criterion comment="audit auditctl 64-bit setdomainname" test_ref="test_64bit_setdomainname_auditctl" />
          </ns0:criteria>
        </ns0:criteria>
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="audit_rules_networkconfig_modification_hostname" version="1" class="compliance">
      <ns0:metadata>
        <ns0:title>Record Events that Modify the System's Network Environment</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>The network environment should not be modified by anything other than
      administrator action. Any change to network parameters should be audited.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="OR">
        <ns0:criteria operator="AND">
          <ns0:extend_definition comment="audit augenrules" definition_ref="audit_rules_augenrules" />
          <ns0:criterion comment="audit augenrules 32-bit sethostname" test_ref="test_32bit_sethostname_augenrules" />
          <ns0:criteria operator="OR">
            <ns0:extend_definition negate="true" comment="64-bit system" definition_ref="system_info_architecture_64bit" />
            <ns0:criterion comment="audit augenrules 64-bit sethostname" test_ref="test_64bit_sethostname_augenrules" />
          </ns0:criteria>
        </ns0:criteria>
        <ns0:criteria operator="AND">
          <ns0:extend_definition comment="audit auditctl" definition_ref="audit_rules_auditctl" />
          <ns0:criterion comment="audit auditctl 32-bit sethostname" test_ref="test_32bit_sethostname_auditctl" />
          <ns0:criteria operator="OR">
            <ns0:extend_definition negate="true" comment="64-bit system" definition_ref="system_info_architecture_64bit" />
            <ns0:criterion comment="audit auditctl 64-bit sethostname" test_ref="test_64bit_sethostname_auditctl" />
          </ns0:criteria>
        </ns0:criteria>
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="auditd_conf_log_file_not_set" version="1" class="compliance">
      <ns0:metadata>
        <ns0:title>'log_file' Not Set In /etc/audit/auditd.conf</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>Verify 'log_file' is not set in /etc/audit/auditd.conf.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Verify 'log_file' not set in /etc/audit/auditd.conf" test_ref="test_auditd_conf_log_file_not_set" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="auditd_conf_log_group_not_root" version="1" class="compliance">
      <ns0:metadata>
        <ns0:title>'log_group' Not Set To 'root' In /etc/audit/auditd.conf</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>Verify 'log_group' is not set to 'root' in
      /etc/audit/auditd.conf.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Verify 'log_group' not set to 'root' in /etc/audit/auditd.conf" test_ref="test_auditd_conf_log_group_not_root" />
        <ns0:criterion comment="Verify 'log_group' is set in /etc/audit/auditd.conf" test_ref="test_auditd_conf_log_group_is_set" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="bootloader_disable_recovery_set_to_true" version="1" class="compliance">
      <ns0:metadata>
        <ns0:title>Verify GRUB_DISABLE_RECOVERY Set to true</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>GRUB_DISABLE_RECOVERY set to 'true' in
      /etc/default/grub</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Check GRUB_DISABLE_RECOVERY=true in /etc/default/grub" test_ref="test_bootloader_disable_recovery_set_to_true" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="chronyd_specify_multiple_servers" version="1" class="compliance">
      <ns0:metadata>
        <ns0:title>Specify Multiple Remote chronyd NTP Servers for Time Data</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>Multiple chronyd NTP Servers for time synchronization should be specified.</ns0:description>
      </ns0:metadata>
      <ns0:criteria comment="chrony.conf conditions are met" operator="AND">
        <ns0:criterion test_ref="test_chronyd_multiple_servers" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="grub2_default_exists" version="1" class="compliance">
      <ns0:metadata>
        <ns0:title>GRUB_CMDLINE_LINUX_DEFAULT existance check</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>Check if GRUB_CMDLINE_LINUX_DEFAULT exists in /etc/default/grub.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="check for GRUB_CMDLINE_LINUX_DEFAULT exists in /etc/default/grub" test_ref="test_grub2_default_exists" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="grub2_entries_reference_kernelopts" version="2" class="compliance">
      <ns0:metadata>
        <ns0:title>Use $kernelopts in /boot/loader/entries/*.conf</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>Ensure that grubenv-defined kernel options are referenced in individual boot loader entries</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="check kernel command line parameters for referenced boot entries reference the $kernelopts variable." test_ref="test_grub2_entries_reference_kernelopts" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_OS_is_al2023" version="2" class="inventory">
      <ns0:metadata>
        <ns0:title>Amazon Linux 2023</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:reference ref_id="cpe:/o:amazon:amazon_linux:2023" source="CPE" />
        <ns0:description>The operating system installed on the system is Amazon Linux 2023</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:extend_definition comment="Installed OS is part of the Unix family" definition_ref="installed_OS_is_part_of_Unix_family" />
        <ns0:criterion comment="OS is Amazon Linux 2023" test_ref="test_al2023_name" />
        <ns0:criterion comment="OS version is 2023" test_ref="test_al2023_version" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_OS_is_almalinux9" version="3" class="inventory">
      <ns0:metadata>
        <ns0:title>AlmaLinux OS 9</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:reference ref_id="cpe:/o:almalinux:almalinux:9" source="CPE" />
        <ns0:description>The operating system installed on the system is AlmaLinux OS 9</ns0:description>
      </ns0:metadata>
      <ns0:criteria comment="current OS is 9" operator="AND">
        <ns0:extend_definition comment="Installed OS is part of the Unix family" definition_ref="installed_OS_is_part_of_Unix_family" />
        <ns0:criterion comment="AlmaLinux OS is installed" test_ref="test_almalinux" />
        <ns0:criterion comment="AlmaLinux OS 9 is installed" test_ref="test_almalinux9" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_OS_is_anolis23" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Anolis OS 23</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:reference ref_id="cpe:/o:Anolis OS:23" source="CPE" />
        <ns0:description>The operating system installed on the system is Anolis OS 23</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:extend_definition comment="Installed OS is part of the Unix family" definition_ref="installed_OS_is_part_of_Unix_family" />
        <ns0:criterion comment="Anolis OS 23 is installed" test_ref="test_anolis23" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_OS_is_centos10" version="2" class="inventory">
      <ns0:metadata>
        <ns0:title>CentOS Stream 10</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:reference ref_id="cpe:/o:centos:centos:10" source="CPE" />
        <ns0:description>The operating system installed on the system is
      CentOS Stream 10</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:extend_definition comment="Installed OS is part of the Unix family" definition_ref="installed_OS_is_part_of_Unix_family" />
        <ns0:criterion comment="OS is CentOS Stream" test_ref="test_centos10_name" />
        <ns0:criterion comment="OS version is 10" test_ref="test_centos10_version" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_OS_is_centos8" version="2" class="inventory">
      <ns0:metadata>
        <ns0:title>CentOS 8</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:reference ref_id="cpe:/o:centos:centos:8" source="CPE" />
        <ns0:description>The operating system installed on the system is
      CentOS 8</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:extend_definition comment="Installed OS is part of the Unix family" definition_ref="installed_OS_is_part_of_Unix_family" />
        <ns0:criterion comment="OS is CentOS" test_ref="test_centos8_name" />
        <ns0:criterion comment="OS version is 8" test_ref="test_centos8_version" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_OS_is_centos9" version="2" class="inventory">
      <ns0:metadata>
        <ns0:title>CentOS Stream 9</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:reference ref_id="cpe:/o:centos:centos:9" source="CPE" />
        <ns0:description>The operating system installed on the system is
      CentOS Stream 9</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:extend_definition comment="Installed OS is part of the Unix family" definition_ref="installed_OS_is_part_of_Unix_family" />
        <ns0:criterion comment="OS is CentOS Stream" test_ref="test_centos9_name" />
        <ns0:criterion comment="OS version is 9" test_ref="test_centos9_version" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_OS_is_debian" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Debian</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>The operating system installed is a Debian System</ns0:description>
      </ns0:metadata>
      <ns0:criteria comment="System is Debian" operator="AND">
        <ns0:extend_definition comment="Installed OS is part of the Unix family" definition_ref="installed_OS_is_part_of_Unix_family" />
        <ns0:criterion comment="Debian is installed" test_ref="test_debian" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_OS_is_fedora" version="3" class="inventory">
      <ns0:metadata>
        <ns0:title>Installed operating system is Fedora</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:reference ref_id="cpe:/o:fedoraproject:fedora:36" source="CPE" />
        <ns0:reference ref_id="cpe:/o:fedoraproject:fedora:37" source="CPE" />
        <ns0:reference ref_id="cpe:/o:fedoraproject:fedora:38" source="CPE" />
        <ns0:reference ref_id="cpe:/o:fedoraproject:fedora:39" source="CPE" />
        <ns0:reference ref_id="cpe:/o:fedoraproject:fedora:40" source="CPE" />
        <ns0:description>The operating system installed on the system is Fedora</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:extend_definition comment="Installed OS is part of the Unix family" definition_ref="installed_OS_is_part_of_Unix_family" />
        <ns0:criterion comment="fedora-release RPM packages are installed" test_ref="test_fedora_release_rpm" />
        <ns0:criterion comment="CPE vendor is 'fedoraproject' and product is 'fedora'" test_ref="test_fedora_vendor_product" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_OS_is_kylinserver10" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Kylin Server 10</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>The operating system installed on the system is Kylin Server 10.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Kylin Server 10 is installed" test_ref="test_kylinserver10_installed" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_OS_is_oeharden" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>OE Harden</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>The operating system installed is an OE Harden based System</ns0:description>
      </ns0:metadata>
      <ns0:criteria comment="System is OE Harden based distribution" operator="AND">
        <ns0:extend_definition comment="Installed OS is part of the Unix family" definition_ref="installed_OS_is_part_of_Unix_family" />
        <ns0:criterion comment="OE Harden based distro" test_ref="test_os_oeharden" />
        <ns0:criterion comment="OE Harden based distribution is installed" test_ref="test_oeharden" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_os_is_ol" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title />
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>Installed OS is OL</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="The operating system installed on the system is OL" test_ref="test_os_id_is_ol" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_OS_is_ol10" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Oracle Linux 10</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:reference ref_id="cpe:/o:oracle:linux:10" source="CPE" />
        <ns0:description>The operating system installed on the system is
      Oracle Linux 10</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:extend_definition comment="Installed OS is part of the Unix family" definition_ref="installed_OS_is_part_of_Unix_family" />
        <ns0:criteria operator="OR">
          <ns0:criterion comment="Oracle Linux 10 System is installed" test_ref="test_ol10_system" />
        </ns0:criteria>
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_OS_is_ol7" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Oracle Linux 7</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:reference ref_id="cpe:/o:oracle:linux:7" source="CPE" />
        <ns0:description>The operating system installed on the system is
      Oracle Linux 7</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:extend_definition comment="Installed OS is part of the Unix family" definition_ref="installed_OS_is_part_of_Unix_family" />
        <ns0:criteria operator="OR">
          <ns0:criterion comment="Oracle Linux 7 System is installed" test_ref="test_ol7_system" />
        </ns0:criteria>
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_OS_is_ol8" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Oracle Linux 8</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:reference ref_id="cpe:/o:oracle:linux:8" source="CPE" />
        <ns0:description>The operating system installed on the system is
      Oracle Linux 8</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:extend_definition comment="Installed OS is part of the Unix family" definition_ref="installed_OS_is_part_of_Unix_family" />
        <ns0:criteria operator="OR">
          <ns0:criterion comment="Oracle Linux 8 System is installed" test_ref="test_ol8_system" />
        </ns0:criteria>
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_OS_is_ol9" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Oracle Linux 9</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:reference ref_id="cpe:/o:oracle:linux:9" source="CPE" />
        <ns0:description>The operating system installed on the system is
      Oracle Linux 9</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:extend_definition comment="Installed OS is part of the Unix family" definition_ref="installed_OS_is_part_of_Unix_family" />
        <ns0:criteria operator="OR">
          <ns0:criterion comment="Oracle Linux 9 System is installed" test_ref="test_ol9_system" />
        </ns0:criteria>
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_OS_is_openembedded" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>OpenEmbedded</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>The operating system installed is an OpenEmbedded based system</ns0:description>
      </ns0:metadata>
      <ns0:criteria comment="System is OpenEmbedded based" operator="AND">
        <ns0:extend_definition comment="Installed OS is part of the Unix family" definition_ref="installed_OS_is_part_of_Unix_family" />
        <ns0:criterion comment="OpenEmbedded distro" test_ref="test_os_openembedded" />
        <ns0:criterion comment="OpenEmbedded is installed" test_ref="test_openembedded" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_OS_is_openeuler2203" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>openEuler 22.03 LTS</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>The operating system installed on the system is openEuler 22.03 LTS.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="openEuler 22.03 LTS is installed" test_ref="test_openeuler2203_installed" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_OS_is_opensuse" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>openSUSE</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>The operating system installed on the system is openSUSE.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:extend_definition comment="Installed OS is part of the Unix family" definition_ref="installed_OS_is_part_of_Unix_family" />
        <ns0:criterion comment="openSUSE is installed" test_ref="test_opensuse_installed" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_OS_is_opensuse_leap15" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>openSUSE Leap 15</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:reference ref_id="cpe:/o:opensuse:leap:15" source="CPE" />
        <ns0:description>The operating system installed on the system is openSUSE Leap 15.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:extend_definition comment="Installed OS is part of the Unix family" definition_ref="installed_OS_is_part_of_Unix_family" />
        <ns0:criterion comment="openSUSE Leap 15 is installed" test_ref="test_opensuse_leap15_installed" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_OS_is_opensuse_leap16" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>openSUSE Leap 16</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:reference ref_id="cpe:/o:opensuse:leap:16" source="CPE" />
        <ns0:description>The operating system installed on the system is openSUSE Leap 16.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:extend_definition comment="Installed OS is part of the Unix family" definition_ref="installed_OS_is_part_of_Unix_family" />
        <ns0:criterion comment="openSUSE Leap 16 is installed" test_ref="test_opensuse_leap16_installed" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_OS_is_part_of_Unix_family" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Installed operating system is part of the Unix family</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>The operating system installed on the system is part of the Unix OS family</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Installed operating system is part of the unix family" test_ref="test_unix_family" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_OS_is_petalinux" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Petalinux</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>The operating system installed is a Petalinux based System</ns0:description>
      </ns0:metadata>
      <ns0:criteria comment="System is Petalinux based distribution" operator="AND">
        <ns0:extend_definition comment="Installed OS is part of the Unix family" definition_ref="installed_OS_is_part_of_Unix_family" />
        <ns0:criterion comment="Petalinux based distro" test_ref="test_os_petalinux" />
        <ns0:criterion comment="Petalinux based distribution is installed" test_ref="test_petalinux" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_OS_is_poky" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Poky</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>The operating system installed is a Poky based System</ns0:description>
      </ns0:metadata>
      <ns0:criteria comment="System is Poky based distribution" operator="AND">
        <ns0:extend_definition comment="Installed OS is part of the Unix family" definition_ref="installed_OS_is_part_of_Unix_family" />
        <ns0:criterion comment="Poky based distro" test_ref="test_os_poky" />
        <ns0:criterion comment="Poky based distribution is installed" test_ref="test_poky" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_OS_is_rhcos4" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Red Hat Enterprise Linux CoreOS</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:reference ref_id="cpe:/o:redhat:enterprise_linux_coreos:4" source="CPE" />
        <ns0:description>The operating system installed on the system is
      Red Hat Enterprise Linux CoreOS release 4</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="OR">
        <ns0:criteria operator="AND">
          <ns0:criterion comment="CoreOS variant" test_ref="test_rhel_coreos_variant" />
          <ns0:criterion comment="RHCOS version 4 is installed" test_ref="test_rhcos4" />
        </ns0:criteria>
        <ns0:criteria operator="AND">
          <ns0:criterion comment="RHCOS is installed (ID='rhcos')" test_ref="test_rhcos" />
          <ns0:criterion comment="RHEL_VERSION is 8" test_ref="test_rhcos4_rhel8_rhel_version" />
        </ns0:criteria>
        <ns0:criteria operator="AND">
          <ns0:criterion comment="RHCOS is installed (ID='rhcos')" test_ref="test_rhcos" />
          <ns0:criterion comment="RHEL_VERSION is 9" test_ref="test_rhcos4_rhel9_rhel_version" />
        </ns0:criteria>
        <ns0:criteria operator="AND">
          <ns0:criterion comment="ID is rhel" test_ref="test_rhel_id" />
          <ns0:criterion comment="Major version is 9" test_ref="test_rhel_coreos_version9" />
        </ns0:criteria>
        <ns0:criteria operator="AND">
          <ns0:criterion comment="ID is rhel" test_ref="test_rhel_id" />
          <ns0:criterion comment="Major version is 10" test_ref="test_rhel_coreos_version10" />
        </ns0:criteria>
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_OS_is_rhcos4_rhel8" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Red Hat Enterprise Linux CoreOS RHEL8 Based</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:reference ref_id="cpe:/o:redhat:rhcos4:8" source="CPE" />
        <ns0:description>The operating system installed on the system is
      Red Hat Enterprise Linux CoreOS RHEL8 Based</ns0:description>
      </ns0:metadata>
      <ns0:criteria comment="Old format: ID=rhcos with RHEL_VERSION=8.x" operator="AND">
        <ns0:criterion comment="ID is rhcos" test_ref="test_rhcos" />
        <ns0:criterion comment="RHEL_VERSION is 8" test_ref="test_rhcos4_rhel8_rhel_version" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_OS_is_rhcos4_rhel9" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Red Hat Enterprise Linux CoreOS RHEL9 Based</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:reference ref_id="cpe:/o:redhat:rhcos4:9" source="CPE" />
        <ns0:description>The operating system installed on the system is
      Red Hat Enterprise Linux CoreOS RHEL9 Based</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="OR">
        <ns0:criteria comment="Old format: ID=rhcos with RHEL_VERSION=9.x" operator="AND">
          <ns0:criterion comment="ID is rhcos" test_ref="test_rhcos" />
          <ns0:criterion comment="RHEL_VERSION is 9" test_ref="test_rhcos4_rhel9_rhel_version" />
        </ns0:criteria>
        <ns0:criteria comment="New format: ID=rhel with VERSION_ID=9.x" operator="AND">
          <ns0:criterion comment="ID is rhel" test_ref="test_rhel_id" />
          <ns0:criterion comment="CoreOS variant" test_ref="test_rhel_coreos_variant" />
          <ns0:criterion comment="VERSION_ID is 9.x" test_ref="test_rhel_coreos_version9" />
        </ns0:criteria>
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_OS_is_rhcos4_rhel10" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Red Hat Enterprise Linux CoreOS RHEL10 Based</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:reference ref_id="cpe:/o:redhat:rhcos4:10" source="CPE" />
        <ns0:description>The operating system installed on the system is
      Red Hat Enterprise Linux CoreOS RHEL10 Based</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="ID is rhel" test_ref="test_rhel_id" />
        <ns0:criterion comment="CoreOS variant" test_ref="test_rhel_coreos_variant" />
        <ns0:criterion comment="VERSION_ID is 10.x" test_ref="test_rhel_coreos_version10" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_os_is_rhel" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title />
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>Installed OS is RHEL</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="The operating system installed on the system is RHEL" test_ref="test_os_id_is_rhel" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_OS_is_rhel10" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Red Hat Enterprise Linux 10</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:reference ref_id="cpe:/o:redhat:enterprise_linux:10" source="CPE" />
        <ns0:description>The operating system installed on the system is
      Red Hat Enterprise Linux 10</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Installed operating system is part of the unix family" test_ref="test_rhel10_unix_family" />
        <ns0:criteria operator="OR">
          <ns0:criterion comment="RHEL 10 is installed" test_ref="test_rhel10" />
          <ns0:criteria comment="Red Hat Enterprise Virtualization Host is installed" operator="AND">
            <ns0:criterion comment="Red Hat Virtualization Host (RHVH)" test_ref="test_rhvh4_version" />
            <ns0:criterion comment="Red Hat Enterprise Virtualization Host is based on RHEL 10" test_ref="test_rhevh_rhel10_version" />
          </ns0:criteria>
        </ns0:criteria>
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_OS_is_rhel8" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Red Hat Enterprise Linux 8</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:reference ref_id="cpe:/o:redhat:enterprise_linux:8" source="CPE" />
        <ns0:description>The operating system installed on the system is
      Red Hat Enterprise Linux 8</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Installed operating system is part of the unix family" test_ref="test_rhel8_unix_family" />
        <ns0:criteria operator="OR">
          <ns0:criteria comment="RHEL 8 is installed" operator="AND">
            <ns0:criterion comment="RHEL 8 is installed" test_ref="test_rhel8" />
            <ns0:extend_definition negate="true" comment="Installed OS is not OL8" definition_ref="installed_OS_is_ol8" />
          </ns0:criteria>
          <ns0:criteria comment="Red Hat Enterprise Virtualization Host is installed" operator="AND">
            <ns0:criterion comment="Red Hat Virtualization Host (RHVH)" test_ref="test_rhvh4_version" />
            <ns0:criterion comment="Red Hat Enterprise Virtualization Host is based on RHEL 8" test_ref="test_rhevh_rhel8_version" />
          </ns0:criteria>
        </ns0:criteria>
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_OS_is_rhel8_0" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Red Hat Enterprise Linux 8.0</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:reference ref_id="cpe:/o:redhat:enterprise_linux:8.0" source="CPE" />
        <ns0:description>The operating system installed on the system is Red Hat Enterprise Linux 8.0</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="RHEL 8.0 is installed" test_ref="test_rhel8_0" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_OS_is_rhel8_1" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Red Hat Enterprise Linux 8.1</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:reference ref_id="cpe:/o:redhat:enterprise_linux:8.1" source="CPE" />
        <ns0:description>The operating system installed on the system is Red Hat Enterprise Linux 8.1</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="RHEL 8.1 is installed" test_ref="test_rhel8_1" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_OS_is_rhel8_2" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Red Hat Enterprise Linux 8.2</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:reference ref_id="cpe:/o:redhat:enterprise_linux:8.2" source="CPE" />
        <ns0:description>The operating system installed on the system is Red Hat Enterprise Linux 8.2</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="RHEL 8.2 is installed" test_ref="test_rhel8_2" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_OS_is_rhel8_3" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Red Hat Enterprise Linux 8.3</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:reference ref_id="cpe:/o:redhat:enterprise_linux:8.3" source="CPE" />
        <ns0:description>The operating system installed on the system is Red Hat Enterprise Linux 8.3</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="RHEL 8.3 is installed" test_ref="test_rhel8_3" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_OS_is_rhel8_4" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Red Hat Enterprise Linux 8.4</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:reference ref_id="cpe:/o:redhat:enterprise_linux:8.4" source="CPE" />
        <ns0:description>The operating system installed on the system is Red Hat Enterprise Linux 8.4</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="RHEL 8.4 is installed" test_ref="test_rhel8_4" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_OS_is_rhel8_5" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Red Hat Enterprise Linux 8.5</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:reference ref_id="cpe:/o:redhat:enterprise_linux:8.5" source="CPE" />
        <ns0:description>The operating system installed on the system is Red Hat Enterprise Linux 8.5</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="RHEL 8.5 is installed" test_ref="test_rhel8_5" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_OS_is_rhel8_6" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Red Hat Enterprise Linux 8.6</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:reference ref_id="cpe:/o:redhat:enterprise_linux:8.6" source="CPE" />
        <ns0:description>The operating system installed on the system is Red Hat Enterprise Linux 8.6</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="RHEL 8.6 is installed" test_ref="test_rhel8_6" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_OS_is_rhel8_7" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Red Hat Enterprise Linux 8.7</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:reference ref_id="cpe:/o:redhat:enterprise_linux:8.7" source="CPE" />
        <ns0:description>The operating system installed on the system is Red Hat Enterprise Linux 8.7</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="RHEL 8.7 is installed" test_ref="test_rhel8_7" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_OS_is_rhel8_8" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Red Hat Enterprise Linux 8.8</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:reference ref_id="cpe:/o:redhat:enterprise_linux:8.8" source="CPE" />
        <ns0:description>The operating system installed on the system is Red Hat Enterprise Linux 8.8</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="RHEL 8.8 is installed" test_ref="test_rhel8_8" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_OS_is_rhel8_9" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Red Hat Enterprise Linux 8.9</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:reference ref_id="cpe:/o:redhat:enterprise_linux:8.9" source="CPE" />
        <ns0:description>The operating system installed on the system is Red Hat Enterprise Linux 8.9</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="RHEL 8.9 is installed" test_ref="test_rhel8_9" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_OS_is_rhel8_10" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Red Hat Enterprise Linux 8.10</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:reference ref_id="cpe:/o:redhat:enterprise_linux:8.10" source="CPE" />
        <ns0:description>The operating system installed on the system is Red Hat Enterprise Linux 8.10</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="RHEL 8.10 is installed" test_ref="test_rhel8_10" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_OS_is_rhel9" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Red Hat Enterprise Linux 9</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:reference ref_id="cpe:/o:redhat:enterprise_linux:9" source="CPE" />
        <ns0:description>The operating system installed on the system is
      Red Hat Enterprise Linux 9</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Installed operating system is part of the unix family" test_ref="test_rhel9_unix_family" />
        <ns0:criteria operator="OR">
          <ns0:criteria comment="RHEL 9 is installed" operator="AND">
            <ns0:criterion comment="RHEL 9 is installed" test_ref="test_rhel9" />
            <ns0:extend_definition negate="true" comment="Installed OS is not OL9" definition_ref="installed_OS_is_ol9" />
          </ns0:criteria>
          <ns0:criteria comment="Red Hat Enterprise Virtualization Host is installed" operator="AND">
            <ns0:criterion comment="Red Hat Virtualization Host (RHVH)" test_ref="test_rhvh4_version" />
            <ns0:criterion comment="Red Hat Enterprise Virtualization Host is based on RHEL 9" test_ref="test_rhevh_rhel9_version" />
          </ns0:criteria>
        </ns0:criteria>
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_OS_is_rhv4" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Red Hat Virtualization 4</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:reference ref_id="cpe:/o:redhat:virtualization:4" source="CPE" />
        <ns0:description>The operating system installed on the system is
      Red Hat Virtualization Host 4.4+ or Red Hat Enterprise Host.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="OR">
        <ns0:extend_definition comment="RHEL8 OS installed" definition_ref="installed_OS_is_rhel8" />
        <ns0:criterion comment="Red Hat Virtualization Host (RHVH)" test_ref="test_rhvh4_version" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_OS_is_sle12" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>SUSE Linux Enterprise 12</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:reference ref_id="cpe:/o:suse:linux_enterprise_server:12" source="CPE" />
        <ns0:reference ref_id="cpe:/o:suse:linux_enterprise_desktop:12" source="CPE" />
        <ns0:description>The operating system installed on the system is
      SUSE Linux Enterprise 12.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Installed operating system is part of the unix family" test_ref="test_sle12_unix_family" />
        <ns0:criteria operator="OR">
          <ns0:criterion comment="SLE 12 Desktop is installed" test_ref="test_sle12_desktop" />
          <ns0:criterion comment="SLE 12 Server is installed" test_ref="test_sle12_server" />
          <ns0:criterion comment="SLES 12 for SAP Applications is installed" test_ref="test_sles_12_for_sap" />
        </ns0:criteria>
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_OS_is_sle15" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>SUSE Linux Enterprise 15</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:reference ref_id="cpe:/o:suse:linux_enterprise_server:15" source="CPE" />
        <ns0:reference ref_id="cpe:/o:suse:linux_enterprise_desktop:15" source="CPE" />
        <ns0:description>The operating system installed on the system is
      SUSE Linux Enterprise 15.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Installed operating system is part of the unix family" test_ref="test_sle15_unix_family" />
        <ns0:criteria operator="OR">
          <ns0:criterion comment="SLE 15 Desktop is installed" test_ref="test_sle15_desktop" />
          <ns0:criterion comment="SLE 15 Server is installed" test_ref="test_sle15_server" />
          <ns0:criterion comment="SLES 15 for SAP Applications is installed" test_ref="test_sles_15_for_sap" />
          <ns0:criterion comment="SUSE Manager 4 is installed" test_ref="test_suma_4" />
          <ns0:criterion comment="SLE HPC is installed" test_ref="test_sle_hpc" />
        </ns0:criteria>
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_OS_is_sle16" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>SUSE Linux Enterprise 16</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:reference ref_id="cpe:/o:suse:linux_enterprise_server:16" source="CPE" />
        <ns0:description>The operating system installed on the system is SUSE Linux Enterprise Server 16.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Installed operating system is part of the unix family" test_ref="test_sle16_unix_family" />
        <ns0:criteria operator="OR">
          <ns0:criterion comment="SLE 16 Server is installed" test_ref="test_sle16_server" />
          <ns0:criterion comment="SLES 16 for SAP Applications is installed" test_ref="test_sles_16_for_sap" />
          <ns0:criterion comment="SLES 16 for High Availability Extension is installed" test_ref="test_sles_16_for_ha" />
        </ns0:criteria>
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_OS_is_slmicro5" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>SUSE Linux Enterprise Micro</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:reference ref_id="cpe:/o:suse:suse-microos:5.2" source="CPE" />
        <ns0:reference ref_id="cpe:/o:suse:sle-micro:5.3" source="CPE" />
        <ns0:reference ref_id="cpe:/o:suse:sle-micro:5.4" source="CPE" />
        <ns0:reference ref_id="cpe:/o:suse:sle-micro:5.5" source="CPE" />
        <ns0:description>The operating system installed on the system is
                SUSE Linux Enterprise Micro.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Installed operating system is part of the unix family" test_ref="test_slmicro5_unix_family" />
        <ns0:criteria operator="OR">
          <ns0:criterion comment="SUSE MicroOS 5.* is installed" test_ref="test_slmicroos5" />
          <ns0:criterion comment="SLE Micro 5.* is installed" test_ref="test_slmicro5" />
        </ns0:criteria>
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_OS_is_slmicro6" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>SUSE Linux Enterprise Micro</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:reference ref_id="cpe:/o:suse:sl-micro:6.0" source="CPE" />
        <ns0:reference ref_id="cpe:/o:suse:sl-micro:6.1" source="CPE" />
        <ns0:description>The operating system installed on the system is
                SUSE Linux Micro.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Installed operating system is part of the unix family" test_ref="test_slmicro6_unix_family" />
        <ns0:criteria operator="OR">
          <ns0:criterion comment="SLE Micro 6.* is installed" test_ref="test_slmicro6" />
        </ns0:criteria>
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_OS_is_tencentos4" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>TencentOS Server 4</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:reference ref_id="cpe:/o:tencentos:tencentos_server:4" source="CPE" />
        <ns0:description>The operating system installed on the system is TencentOS Server 4</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:extend_definition comment="Installed OS is part of the Unix family" definition_ref="installed_OS_is_part_of_Unix_family" />
        <ns0:criterion comment="TencentOS Server 4 is installed" test_ref="test_tencentos4" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_OS_is_ubuntu" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Ubuntu</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>The operating system installed is an Ubuntu System</ns0:description>
      </ns0:metadata>
      <ns0:criteria comment="System is Ubuntu" operator="AND">
        <ns0:extend_definition comment="Installed OS is part of the Unix family" definition_ref="installed_OS_is_part_of_Unix_family" />
        <ns0:criterion comment="lsb-based distrib" test_ref="test_lsb" />
        <ns0:criterion comment="Ubuntu is installed" test_ref="test_ubuntu" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_OS_is_ubuntu2204" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Ubuntu 22.04 LTS</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:reference ref_id="cpe:/o:canonical:ubuntu_linux:22.04" source="CPE" />
        <ns0:description>The operating system installed on the system is Ubuntu 22.04 LTS</ns0:description>
      </ns0:metadata>
      <ns0:criteria comment="current Ubuntu version is Jammy" operator="AND">
        <ns0:extend_definition comment="Ubuntu is installed" definition_ref="installed_OS_is_ubuntu" />
        <ns0:criterion comment="Jammy is installed" test_ref="test_ubuntu_jammy" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_OS_is_ubuntu2404" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Ubuntu 24.04 LTS</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:reference ref_id="cpe:/o:canonical:ubuntu_linux:24.04" source="CPE" />
        <ns0:description>The operating system installed on the system is Ubuntu 24.04 LTS</ns0:description>
      </ns0:metadata>
      <ns0:criteria comment="current Ubuntu version is Noble" operator="AND">
        <ns0:extend_definition comment="Ubuntu is installed" definition_ref="installed_OS_is_ubuntu" />
        <ns0:criterion comment="Noble is installed" test_ref="test_ubuntu_noble" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_env_has_zipl_package" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>System uses zIPL</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:reference ref_id="cpe:/a:zipl" source="CPE" />
        <ns0:description>Checks if system uses zIPL bootloader.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Package s390utils-base is installed" test_ref="test_env_has_zipl_installed" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_env_is_osbuild" version="2" class="inventory">
      <ns0:metadata>
        <ns0:title>Check if the environment is a OSBuild pipeline</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:reference ref_id="cpe:/a:osbuild" source="CPE" />
        <ns0:description>Check the value of environment variable container.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Check the value of container variable" test_ref="test_installed_env_is_osbuild" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="no_cd_dvd_drive_in_etc_fstab" version="1" class="compliance">
      <ns0:metadata>
        <ns0:title>No CD/DVD drive is configured to automount in /etc/fstab</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>Check the /etc/fstab and check if a CD/DVD drive
      is not configured for automount.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Check if CD/DVD drive is not configured to automout in /etc/fstab" test_ref="test_no_cd_dvd_drive_in_etc_fstab" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="removable_partition_doesnt_exist" version="1" class="compliance">
      <ns0:metadata>
        <ns0:title>Device Files for Removable Media Partitions Does Not Exist on the System</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>Verify if device file representing removable partitions
      exist on the system</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Check if removable partition really exists on the system" test_ref="test_removable_partition_doesnt_exist" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="sshd_not_required_or_unset" version="1" class="compliance">
      <ns0:metadata>
        <ns0:title>SSHD is not required to be installed or requirement not set</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>If SSHD is not required, we check it is not installed. If SSH requirement is unset, we are good.</ns0:description>
      </ns0:metadata>
      <ns0:criteria comment="SSH not required or not set" operator="OR">
        <ns0:criterion test_ref="test_sshd_not_required" />
        <ns0:extend_definition comment="SSH requirement is unset" definition_ref="sshd_requirement_unset" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="sshd_required_or_unset" version="1" class="compliance">
      <ns0:metadata>
        <ns0:title>SSHD is required to be installed or requirement not set</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>If SSHD is required, we check it is installed. If SSH requirement is unset, we are good.</ns0:description>
      </ns0:metadata>
      <ns0:criteria comment="SSH required or not set" operator="OR">
        <ns0:criterion test_ref="test_sshd_required" />
        <ns0:extend_definition comment="SSH requirement is unset" definition_ref="sshd_requirement_unset" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="sshd_requirement_unset" version="1" class="compliance">
      <ns0:metadata>
        <ns0:title>It doesn't matter if sshd is installed or not</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>Test if value sshd_required is 0.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion test_ref="test_sshd_requirement_unset" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="sshd_version_equal_or_higher_than_74" version="1" class="compliance">
      <ns0:metadata>
        <ns0:title>OpenSSH Server is 7.4 or newer</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>Check if version of OpenSSH Server is equal or higher than 7.4</ns0:description>
      </ns0:metadata>
      <ns0:criteria comment="OpenSSH Server version is equal or higher than 7.4" operator="OR">
        <ns0:criterion comment="Check if OpenSSH Server is equal or higher than 7.4" test_ref="test_openssh-server_version" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="sysctl_kernel_ipv6_disable" version="2" class="compliance">
      <ns0:metadata>
        <ns0:title>Kernel Runtime Parameter IPv6 Check</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>Disables IPv6 for all network interfaces.</ns0:description>
      </ns0:metadata>
      <ns0:criteria comment="IPv6 disabled or net.ipv6.conf.all.disable_ipv6 set correctly" operator="OR">
        <ns0:criteria operator="AND">
          <ns0:extend_definition comment="net.ipv6.conf.all.disable_ipv6 configuration setting check" definition_ref="sysctl_net_ipv6_conf_all_disable_ipv6_static" />
          <ns0:extend_definition comment="net.ipv6.conf.all.disable_ipv6 runtime setting check" definition_ref="sysctl_net_ipv6_conf_all_disable_ipv6_runtime" />
        </ns0:criteria>
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="system_info_architecture_64bit" version="1" class="compliance">
      <ns0:metadata>
        <ns0:title>Test for 64-bit Architecture</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>Generic test for 64-bit architectures to be used by other tests</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="OR">
        <ns0:extend_definition comment="Generic test for x86_64 architecture" definition_ref="system_info_architecture_x86_64" />
        <ns0:extend_definition comment="Generic test for ppc64 architecture" definition_ref="system_info_architecture_ppc_64" />
        <ns0:extend_definition comment="Generic test for aarch64 architecture" definition_ref="system_info_architecture_aarch_64" />
        <ns0:extend_definition comment="Generic test for s390x architecture" definition_ref="system_info_architecture_s390_64" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="system_info_architecture_aarch_64" version="1" class="compliance">
      <ns0:metadata>
        <ns0:title>Test for aarch_64 Architecture</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>Generic test for aarch_64 architecture to be used by other tests</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Generic test for aarch_64 architecture" test_ref="test_system_info_architecture_aarch_64" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="system_info_architecture_ppc_64" version="1" class="compliance">
      <ns0:metadata>
        <ns0:title>Test for PPC and PPCLE Architecture</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>Generic test for PPC PPC64LE architecture to be used by other tests</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="OR">
        <ns0:criterion comment="Generic test for ppc64 architecture" test_ref="test_system_info_architecture_ppc_64" />
        <ns0:criterion comment="Generic test for ppcle64 architecture" test_ref="test_system_info_architecture_ppcle_64" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="system_info_architecture_s390_64" version="1" class="compliance">
      <ns0:metadata>
        <ns0:title>Test for s390_64 Architecture</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>Generic test for s390_64 architecture to be used by other tests</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Generic test for s390_64 architecture" test_ref="test_system_info_architecture_s390_64" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="system_info_architecture_x86" version="1" class="compliance">
      <ns0:metadata>
        <ns0:title>Test for x86 Architecture</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>Generic test for x86 architecture to be used by other tests</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Generic test for x86 architecture" test_ref="test_system_info_architecture_x86" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="system_info_architecture_x86_64" version="1" class="compliance">
      <ns0:metadata>
        <ns0:title>Test for x86_64 Architecture</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>Generic test for x86_64 architecture to be used by other tests</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Generic test for x86_64 architecture" test_ref="test_system_info_architecture_x86_64" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="tmux_conf_readable_by_others" version="1" class="compliance">
      <ns0:metadata>
        <ns0:title />
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>Check /etc/tmux.conf is readable by others</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Check /etc/tmux.conf is readable by others" test_ref="test_tmux_conf_readable_by_others" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="usbguard_rules_not_empty_not_missing" version="1" class="compliance">
      <ns0:metadata>
        <ns0:title>Check that file storing USBGuard rules exists and is not empty</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>Check that file storing USBGuard rules at /etc/usbguard/rules.conf exists and is not empty</ns0:description>
      </ns0:metadata>
      <ns0:criteria comment="Check that file storing USBGuard rules exists and is not empty" operator="AND">
        <ns0:criterion comment="Check that the usbguard rules in either /etc/usbguard/rules.conf or /etc/usbguard/rules.d/ contain at least one non white space character." test_ref="test_usbguard_rules_nonempty" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="var_accounts_user_umask_as_number" version="1" class="compliance">
      <ns0:metadata>
        <ns0:title>Value of 'var_accounts_user_umask' variable represented as octal number</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>Value of 'var_accounts_user_umask' variable represented as octal number</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion test_ref="test_existence_of_var_accounts_user_umask_as_number_variable" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="var_removable_partition_is_cd_dvd_drive" version="1" class="compliance">
      <ns0:metadata>
        <ns0:title>Value of 'var_removable_partition' variable is set to '/dev/cdrom'</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>Verify if value of 'var_removable_partition' variable is set
      to '/dev/cdrom'</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Check if removable partition value represents CD/DVD drive" test_ref="test_var_removable_partition_is_cd_dvd_drive" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="var_umask_for_daemons_as_number" version="1" class="compliance">
      <ns0:metadata>
        <ns0:title>Value of 'var_umask_for_daemons' variable represented as octal number</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>Value of 'var_umask_for_daemons' variable represented as octal number</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion test_ref="test_existence_of_var_umask_for_daemons_as_number_variable" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="ipv6_enabled" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>IPv6 is enabled on system</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description />
      </ns0:metadata>
      <ns0:criteria operator="OR">
        <ns0:criterion comment="check if ipv6.disable argument is correct in GRUB_CMDLINE_LINUX" test_ref="test_grub2_ipv6_disable_is_correct" />
        <ns0:criterion comment="check if ipv6.disable parameter is defined in /etc/default/grub" test_ref="test_grub2_ipv6_disable_is_absent" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_env_mount_boot-efi" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Mountpoint /boot/efi is active (mounted) or configured in /etc/fstab</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description />
      </ns0:metadata>
      <ns0:criteria operator="OR">
        <ns0:criteria operator="AND">
          <ns0:criterion comment="The path /boot/efi is an active (mounted) mount point" test_ref="test_mount_active_boot_efi_exists" />
        </ns0:criteria>
        <ns0:criteria operator="AND">
          <ns0:criterion comment="The path /boot/efi is a mount point configured in /etc/fstab" test_ref="test_mount_configured_fstab_boot_efi_exists" />
        </ns0:criteria>
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_env_mount_home" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Mountpoint /home is active (mounted) or configured in /etc/fstab</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description />
      </ns0:metadata>
      <ns0:criteria operator="OR">
        <ns0:criteria operator="AND">
          <ns0:criterion comment="The path /home is an active (mounted) mount point" test_ref="test_mount_active_home_exists" />
        </ns0:criteria>
        <ns0:criteria operator="AND">
          <ns0:criterion comment="The path /home is a mount point configured in /etc/fstab" test_ref="test_mount_configured_fstab_home_exists" />
        </ns0:criteria>
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_env_mount_opt" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Mountpoint /opt is active (mounted) or configured in /etc/fstab</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description />
      </ns0:metadata>
      <ns0:criteria operator="OR">
        <ns0:criteria operator="AND">
          <ns0:criterion comment="The path /opt is an active (mounted) mount point" test_ref="test_mount_active_opt_exists" />
        </ns0:criteria>
        <ns0:criteria operator="AND">
          <ns0:criterion comment="The path /opt is a mount point configured in /etc/fstab" test_ref="test_mount_configured_fstab_opt_exists" />
        </ns0:criteria>
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_env_mount_srv" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Mountpoint /srv is active (mounted) or configured in /etc/fstab</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description />
      </ns0:metadata>
      <ns0:criteria operator="OR">
        <ns0:criteria operator="AND">
          <ns0:criterion comment="The path /srv is an active (mounted) mount point" test_ref="test_mount_active_srv_exists" />
        </ns0:criteria>
        <ns0:criteria operator="AND">
          <ns0:criterion comment="The path /srv is a mount point configured in /etc/fstab" test_ref="test_mount_configured_fstab_srv_exists" />
        </ns0:criteria>
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_env_mount_tmp" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Mountpoint /tmp is active (mounted) or configured in /etc/fstab</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description />
      </ns0:metadata>
      <ns0:criteria operator="OR">
        <ns0:criteria operator="AND">
          <ns0:criterion comment="The path /tmp is an active (mounted) mount point" test_ref="test_mount_active_tmp_exists" />
        </ns0:criteria>
        <ns0:criteria operator="AND">
          <ns0:criterion comment="The path /tmp is a mount point configured in /etc/fstab" test_ref="test_mount_configured_fstab_tmp_exists" />
        </ns0:criteria>
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_env_mount_var-log-audit" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Mountpoint /var/log/audit is active (mounted) or configured in /etc/fstab</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description />
      </ns0:metadata>
      <ns0:criteria operator="OR">
        <ns0:criteria operator="AND">
          <ns0:criterion comment="The path /var/log/audit is an active (mounted) mount point" test_ref="test_mount_active_var_log_audit_exists" />
        </ns0:criteria>
        <ns0:criteria operator="AND">
          <ns0:criterion comment="The path /var/log/audit is a mount point configured in /etc/fstab" test_ref="test_mount_configured_fstab_var_log_audit_exists" />
        </ns0:criteria>
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_env_mount_var-log" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Mountpoint /var/log is active (mounted) or configured in /etc/fstab</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description />
      </ns0:metadata>
      <ns0:criteria operator="OR">
        <ns0:criteria operator="AND">
          <ns0:criterion comment="The path /var/log is an active (mounted) mount point" test_ref="test_mount_active_var_log_exists" />
        </ns0:criteria>
        <ns0:criteria operator="AND">
          <ns0:criterion comment="The path /var/log is a mount point configured in /etc/fstab" test_ref="test_mount_configured_fstab_var_log_exists" />
        </ns0:criteria>
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_env_mount_var-tmp" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Mountpoint /var/tmp is active (mounted) or configured in /etc/fstab</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description />
      </ns0:metadata>
      <ns0:criteria operator="OR">
        <ns0:criteria operator="AND">
          <ns0:criterion comment="The path /var/tmp is an active (mounted) mount point" test_ref="test_mount_active_var_tmp_exists" />
        </ns0:criteria>
        <ns0:criteria operator="AND">
          <ns0:criterion comment="The path /var/tmp is a mount point configured in /etc/fstab" test_ref="test_mount_configured_fstab_var_tmp_exists" />
        </ns0:criteria>
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="installed_env_mount_var" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Mountpoint /var is active (mounted) or configured in /etc/fstab</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description />
      </ns0:metadata>
      <ns0:criteria operator="OR">
        <ns0:criteria operator="AND">
          <ns0:criterion comment="The path /var is an active (mounted) mount point" test_ref="test_mount_active_var_exists" />
        </ns0:criteria>
        <ns0:criteria operator="AND">
          <ns0:criterion comment="The path /var is a mount point configured in /etc/fstab" test_ref="test_mount_configured_fstab_var_exists" />
        </ns0:criteria>
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="os_linux_ol_gt_or_eq_8_7" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Operating System is ol</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>The installed operating system is Oracle Linux</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="The operating system installed on the system is Oracle Linux" test_ref="test_os_id_is_os_linux_ol_gt_or_eq_8_7" />
        <ns0:criterion comment="The operating system Oracle Linux of version greater than or equal 8.7 is installed" test_ref="test_os_linux_ol_gt_or_eq_8_7_gt_or_eq_8_7" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="os_linux_ol_gt_or_eq_9_0" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Operating System is ol</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>The installed operating system is Oracle Linux</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="The operating system installed on the system is Oracle Linux" test_ref="test_os_id_is_os_linux_ol_gt_or_eq_9_0" />
        <ns0:criterion comment="The operating system Oracle Linux of version greater than or equal 9.0 is installed" test_ref="test_os_linux_ol_gt_or_eq_9_0_gt_or_eq_9_0" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="os_linux_rhel_gt_or_eq_8_7" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Operating System is rhel</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>The installed operating system is Red Hat Enterprise Linux</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="The operating system installed on the system is Red Hat Enterprise Linux" test_ref="test_os_id_is_os_linux_rhel_gt_or_eq_8_7" />
        <ns0:criterion comment="The operating system Red Hat Enterprise Linux of version greater than or equal 8.7 is installed" test_ref="test_os_linux_rhel_gt_or_eq_8_7_gt_or_eq_8_7" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="os_linux_rhel_gt_or_eq_9_0" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Operating System is rhel</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>The installed operating system is Red Hat Enterprise Linux</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="The operating system installed on the system is Red Hat Enterprise Linux" test_ref="test_os_id_is_os_linux_rhel_gt_or_eq_9_0" />
        <ns0:criterion comment="The operating system Red Hat Enterprise Linux of version greater than or equal 9.0 is installed" test_ref="test_os_linux_rhel_gt_or_eq_9_0_gt_or_eq_9_0" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="os_linux_rhel_le_or_eq_8_4" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Operating System is rhel</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>The installed operating system is Red Hat Enterprise Linux</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="The operating system installed on the system is Red Hat Enterprise Linux" test_ref="test_os_id_is_os_linux_rhel_le_or_eq_8_4" />
        <ns0:criterion comment="The operating system Red Hat Enterprise Linux of version less than or equal 8.4 is installed" test_ref="test_os_linux_rhel_le_or_eq_8_4_le_or_eq_8_4" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="os_linux_rhel_ne_9_0" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Operating System is rhel</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>The installed operating system is Red Hat Enterprise Linux</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="The operating system installed on the system is Red Hat Enterprise Linux" test_ref="test_os_id_is_os_linux_rhel_ne_9_0" />
        <ns0:criterion comment="The operating system Red Hat Enterprise Linux of version not equal 9.0 is installed" test_ref="test_os_linux_rhel_ne_9_0_ne_9_0" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="os_linux_sles_gt_or_eq_15" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Operating System is sles</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>The installed operating system is SUSE Linux Enterprise Server</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="The operating system installed on the system is SUSE Linux Enterprise Server" test_ref="test_os_id_is_os_linux_sles_gt_or_eq_15" />
        <ns0:criterion comment="The operating system SUSE Linux Enterprise Server of version greater than or equal 15 is installed" test_ref="test_os_linux_sles_gt_or_eq_15_gt_or_eq_15" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="package_aide" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Package aide is installed</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>The DPKG package aide should be installed.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Platform package aide is installed" test_ref="inventory_test_package_aide_installed" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="package_apparmor" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Package apparmor is installed</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>The DPKG package apparmor should be installed.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Platform package apparmor is installed" test_ref="inventory_test_package_apparmor_installed" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="package_apport" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Package apport is installed</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>The DPKG package apport should be installed.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Platform package apport is installed" test_ref="inventory_test_package_apport_installed" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="package_apt_get" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Package apt is installed</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>The DPKG package apt should be installed.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Platform package apt is installed" test_ref="inventory_test_package_apt_get_installed" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="package_audit" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Package auditd is installed</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>The DPKG package auditd should be installed.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Platform package auditd is installed" test_ref="inventory_test_package_audit_installed" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="package_autofs" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Package autofs is installed</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>The DPKG package autofs should be installed.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Platform package autofs is installed" test_ref="inventory_test_package_autofs_installed" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="package_avahi" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Package avahi-daemon is installed</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>The DPKG package avahi-daemon should be installed.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Platform package avahi-daemon is installed" test_ref="inventory_test_package_avahi_installed" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="package_bash" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Package bash is installed</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>The DPKG package bash should be installed.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Platform package bash is installed" test_ref="inventory_test_package_bash_installed" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="package_bind" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Package bind is installed</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>The DPKG package bind should be installed.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Platform package bind is installed" test_ref="inventory_test_package_bind_installed" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="package_chrony" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Package chrony is installed</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>The DPKG package chrony should be installed.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Platform package chrony is installed" test_ref="inventory_test_package_chrony_installed" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="package_firewalld" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Package firewalld is installed</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>The DPKG package firewalld should be installed.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Platform package firewalld is installed" test_ref="inventory_test_package_firewalld_installed" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="package_gdm" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Package gdm3 is installed</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>The DPKG package gdm3 should be installed.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Platform package gdm3 is installed" test_ref="inventory_test_package_gdm_installed" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="package_iptables" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Package iptables is installed</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>The DPKG package iptables should be installed.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Platform package iptables is installed" test_ref="inventory_test_package_iptables_installed" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="package_libpwquality" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Package libpwquality1 is installed</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>The DPKG package libpwquality1 should be installed.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Platform package libpwquality1 is installed" test_ref="inventory_test_package_libpwquality_installed" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="package_libreswan" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Package libreswan is installed</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>The DPKG package libreswan should be installed.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Platform package libreswan is installed" test_ref="inventory_test_package_libreswan_installed" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="package_libuser" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Package libuser is installed</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>The DPKG package libuser should be installed.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Platform package libuser is installed" test_ref="inventory_test_package_libuser_installed" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="package_logrotate" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Package logrotate is installed</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>The DPKG package logrotate should be installed.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Platform package logrotate is installed" test_ref="inventory_test_package_logrotate_installed" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="package_net-snmp" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Package snmp is installed</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>The DPKG package snmp should be installed.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Platform package snmp is installed" test_ref="inventory_test_package_net-snmp_installed" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="package_networkmanager" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Package network-manager is installed</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>The DPKG package network-manager should be installed.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Platform package network-manager is installed" test_ref="inventory_test_package_networkmanager_installed" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="package_nftables" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Package nftables is installed</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>The DPKG package nftables should be installed.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Platform package nftables is installed" test_ref="inventory_test_package_nftables_installed" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="package_nss-pam-ldapd" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Package libpam-ldapd is installed</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>The DPKG package libpam-ldapd should be installed.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Platform package libpam-ldapd is installed" test_ref="inventory_test_package_nss-pam-ldapd_installed" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="package_ntp" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Package ntp is installed</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>The DPKG package ntp should be installed.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Platform package ntp is installed" test_ref="inventory_test_package_ntp_installed" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="package_openssh-server_le_7_0" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Package openssh-server is installed</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>The DPKG package openssh-server version less than 7.0 should be installed.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Platform package openssh-server of version less than 7.0 is installed" test_ref="inventory_test_package_openssh-server_le_7_0_le_7_0_installed" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="package_openssh-server_le_7_5" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Package openssh-server is installed</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>The DPKG package openssh-server version less than 7.5 should be installed.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Platform package openssh-server of version less than 7.5 is installed" test_ref="inventory_test_package_openssh-server_le_7_5_le_7_5_installed" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="package_openssh" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Package openssh is installed</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>The DPKG package openssh should be installed.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Platform package openssh is installed" test_ref="inventory_test_package_openssh_installed" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="package_pam" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Package libpam-runtime is installed</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>The DPKG package libpam-runtime should be installed.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Platform package libpam-runtime is installed" test_ref="inventory_test_package_pam_installed" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="package_pam_apparmor" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Package pam_apparmor is installed</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>The DPKG package pam_apparmor should be installed.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Platform package pam_apparmor is installed" test_ref="inventory_test_package_pam_apparmor_installed" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="package_polkit" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Package polkit is installed</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>The DPKG package polkit should be installed.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Platform package polkit is installed" test_ref="inventory_test_package_polkit_installed" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="package_postfix" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Package postfix is installed</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>The DPKG package postfix should be installed.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Platform package postfix is installed" test_ref="inventory_test_package_postfix_installed" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="package_rootfiles" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Package rootfiles is installed</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>The DPKG package rootfiles should be installed.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Platform package rootfiles is installed" test_ref="inventory_test_package_rootfiles_installed" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="package_rsh-server" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Package rsh-server is installed</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>The DPKG package rsh-server should be installed.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Platform package rsh-server is installed" test_ref="inventory_test_package_rsh-server_installed" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="package_rsyslog" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Package rsyslog is installed</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>The DPKG package rsyslog should be installed.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Platform package rsyslog is installed" test_ref="inventory_test_package_rsyslog_installed" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="package_shadow-utils" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Package login is installed</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>The DPKG package login should be installed.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Platform package login is installed" test_ref="inventory_test_package_shadow-utils_installed" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="package_snmpd" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Package net-snmp is installed</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>The DPKG package net-snmp should be installed.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Platform package net-snmp is installed" test_ref="inventory_test_package_snmpd_installed" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="package_squid" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Package squid is installed</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>The DPKG package squid should be installed.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Platform package squid is installed" test_ref="inventory_test_package_squid_installed" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="package_sssd" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Package sssd is installed</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>The DPKG package sssd should be installed.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Platform package sssd is installed" test_ref="inventory_test_package_sssd_installed" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="package_sudo" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Package sudo is installed</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>The DPKG package sudo should be installed.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Platform package sudo is installed" test_ref="inventory_test_package_sudo_installed" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="package_systemd-journal-remote" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Package systemd-journal-remote is installed</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>The DPKG package systemd-journal-remote should be installed.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Platform package systemd-journal-remote is installed" test_ref="inventory_test_package_systemd-journal-remote_installed" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="package_systemd-timesyncd" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Package systemd-timesyncd is installed</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>The DPKG package systemd-timesyncd should be installed.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Platform package systemd-timesyncd is installed" test_ref="inventory_test_package_systemd-timesyncd_installed" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="package_systemd" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Package systemd is installed</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>The DPKG package systemd should be installed.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Platform package systemd is installed" test_ref="inventory_test_package_systemd_installed" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="package_telnet-server" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Package telnet-server is installed</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>The DPKG package telnet-server should be installed.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Platform package telnet-server is installed" test_ref="inventory_test_package_telnet-server_installed" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="package_tftp-server" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Package tftp-server is installed</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>The DPKG package tftp-server should be installed.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Platform package tftp-server is installed" test_ref="inventory_test_package_tftp-server_installed" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="package_tmux" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Package tmux is installed</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>The DPKG package tmux should be installed.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Platform package tmux is installed" test_ref="inventory_test_package_tmux_installed" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="package_ufw" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Package ufw is installed</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>The DPKG package ufw should be installed.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Platform package ufw is installed" test_ref="inventory_test_package_ufw_installed" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="package_usbguard" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>Package usbguard is installed</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>The DPKG package usbguard should be installed.</ns0:description>
      </ns0:metadata>
      <ns0:criteria operator="AND">
        <ns0:criterion comment="Platform package usbguard is installed" test_ref="inventory_test_package_usbguard_installed" />
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="service_disabled_firewalld" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>The firewalld is disabled on the system</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>The firewalld service should be disabled.</ns0:description>
      </ns0:metadata>
      <ns0:criteria comment="package firewalld removed or service firewalld is not configured to start" operator="OR">
        <ns0:criterion comment="firewalld removed" test_ref="service_disabled_firewalldtest_service_firewalld_package_firewalld_removed" />
        <ns0:criteria comment="service is not present or not configured" operator="OR">
          <ns0:criteria comment="service firewalld is not configured to start" operator="AND">
            <ns0:criterion comment="firewalld is not running" test_ref="test_service_not_running_service_disabled_firewalld_firewalld" />
            <ns0:criterion comment="Property LoadState of service firewalld is masked" test_ref="test_service_loadstate_is_masked_service_disabled_firewalld_firewalld" />
          </ns0:criteria>
          <ns0:criterion comment="firewalld is not found" test_ref="test_service_not_found_service_disabled_firewalld_firewalld" />
        </ns0:criteria>
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="service_disabled_iptables" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>The iptables is disabled on the system</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>The iptables service should be disabled.</ns0:description>
      </ns0:metadata>
      <ns0:criteria comment="package iptables removed or service iptables is not configured to start" operator="OR">
        <ns0:criterion comment="iptables removed" test_ref="service_disabled_iptablestest_service_iptables_package_iptables_removed" />
        <ns0:criteria comment="service is not present or not configured" operator="OR">
          <ns0:criteria comment="service iptables is not configured to start" operator="AND">
            <ns0:criterion comment="iptables is not running" test_ref="test_service_not_running_service_disabled_iptables_iptables" />
            <ns0:criterion comment="Property LoadState of service iptables is masked" test_ref="test_service_loadstate_is_masked_service_disabled_iptables_iptables" />
          </ns0:criteria>
          <ns0:criterion comment="iptables is not found" test_ref="test_service_not_found_service_disabled_iptables_iptables" />
        </ns0:criteria>
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="service_disabled_nftables" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>The nftables is disabled on the system</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>The nftables service should be disabled.</ns0:description>
      </ns0:metadata>
      <ns0:criteria comment="package nftables removed or service nftables is not configured to start" operator="OR">
        <ns0:criterion comment="nftables removed" test_ref="service_disabled_nftablestest_service_nftables_package_nftables_removed" />
        <ns0:criteria comment="service is not present or not configured" operator="OR">
          <ns0:criteria comment="service nftables is not configured to start" operator="AND">
            <ns0:criterion comment="nftables is not running" test_ref="test_service_not_running_service_disabled_nftables_nftables" />
            <ns0:criterion comment="Property LoadState of service nftables is masked" test_ref="test_service_loadstate_is_masked_service_disabled_nftables_nftables" />
          </ns0:criteria>
          <ns0:criterion comment="nftables is not found" test_ref="test_service_not_found_service_disabled_nftables_nftables" />
        </ns0:criteria>
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="service_disabled_rsyslog" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>The rsyslog is disabled on the system</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>The rsyslog service should be disabled.</ns0:description>
      </ns0:metadata>
      <ns0:criteria comment="package rsyslog removed or service rsyslog is not configured to start" operator="OR">
        <ns0:criterion comment="rsyslog removed" test_ref="service_disabled_rsyslogtest_service_rsyslog_package_rsyslog_removed" />
        <ns0:criteria comment="service is not present or not configured" operator="OR">
          <ns0:criteria comment="service rsyslog is not configured to start" operator="AND">
            <ns0:criterion comment="rsyslog is not running" test_ref="test_service_not_running_service_disabled_rsyslog_rsyslog" />
            <ns0:criterion comment="Property LoadState of service rsyslog is masked" test_ref="test_service_loadstate_is_masked_service_disabled_rsyslog_rsyslog" />
          </ns0:criteria>
          <ns0:criterion comment="rsyslog is not found" test_ref="test_service_not_found_service_disabled_rsyslog_rsyslog" />
        </ns0:criteria>
      </ns0:criteria>
    </ns0:definition>
    <ns0:definition id="service_disabled_ufw" version="1" class="inventory">
      <ns0:metadata>
        <ns0:title>The ufw is disabled on the system</ns0:title>
        <ns0:affected family="unix">
          <ns0:platform>Ubuntu 22.04</ns0:platform>
        </ns0:affected>
        <ns0:description>The ufw service should be disabled.</ns0:description>
      </ns0:metadata>
      <ns0:criteria comment="package ufw removed or service ufw is not configured to start" operator="OR">
        <ns0:criterion comment="ufw removed" test_ref="service_disabled_ufwtest_service_ufw_package_ufw_removed" />
        <ns0:criteria comment="service is not present or not configured" operator="OR">
          <ns0:criteria comment="service ufw is not configured to start" operator="AND">
            <ns0:criterion comment="ufw is not running" test_ref="test_service_not_running_service_disabled_ufw_ufw" />
            <ns0:criterion comment="Property LoadState of service ufw is masked" test_ref="test_service_loadstate_is_masked_service_disabled_ufw_ufw" />
          </ns0:criteria>
          <ns0:criterion comment="ufw is not found" test_ref="test_service_not_found_service_disabled_ufw_ufw" />
        </ns0:criteria>
      </ns0:criteria>
    </ns0:definition>
  </ns0:definitions>
  <ns0:tests>
    <ns3:dpkginfo_test id="bootc_platform_test_kernel_installed" version="1" check="all" comment="package kernel is installed" check_existence="all_exist" state_operator="AND">
      <ns3:object object_ref="obj_bootc_platform_test_kernel_installed" />
    </ns3:dpkginfo_test>
    <ns3:dpkginfo_test id="bootc_platform_test_rpm_ostree_installed" version="1" check="all" comment="package rpm-ostree is installed" check_existence="all_exist" state_operator="AND">
      <ns3:object object_ref="obj_bootc_platform_test_rpm_ostree_installed" />
    </ns3:dpkginfo_test>
    <ns3:dpkginfo_test id="bootc_platform_test_bootc_installed" version="1" check="all" comment="package bootc is installed" check_existence="all_exist" state_operator="AND">
      <ns3:object object_ref="obj_bootc_platform_test_bootc_installed" />
    </ns3:dpkginfo_test>
    <ns3:dpkginfo_test id="bootc_platform_test_openshift_kubelet_removed" version="1" check="all" comment="package openshift-kubelet is removed" check_existence="none_exist" state_operator="AND">
      <ns3:object object_ref="obj_bootc_platform_test_openshift_kubelet_removed" />
    </ns3:dpkginfo_test>
    <ns4:file_test id="bootc_platform_test_run_ostree_booted_exists" version="1" check="all" comment="The file /run/ostree-booted exists" check_existence="all_exist" state_operator="AND">
      <ns4:object object_ref="bootc_platform_obj_run_ostree_booted_exists" />
    </ns4:file_test>
    <ns4:file_test id="bootc_platform_test_ostree_symlink_exists" version="1" check="all" comment="The file /ostree is a symlink" check_existence="all_exist" state_operator="AND">
      <ns4:object object_ref="bootc_platform_obj_ostree_symlink_exists" />
      <ns4:state state_ref="bootc_platform_ste_ostree_symlink_exists" />
    </ns4:file_test>
    <ns3:rpminfo_test id="test_alinux2" version="1" check="all" comment="alinux-release is version 2" state_operator="AND">
      <ns3:object object_ref="obj_alinux2" />
      <ns3:state state_ref="state_alinux2" />
    </ns3:rpminfo_test>
    <ns3:rpminfo_test id="test_alinux3" version="1" check="all" comment="alinux-release is version 3" state_operator="AND">
      <ns3:object object_ref="obj_alinux3" />
      <ns3:state state_ref="state_alinux3" />
    </ns3:rpminfo_test>
    <ns3:rpminfo_test id="test_anolis8" version="1" check="all" comment="anolis-release is version 8" state_operator="AND">
      <ns3:object object_ref="obj_anolis8" />
      <ns3:state state_ref="state_anolis8" />
    </ns3:rpminfo_test>
    <ns5:textfilecontent54_test id="test_debian_11" version="1" check="all" comment="Check Debian version" state_operator="AND">
      <ns5:object object_ref="obj_debian_11" />
    </ns5:textfilecontent54_test>
    <ns5:textfilecontent54_test id="test_debian_12" version="1" check="all" comment="Check Debian version" state_operator="AND">
      <ns5:object object_ref="obj_debian_12" />
    </ns5:textfilecontent54_test>
    <ns5:textfilecontent54_test id="test_debian_13" version="1" check="all" comment="Check Debian version" state_operator="AND">
      <ns5:object object_ref="obj_debian_13" />
    </ns5:textfilecontent54_test>
    <ns3:rpminfo_test id="test_rhevm4_version" version="1" check="all" comment="rhevm4-appliance is installed" state_operator="AND">
      <ns3:object object_ref="obj_rhevm4_version" />
      <ns3:state state_ref="state_rhevm4_version" />
    </ns3:rpminfo_test>
    <ns3:dpkginfo_test id="test_env_has_grub2_installed" version="1" check="all" comment="system has package grub2-common installed" check_existence="all_exist" state_operator="AND">
      <ns3:object object_ref="obj_env_has_grub2_installed" />
    </ns3:dpkginfo_test>
    <ns4:file_test id="test_system_using_opal" version="1" check="all" comment="Check if /sys/firmware/opal exists" check_existence="all_exist" state_operator="AND">
      <ns4:object object_ref="object_system_using_opal" />
    </ns4:file_test>
    <ns3:dpkginfo_test id="test_env_has_login_defs_installed" version="1" check="all" comment="system has package login installed, which provides the /etc/login.defs file" check_existence="all_exist" state_operator="AND">
      <ns3:object object_ref="obj_env_has_login_defs_installed" />
    </ns3:dpkginfo_test>
    <ns3:rpminfo_test id="test_env_has_ovirt-host_installed" version="1" check="all" comment="system has package ovirt-host installed" state_operator="AND">
      <ns3:object object_ref="obj_env_has_ovirt-host_installed" />
    </ns3:rpminfo_test>
    <ns3:rpminfo_test id="test_env_has_ovirt-engine_installed" version="1" check="all" comment="system has package ovirt-engine installed" state_operator="AND">
      <ns3:object object_ref="obj_env_has_ovirt-engine_installed" />
    </ns3:rpminfo_test>
    <ns4:file_test id="test_proc_net_wireless_exists" version="1" check="all" comment="Test if /proc/net/wireless exists" check_existence="all_exist" state_operator="AND">
      <ns4:object object_ref="object_proc_net_wireless_exists" />
    </ns4:file_test>
    <ns4:file_test id="test_installed_env_is_a_docker_container" version="1" check="all" comment="Check if /.dockerenv exists" check_existence="all_exist" state_operator="AND">
      <ns4:object object_ref="object_installed_env_is_a_docker_container" />
    </ns4:file_test>
    <ns4:file_test id="test_installed_env_is_a_podman_container" version="1" check="all" comment="Check if /run/.containerenv exists" check_existence="all_exist" state_operator="AND">
      <ns4:object object_ref="object_installed_env_is_a_podman_container" />
    </ns4:file_test>
    <ns4:uname_test id="test_kernel_uek" version="1" check="all" comment="Runing kernel is UEK" check_existence="all_exist" state_operator="AND">
      <ns4:object object_ref="obj_kernel_uek" />
      <ns4:state state_ref="state_kernel_uek" />
    </ns4:uname_test>
    <ns3:dpkginfo_test id="test_krb5_server_version_1_17_18" version="1" check="at least one" comment="Kerberos server version is lesser than 1.17-18" check_existence="any_exist" state_operator="AND">
      <ns3:object object_ref="obj_krb5_server_version_1_17_18" />
      <ns3:state state_ref="state_krb5_server_version_1_17_18" />
    </ns3:dpkginfo_test>
    <ns3:dpkginfo_test id="test_krb5_workstation_version_1_17_18" version="1" check="at least one" comment="Kerberos workstation version is lesser than 1.17-18" check_existence="any_exist" state_operator="AND">
      <ns3:object object_ref="obj_krb5_workstation_version_1_17_18" />
      <ns3:state state_ref="state_krb5_workstation_version_1_17_18" />
    </ns3:dpkginfo_test>
    <ns5:textfilecontent54_test id="test_nfs_mount_exists" version="1" check="all" comment="at least one nfs is defined" state_operator="AND">
      <ns5:object object_ref="object_nfs_mount_defined" />
    </ns5:textfilecontent54_test>
    <ns5:textfilecontent54_test id="test_proc_sys_kernel_osrelease_arch_aarch64" version="1" check="all" comment="proc_sys_kernel is for aarch64 architecture" state_operator="AND">
      <ns5:object object_ref="object_proc_sys_kernel_osrelease_arch_aarch64" />
    </ns5:textfilecontent54_test>
    <ns5:textfilecontent54_test id="test_proc_sys_kernel_osrelease_arch_ppc64le" version="1" check="all" comment="proc_sys_kernel is for ppc64le architecture" state_operator="AND">
      <ns5:object object_ref="object_proc_sys_kernel_osrelease_arch_ppc64le" />
    </ns5:textfilecontent54_test>
    <ns5:textfilecontent54_test id="test_proc_sys_kernel_osrelease_arch_s390x" version="1" check="all" comment="proc_sys_kernel is for s390x architecture" state_operator="AND">
      <ns5:object object_ref="object_proc_sys_kernel_osrelease_arch_s390x" />
    </ns5:textfilecontent54_test>
    <ns5:textfilecontent54_test id="test_proc_sys_kernel_osrelease_arch_x86_64" version="1" check="all" comment="proc_sys_kernel is for x86_64 architecture" state_operator="AND">
      <ns5:object object_ref="object_proc_sys_kernel_osrelease_arch_x86_64" />
    </ns5:textfilecontent54_test>
    <ns4:sysctl_test id="test_runtime_kernel_fips_enabled" version="1" check="all" comment="kernel runtime parameter crypto.fips_enabled set to 1" check_existence="all_exist" state_operator="AND">
      <ns4:object object_ref="obj_runtime_kernel_fips_enabled" />
      <ns4:state state_ref="state_runtime_kernel_fips_enabled" />
    </ns4:sysctl_test>
    <ns5:filehash58_test id="test_secure_boot_enabled" version="1" check="all" comment="Scure Boot is enabled" check_existence="all_exist" state_operator="AND">
      <ns5:object object_ref="obj_secure_boot_enabled" />
      <ns5:state state_ref="state_secure_boot_enabled" />
    </ns5:filehash58_test>
    <ns5:textfilecontent54_test id="test_etc_selinux_configured" version="1" check="all" comment="/selinux/enforce is 1" check_existence="all_exist" state_operator="AND">
      <ns5:object object_ref="object_etc_selinux_configured" />
      <ns5:state state_ref="state_etc_selinux_configured" />
    </ns5:textfilecontent54_test>
    <ns4:file_test id="test_selinux_sys_fs_exist" version="1" check="all" comment="check if /sys/fs/selinux exists" check_existence="all_exist" state_operator="AND">
      <ns4:object object_ref="object_selinux_sys_fs_exist" />
    </ns4:file_test>
    <ns5:textfilecontent54_test id="test_id_provider_is_set_to_ldap" version="1" check="all" comment="SSSD Configuration is set to use LDAP" check_existence="all_exist" state_operator="AND">
      <ns5:object object_ref="object_id_provider_is_set_to_ldap" />
    </ns5:textfilecontent54_test>
    <ns4:file_test id="test_efi_dir_existence" version="1" check="all" comment="Verify if /sys/firmware/efi folder exists" state_operator="AND">
      <ns4:object object_ref="object_file_sys_firmware_efi" />
    </ns4:file_test>
    <ns3:dpkginfo_test id="inventory_test_kernel_installed" version="1" check="all" comment="package linux-base is installed" check_existence="all_exist" state_operator="AND">
      <ns3:object object_ref="obj_inventory_test_kernel_installed" />
    </ns3:dpkginfo_test>
    <ns5:textfilecontent54_test id="test_accounts_password_pam_faillock" version="1" check="all" comment="check the configuration of /etc/pam.d/system-auth" state_operator="AND">
      <ns5:object object_ref="obj_accounts_password_pam_faillock" />
    </ns5:textfilecontent54_test>
    <ns5:textfilecontent54_test id="test_password_pam_pwquality" version="1" check="all" comment="check the configuration of /etc/pam.d/system-auth" state_operator="AND">
      <ns5:object object_ref="obj_password_pam_pwquality" />
    </ns5:textfilecontent54_test>
    <ns5:textfilecontent54_test id="test_audit_rules_auditctl" version="1" check="all" comment="audit auditctl" state_operator="AND">
      <ns5:object object_ref="object_audit_rules_auditctl" />
    </ns5:textfilecontent54_test>
    <ns5:textfilecontent54_test id="test_audit_rules_augenrules" version="1" check="all" comment="audit augenrules" state_operator="AND">
      <ns5:object object_ref="object_audit_rules_augenrules" />
    </ns5:textfilecontent54_test>
    <ns5:textfilecontent54_test id="test_32bit_setdomainname_augenrules" version="1" check="all" comment="audit augenrules 32-bit setdomainname" state_operator="AND">
      <ns5:object object_ref="object_32bit_setdomainname_augenrules" />
    </ns5:textfilecontent54_test>
    <ns5:textfilecontent54_test id="test_64bit_setdomainname_augenrules" version="1" check="all" comment="audit augenrules 64-bit setdomainname" state_operator="AND">
      <ns5:object object_ref="object_64bit_setdomainname_augenrules" />
    </ns5:textfilecontent54_test>
    <ns5:textfilecontent54_test id="test_32bit_setdomainname_auditctl" version="1" check="all" comment="audit auditctl 32-bit setdomainname" state_operator="AND">
      <ns5:object object_ref="object_32bit_setdomainname_auditctl" />
    </ns5:textfilecontent54_test>
    <ns5:textfilecontent54_test id="test_64bit_setdomainname_auditctl" version="1" check="all" comment="audit auditctl 64-bit setdomainname" state_operator="AND">
      <ns5:object object_ref="object_64bit_setdomainname_auditctl" />
    </ns5:textfilecontent54_test>
    <ns5:textfilecontent54_test id="test_32bit_sethostname_augenrules" version="1" check="all" comment="audit augenrules 32-bit sethostname" state_operator="AND">
      <ns5:object object_ref="object_32bit_sethostname_augenrules" />
    </ns5:textfilecontent54_test>
    <ns5:textfilecontent54_test id="test_64bit_sethostname_augenrules" version="1" check="all" comment="audit augenrules 64-bit sethostname" state_operator="AND">
      <ns5:object object_ref="object_64bit_sethostname_augenrules" />
    </ns5:textfilecontent54_test>
    <ns5:textfilecontent54_test id="test_32bit_sethostname_auditctl" version="1" check="all" comment="audit auditctl 32-bit sethostname" state_operator="AND">
      <ns5:object object_ref="object_32bit_sethostname_auditctl" />
    </ns5:textfilecontent54_test>
    <ns5:textfilecontent54_test id="test_64bit_sethostname_auditctl" version="1" check="all" comment="audit auditctl 64-bit sethostname" state_operator="AND">
      <ns5:object object_ref="object_64bit_sethostname_auditctl" />
    </ns5:textfilecontent54_test>
    <ns5:textfilecontent54_test id="test_auditd_conf_log_file_not_set" version="1" check="all" comment="log_file not set" check_existence="none_exist" state_operator="AND">
      <ns5:object object_ref="object_auditd_conf_log_file" />
    </ns5:textfilecontent54_test>
    <ns5:textfilecontent54_test id="test_auditd_conf_log_group_not_root" version="1" check="all" comment="log_group = root" check_existence="none_exist" state_operator="AND">
      <ns5:object object_ref="object_auditd_conf_log_group_root" />
    </ns5:textfilecontent54_test>
    <ns5:textfilecontent54_test id="test_auditd_conf_log_group_is_set" version="1" check="all" comment="log_group is set" check_existence="all_exist" state_operator="AND">
      <ns5:object object_ref="object_auditd_conf_log_group_is_set" />
    </ns5:textfilecontent54_test>
    <ns5:textfilecontent54_test id="test_bootloader_disable_recovery_set_to_true" version="1" check="all" comment="Check for GRUB_DISABLE_RECOVERY=true in /etc/default/grub" check_existence="all_exist" state_operator="AND">
      <ns5:object object_ref="object_bootloader_disable_recovery_argument" />
      <ns5:state state_ref="state_bootloader_disable_recovery_argument" />
    </ns5:textfilecontent54_test>
    <ns5:textfilecontent54_test id="test_chronyd_multiple_servers" version="1" check="all" comment="Ensure more than one chronyd NTP server is set" check_existence="all_exist" state_operator="AND">
      <ns5:object object_ref="object_chronyd_multiple_servers" />
    </ns5:textfilecontent54_test>
    <ns5:textfilecontent54_test id="test_grub2_default_exists" version="1" check="all" comment="check for GRUB_CMDLINE_LINUX_DEFAULT in /etc/default/grub" check_existence="all_exist" state_operator="AND">
      <ns5:object object_ref="object_grub2_default_exists" />
    </ns5:textfilecontent54_test>
    <ns5:textfilecontent54_test id="test_grub2_entries_reference_kernelopts" version="1" check="all" comment="check kernel command line parameters for referenced boot entries reference the $kernelopts variable." check_existence="all_exist" state_operator="AND">
      <ns5:object object_ref="object_grub2_entries_reference_kernelopts" />
    </ns5:textfilecontent54_test>
    <ns5:textfilecontent54_test id="test_al2023_name" version="1" check="all" comment="Check os-release ID" state_operator="AND">
      <ns5:object object_ref="obj_name_al2023" />
      <ns5:state state_ref="state_name_al2023" />
    </ns5:textfilecontent54_test>
    <ns5:textfilecontent54_test id="test_al2023_version" version="1" check="all" comment="Check os-release VERSION_ID" state_operator="AND">
      <ns5:object object_ref="obj_version_al2023" />
      <ns5:state state_ref="state_version_al2023" />
    </ns5:textfilecontent54_test>
    <ns4:file_test id="test_almalinux" version="1" check="all" comment="/etc/almalinux-release exists" check_existence="all_exist" state_operator="AND">
      <ns4:object object_ref="obj_almalinux" />
    </ns4:file_test>
    <ns5:textfilecontent54_test id="test_almalinux9" version="1" check="all" comment="Check Custom OS version" state_operator="AND">
      <ns5:object object_ref="obj_almalinux9" />
    </ns5:textfilecontent54_test>
    <ns3:rpminfo_test id="test_anolis23" version="1" check="all" comment="anolis-release is version 23" state_operator="AND">
      <ns3:object object_ref="obj_anolis23" />
      <ns3:state state_ref="state_anolis23" />
    </ns3:rpminfo_test>
    <ns5:textfilecontent54_test id="test_centos10_name" version="1" check="all" comment="Check os-release ID" state_operator="AND">
      <ns5:object object_ref="obj_name_centos10" />
      <ns5:state state_ref="state_name_centos10" />
    </ns5:textfilecontent54_test>
    <ns5:textfilecontent54_test id="test_centos10_version" version="1" check="all" comment="Check os-release VERSION_ID" state_operator="AND">
      <ns5:object object_ref="obj_version_centos10" />
      <ns5:state state_ref="state_version_centos10" />
    </ns5:textfilecontent54_test>
    <ns5:textfilecontent54_test id="test_centos8_name" version="1" check="all" comment="Check os-release ID" state_operator="AND">
      <ns5:object object_ref="obj_name_centos8" />
      <ns5:state state_ref="state_name_centos8" />
    </ns5:textfilecontent54_test>
    <ns5:textfilecontent54_test id="test_centos8_version" version="1" check="all" comment="Check os-release VERSION_ID" state_operator="AND">
      <ns5:object object_ref="obj_version_centos8" />
      <ns5:state state_ref="state_version_centos8" />
    </ns5:textfilecontent54_test>
    <ns5:textfilecontent54_test id="test_centos9_name" version="1" check="all" comment="Check os-release ID" state_operator="AND">
      <ns5:object object_ref="obj_name_centos9" />
      <ns5:state state_ref="state_name_centos9" />
    </ns5:textfilecontent54_test>
    <ns5:textfilecontent54_test id="test_centos9_version" version="1" check="all" comment="Check os-release VERSION_ID" state_operator="AND">
      <ns5:object object_ref="obj_version_centos9" />
      <ns5:state state_ref="state_version_centos9" />
    </ns5:textfilecontent54_test>
    <ns4:file_test id="test_debian" version="1" check="all" comment="/etc/debian_version exists" check_existence="all_exist" state_operator="AND">
      <ns4:object object_ref="obj_debian" />
    </ns4:file_test>
    <ns3:rpminfo_test id="test_fedora_release_rpm" version="1" check="all" comment="fedora-release RPM packages are installed" state_operator="AND">
      <ns3:object object_ref="object_fedora_release_rpm" />
    </ns3:rpminfo_test>
    <ns5:textfilecontent54_test id="test_fedora_vendor_product" version="1" check="all" comment="CPE vendor is 'fedoraproject' and 'product' is fedora" state_operator="AND">
      <ns5:object object_ref="object_fedora_vendor_product" />
    </ns5:textfilecontent54_test>
    <ns3:rpminfo_test id="test_kylinserver10_installed" version="1" check="all" comment="Kylin Server 10 is installed" check_existence="all_exist" state_operator="AND">
      <ns3:object object_ref="obj_kylinserver10_installed" />
      <ns3:state state_ref="state_kylinserver10_installed" />
    </ns3:rpminfo_test>
    <ns4:file_test id="test_os_oeharden" version="1" check="all" comment="/etc/os-release exists" check_existence="all_exist" state_operator="AND">
      <ns4:object object_ref="obj_os_oeharden" />
    </ns4:file_test>
    <ns5:textfilecontent54_test id="test_oeharden" version="1" check="all" comment="Check OpenEmbedded" state_operator="AND">
      <ns5:object object_ref="obj_oeharden" />
    </ns5:textfilecontent54_test>
    <ns5:textfilecontent54_test id="test_os_id_is_ol" version="1" check="all" comment="ID in os-release is ol" state_operator="AND">
      <ns5:object object_ref="obj_os_id_is_ol" />
      <ns5:state state_ref="state_os_id_is_ol" />
    </ns5:textfilecontent54_test>
    <ns3:rpminfo_test id="test_ol10_system" version="1" check="all" comment="oraclelinux-release is version 10" state_operator="AND">
      <ns3:object object_ref="obj_ol10_system" />
      <ns3:state state_ref="state_ol10_system" />
    </ns3:rpminfo_test>
    <ns3:rpminfo_test id="test_ol7_system" version="1" check="all" comment="oraclelinux-release is version 7" state_operator="AND">
      <ns3:object object_ref="obj_ol7_system" />
      <ns3:state state_ref="state_ol7_system" />
    </ns3:rpminfo_test>
    <ns3:rpminfo_test id="test_ol8_system" version="1" check="all" comment="oraclelinux-release is version 8" state_operator="AND">
      <ns3:object object_ref="obj_ol8_system" />
      <ns3:state state_ref="state_ol8_system" />
    </ns3:rpminfo_test>
    <ns3:rpminfo_test id="test_ol9_system" version="1" check="all" comment="oraclelinux-release is version 9" state_operator="AND">
      <ns3:object object_ref="obj_ol9_system" />
      <ns3:state state_ref="state_ol9_system" />
    </ns3:rpminfo_test>
    <ns4:file_test id="test_os_openembedded" version="1" check="all" comment="/etc/os-release exists" check_existence="all_exist" state_operator="AND">
      <ns4:object object_ref="obj_os_openembedded" />
    </ns4:file_test>
    <ns5:textfilecontent54_test id="test_openembedded" version="1" check="all" comment="Check OpenEmbedded" state_operator="AND">
      <ns5:object object_ref="obj_openembedded" />
    </ns5:textfilecontent54_test>
    <ns3:rpminfo_test id="test_openeuler2203_installed" version="1" check="all" comment="openEuler 22.03 LTS is installed" check_existence="all_exist" state_operator="AND">
      <ns3:object object_ref="obj_openeuler2203_installed" />
      <ns3:state state_ref="state_openeuler2203_installed" />
    </ns3:rpminfo_test>
    <ns3:rpminfo_test id="test_opensuse_installed" version="1" check="all" comment="openSUSE is installed" state_operator="AND">
      <ns3:object object_ref="obj_opensuse_installed" />
      <ns3:state state_ref="state_opensuse_installed" />
    </ns3:rpminfo_test>
    <ns3:rpminfo_test id="test_opensuse_leap15_installed" version="1" check="all" comment="openSUSE Leap 15 is installed" state_operator="AND">
      <ns3:object object_ref="obj_opensuse_leap15_installed" />
      <ns3:state state_ref="state_opensuse_leap15_installed" />
    </ns3:rpminfo_test>
    <ns3:rpminfo_test id="test_opensuse_leap16_installed" version="1" check="all" comment="openSUSE Leap 16 is installed" state_operator="AND">
      <ns3:object object_ref="obj_opensuse_leap16_installed" />
      <ns3:state state_ref="state_opensuse_leap16_installed" />
    </ns3:rpminfo_test>
    <ns5:family_test id="test_unix_family" version="1" check="all" comment="Test installed OS is part of the unix family" state_operator="AND">
      <ns5:object object_ref="object_unix_family" />
      <ns5:state state_ref="state_unix_family" />
    </ns5:family_test>
    <ns4:file_test id="test_os_petalinux" version="1" check="all" comment="/etc/os-release exists" check_existence="all_exist" state_operator="AND">
      <ns4:object object_ref="obj_os_petalinux" />
    </ns4:file_test>
    <ns5:textfilecontent54_test id="test_petalinux" version="1" check="all" comment="Check OpenEmbedded" state_operator="AND">
      <ns5:object object_ref="obj_petalinux" />
    </ns5:textfilecontent54_test>
    <ns4:file_test id="test_os_poky" version="1" check="all" comment="/etc/os-release exists" check_existence="all_exist" state_operator="AND">
      <ns4:object object_ref="obj_os_poky" />
    </ns4:file_test>
    <ns5:textfilecontent54_test id="test_poky" version="1" check="all" comment="Check OpenEmbedded" state_operator="AND">
      <ns5:object object_ref="obj_poky" />
    </ns5:textfilecontent54_test>
    <ns5:textfilecontent54_test id="test_rhcos" version="1" check="all" comment="os-release is rhcos" state_operator="AND">
      <ns5:object object_ref="obj_rhcos" />
      <ns5:state state_ref="state_rhcos" />
    </ns5:textfilecontent54_test>
    <ns5:textfilecontent54_test id="test_rhel_coreos_variant" version="1" check="all" comment="Check for variant=CoreOS" state_operator="AND">
      <ns5:object object_ref="obj_rhel_coreos_variant" />
      <ns5:state state_ref="state_rhel_coreos_variant" />
    </ns5:textfilecontent54_test>
    <ns5:textfilecontent54_test id="test_rhel_coreos_version9" version="1" check="all" comment="Check if VERSION_ID=9.x" state_operator="AND">
      <ns5:object object_ref="obj_rhel_coreos_version9" />
      <ns5:state state_ref="state_rhel_coreos_version9" />
    </ns5:textfilecontent54_test>
    <ns5:textfilecontent54_test id="test_rhel_coreos_version10" version="1" check="all" comment="Check if VERSION_ID=10.x" state_operator="AND">
      <ns5:object object_ref="obj_rhel_coreos_version10" />
      <ns5:state state_ref="state_rhel_coreos_version10" />
    </ns5:textfilecontent54_test>
    <ns5:textfilecontent54_test id="test_rhcos4" version="1" check="all" comment="rhcoreos is version 4" state_operator="AND">
      <ns5:object object_ref="obj_rhcos4" />
      <ns5:state state_ref="state_rhcos4" />
    </ns5:textfilecontent54_test>
    <ns5:textfilecontent54_test id="test_rhcos4_rhel8_rhel_version" version="1" check="all" comment="rhcoreos RHEL_VERSION is 8 (old format)" state_operator="AND">
      <ns5:object object_ref="obj_rhcos4_rhel8_rhel_version" />
      <ns5:state state_ref="state_rhcos4_rhel8_rhel_version" />
    </ns5:textfilecontent54_test>
    <ns5:textfilecontent54_test id="test_rhel_id" version="1" check="all" comment="ID is rhel" state_operator="AND">
      <ns5:object object_ref="obj_rhel_id" />
      <ns5:state state_ref="state_rhel_id" />
    </ns5:textfilecontent54_test>
    <ns5:textfilecontent54_test id="test_rhcos4_rhel9_rhel_version" version="1" check="all" comment="rhcoreos RHEL_VERSION is 9 (old format)" state_operator="AND">
      <ns5:object object_ref="obj_rhcos4_rhel9_rhel_version" />
      <ns5:state state_ref="state_rhcos4_rhel9_rhel_version" />
    </ns5:textfilecontent54_test>
    <ns5:textfilecontent54_test id="test_os_id_is_rhel" version="1" check="all" comment="ID in os-release is rhel" state_operator="AND">
      <ns5:object object_ref="obj_os_id_is_rhel" />
      <ns5:state state_ref="state_os_id_is_rhel" />
    </ns5:textfilecontent54_test>
    <ns5:family_test id="test_rhel10_unix_family" version="1" check="all" comment="installed OS part of unix family" state_operator="AND">
      <ns5:object object_ref="obj_rhel10_unix_family" />
      <ns5:state state_ref="state_rhel10_unix_family" />
    </ns5:family_test>
    <ns3:rpminfo_test id="test_rhel10" version="1" check="all" comment="redhat-release is version 10" state_operator="AND">
      <ns3:object object_ref="obj_rhel10" />
      <ns3:state state_ref="state_rhel10" />
    </ns3:rpminfo_test>
    <ns5:textfilecontent54_test id="test_rhevh_rhel10_version" version="1" check="all" comment="RHEVH base RHEL is version 10" state_operator="AND">
      <ns5:object object_ref="obj_rhevh_rhel10_version" />
      <ns5:state state_ref="state_rhevh_rhel10_version" />
    </ns5:textfilecontent54_test>
    <ns5:family_test id="test_rhel8_unix_family" version="1" check="all" comment="installed OS part of unix family" state_operator="AND">
      <ns5:object object_ref="obj_rhel8_unix_family" />
      <ns5:state state_ref="state_rhel8_unix_family" />
    </ns5:family_test>
    <ns3:rpminfo_test id="test_rhel8" version="1" check="all" comment="redhat-release is version 8" state_operator="AND">
      <ns3:object object_ref="obj_rhel8" />
      <ns3:state state_ref="state_rhel8" />
    </ns3:rpminfo_test>
    <ns3:rpminfo_test id="test_rhel8_0" version="1" check="all" comment="redhat-release is version 8.0" state_operator="AND">
      <ns3:object object_ref="obj_rhel8_0" />
      <ns3:state state_ref="state_rhel8_0" />
    </ns3:rpminfo_test>
    <ns3:rpminfo_test id="test_rhel8_1" version="1" check="all" comment="redhat-release is version 8.1" state_operator="AND">
      <ns3:object object_ref="obj_rhel8_1" />
      <ns3:state state_ref="state_rhel8_1" />
    </ns3:rpminfo_test>
    <ns3:rpminfo_test id="test_rhel8_2" version="1" check="all" comment="redhat-release is version 8.2" state_operator="AND">
      <ns3:object object_ref="obj_rhel8_2" />
      <ns3:state state_ref="state_rhel8_2" />
    </ns3:rpminfo_test>
    <ns3:rpminfo_test id="test_rhel8_3" version="1" check="all" comment="redhat-release is version 8.3" state_operator="AND">
      <ns3:object object_ref="obj_rhel8_3" />
      <ns3:state state_ref="state_rhel8_3" />
    </ns3:rpminfo_test>
    <ns3:rpminfo_test id="test_rhel8_4" version="1" check="all" comment="redhat-release is version 8.4" state_operator="AND">
      <ns3:object object_ref="obj_rhel8_4" />
      <ns3:state state_ref="state_rhel8_4" />
    </ns3:rpminfo_test>
    <ns3:rpminfo_test id="test_rhel8_5" version="1" check="all" comment="redhat-release is version 8.5" state_operator="AND">
      <ns3:object object_ref="obj_rhel8_5" />
      <ns3:state state_ref="state_rhel8_5" />
    </ns3:rpminfo_test>
    <ns3:rpminfo_test id="test_rhel8_6" version="1" check="all" comment="redhat-release is version 8.6" state_operator="AND">
      <ns3:object object_ref="obj_rhel8_6" />
      <ns3:state state_ref="state_rhel8_6" />
    </ns3:rpminfo_test>
    <ns3:rpminfo_test id="test_rhel8_7" version="1" check="all" comment="redhat-release is version 8.7" state_operator="AND">
      <ns3:object object_ref="obj_rhel8_7" />
      <ns3:state state_ref="state_rhel8_7" />
    </ns3:rpminfo_test>
    <ns3:rpminfo_test id="test_rhel8_8" version="1" check="all" comment="redhat-release is version 8.8" state_operator="AND">
      <ns3:object object_ref="obj_rhel8_8" />
      <ns3:state state_ref="state_rhel8_8" />
    </ns3:rpminfo_test>
    <ns3:rpminfo_test id="test_rhel8_9" version="1" check="all" comment="redhat-release is version 8.9" state_operator="AND">
      <ns3:object object_ref="obj_rhel8_9" />
      <ns3:state state_ref="state_rhel8_9" />
    </ns3:rpminfo_test>
    <ns3:rpminfo_test id="test_rhel8_10" version="1" check="all" comment="redhat-release is version 8.10" state_operator="AND">
      <ns3:object object_ref="obj_rhel8_10" />
      <ns3:state state_ref="state_rhel8_10" />
    </ns3:rpminfo_test>
    <ns5:textfilecontent54_test id="test_rhevh_rhel8_version" version="1" check="all" comment="RHEVH base RHEL is version 8" state_operator="AND">
      <ns5:object object_ref="obj_rhevh_rhel8_version" />
      <ns5:state state_ref="state_rhevh_rhel8_version" />
    </ns5:textfilecontent54_test>
    <ns5:family_test id="test_rhel9_unix_family" version="1" check="all" comment="installed OS part of unix family" state_operator="AND">
      <ns5:object object_ref="obj_rhel9_unix_family" />
      <ns5:state state_ref="state_rhel9_unix_family" />
    </ns5:family_test>
    <ns3:rpminfo_test id="test_rhel9" version="1" check="all" comment="redhat-release is version 9" state_operator="AND">
      <ns3:object object_ref="obj_rhel9" />
      <ns3:state state_ref="state_rhel9" />
    </ns3:rpminfo_test>
    <ns5:textfilecontent54_test id="test_rhevh_rhel9_version" version="1" check="all" comment="RHEVH base RHEL is version 9" state_operator="AND">
      <ns5:object object_ref="obj_rhevh_rhel9_version" />
      <ns5:state state_ref="state_rhevh_rhel9_version" />
    </ns5:textfilecontent54_test>
    <ns3:rpminfo_test id="test_rhvh4_version" version="1" check="all" comment="redhat-release-virtualization-host RPM package is installed" check_existence="only_one_exists" state_operator="AND">
      <ns3:object object_ref="obj_rhvh4_version" />
      <ns3:state state_ref="state_rhvh4_version" />
    </ns3:rpminfo_test>
    <ns5:family_test id="test_sle12_unix_family" version="1" check="all" comment="installed OS part of unix family" state_operator="AND">
      <ns5:object object_ref="obj_sle12_unix_family" />
      <ns5:state state_ref="state_sle12_unix_family" />
    </ns5:family_test>
    <ns3:rpminfo_test id="test_sle12_desktop" version="1" check="all" comment="sled-release is version 6" state_operator="AND">
      <ns3:object object_ref="obj_sle12_desktop" />
      <ns3:state state_ref="state_sle12_desktop" />
    </ns3:rpminfo_test>
    <ns3:rpminfo_test id="test_sle12_server" version="1" check="all" comment="sles-release is version 6" state_operator="AND">
      <ns3:object object_ref="obj_sle12_server" />
      <ns3:state state_ref="state_sle12_server" />
    </ns3:rpminfo_test>
    <ns3:rpminfo_test id="test_sles_12_for_sap" version="1" check="all" comment="SLES_SAP-release is version 12" state_operator="AND">
      <ns3:object object_ref="obj_sles_12_for_sap" />
      <ns3:state state_ref="state_sles_12_for_sap" />
    </ns3:rpminfo_test>
    <ns5:family_test id="test_sle15_unix_family" version="1" check="all" comment="installed OS part of unix family" state_operator="AND">
      <ns5:object object_ref="obj_sle15_unix_family" />
      <ns5:state state_ref="state_sle15_unix_family" />
    </ns5:family_test>
    <ns3:rpminfo_test id="test_sle15_desktop" version="1" check="all" comment="sled-release is version 15" state_operator="AND">
      <ns3:object object_ref="obj_sle15_desktop" />
      <ns3:state state_ref="state_sle15_desktop" />
    </ns3:rpminfo_test>
    <ns3:rpminfo_test id="test_sle15_server" version="1" check="all" comment="sles-release is version 15" state_operator="AND">
      <ns3:object object_ref="obj_sle15_server" />
      <ns3:state state_ref="state_sle15_server" />
    </ns3:rpminfo_test>
    <ns3:rpminfo_test id="test_sles_15_for_sap" version="1" check="all" comment="SLES_SAP-release is version 15" state_operator="AND">
      <ns3:object object_ref="obj_sles_15_for_sap" />
      <ns3:state state_ref="state_sles_15_for_sap" />
    </ns3:rpminfo_test>
    <ns3:rpminfo_test id="test_suma_4" version="1" check="all" comment="SUMA is version 4" state_operator="AND">
      <ns3:object object_ref="obj_suma_4" />
      <ns3:state state_ref="state_suma_4" />
    </ns3:rpminfo_test>
    <ns3:rpminfo_test id="test_sle_hpc" version="1" check="all" comment="SLE HPC release is version 15" state_operator="AND">
      <ns3:object object_ref="obj_sle_hpc" />
      <ns3:state state_ref="state_sle_hpc" />
    </ns3:rpminfo_test>
    <ns5:family_test id="test_sle16_unix_family" version="1" check="all" comment="installed OS part of unix family" state_operator="AND">
      <ns5:object object_ref="obj_sle16_unix_family" />
      <ns5:state state_ref="state_sle16_unix_family" />
    </ns5:family_test>
    <ns3:rpminfo_test id="test_sle16_server" version="1" check="all" comment="SLES-release is version 16" state_operator="AND">
      <ns3:object object_ref="obj_sle16_server" />
      <ns3:state state_ref="state_sle16_server" />
    </ns3:rpminfo_test>
    <ns3:rpminfo_test id="test_sles_16_for_sap" version="1" check="all" comment="SLES_SAP-release is version 16" state_operator="AND">
      <ns3:object object_ref="obj_sles_16_for_sap" />
      <ns3:state state_ref="state_sles_16_for_sap" />
    </ns3:rpminfo_test>
    <ns3:rpminfo_test id="test_sles_16_for_ha" version="1" check="all" comment="sle-ha-release is version 16" state_operator="AND">
      <ns3:object object_ref="obj_sles_16_for_ha" />
      <ns3:state state_ref="state_sles_16_for_ha" />
    </ns3:rpminfo_test>
    <ns5:family_test id="test_slmicro5_unix_family" version="1" check="all" comment="installed OS part of unix family" state_operator="AND">
      <ns5:object object_ref="obj_slmicro5_unix_family" />
      <ns5:state state_ref="state_slmicro5_unix_family" />
    </ns5:family_test>
    <ns3:rpminfo_test id="test_slmicroos5" version="1" check="all" comment="sle-micro-release is version 5" state_operator="AND">
      <ns3:object object_ref="obj_slmicroos5" />
      <ns3:state state_ref="state_slmicroos5" />
    </ns3:rpminfo_test>
    <ns3:rpminfo_test id="test_slmicro5" version="1" check="all" comment="sle-micro-release is version 5" state_operator="AND">
      <ns3:object object_ref="obj_slmicro5" />
      <ns3:state state_ref="state_slmicro5" />
    </ns3:rpminfo_test>
    <ns5:family_test id="test_slmicro6_unix_family" version="1" check="all" comment="installed OS part of unix family" state_operator="AND">
      <ns5:object object_ref="obj_slmicro6_unix_family" />
      <ns5:state state_ref="state_slmicro6_unix_family" />
    </ns5:family_test>
    <ns3:rpminfo_test id="test_slmicro6" version="1" check="all" comment="sle-micro-release is version 6" state_operator="AND">
      <ns3:object object_ref="obj_slmicro6" />
      <ns3:state state_ref="state_slmicro6" />
    </ns3:rpminfo_test>
    <ns3:rpminfo_test id="test_tencentos4" version="1" check="all" comment="tencentos-release is version 4" state_operator="AND">
      <ns3:object object_ref="obj_tencentos4" />
      <ns3:state state_ref="state_tencentos4" />
    </ns3:rpminfo_test>
    <ns4:file_test id="test_lsb" version="1" check="all" comment="/etc/lsb-release exists" check_existence="all_exist" state_operator="AND">
      <ns4:object object_ref="obj_lsb" />
    </ns4:file_test>
    <ns5:textfilecontent54_test id="test_ubuntu" version="1" check="all" comment="Check Ubuntu" state_operator="AND">
      <ns5:object object_ref="obj_ubuntu" />
    </ns5:textfilecontent54_test>
    <ns5:textfilecontent54_test id="test_ubuntu_jammy" version="1" check="all" comment="Check Ubuntu version" state_operator="AND">
      <ns5:object object_ref="obj_ubuntu_jammy" />
    </ns5:textfilecontent54_test>
    <ns5:textfilecontent54_test id="test_ubuntu_noble" version="1" check="all" comment="Check Ubuntu version" state_operator="AND">
      <ns5:object object_ref="obj_ubuntu_noble" />
    </ns5:textfilecontent54_test>
    <ns3:dpkginfo_test id="test_env_has_zipl_installed" version="1" check="all" comment="system has package zipl installed" check_existence="all_exist" state_operator="AND">
      <ns3:object object_ref="obj_env_has_zipl_installed" />
    </ns3:dpkginfo_test>
    <ns5:environmentvariable58_test id="test_installed_env_is_osbuild" version="1" check="all" comment="environment variable container is set to bwrap-osbuild" check_existence="all_exist" state_operator="AND">
      <ns5:object object_ref="object_installed_env_is_osbuild" />
      <ns5:state state_ref="state_installed_env_is_osbuild" />
    </ns5:environmentvariable58_test>
    <ns5:textfilecontent54_test id="test_no_cd_dvd_drive_in_etc_fstab" version="1" check="all" comment="'CD/DVD drive is not listed in /etc/fstab" check_existence="none_exist" state_operator="AND">
      <ns5:object object_ref="object_no_cd_dvd_drive_in_etc_fstab" />
    </ns5:textfilecontent54_test>
    <ns4:file_test id="test_removable_partition_doesnt_exist" version="1" check="all" comment="Check if expected removable partitions truly exist on the system" check_existence="none_exist" state_operator="AND">
      <ns4:object object_ref="object_removable_partition_doesnt_exist" />
    </ns4:file_test>
    <ns5:variable_test id="test_sshd_not_required" version="1" check="all" comment="Verify if Profile set Value sshd_required as not required" state_operator="AND">
      <ns5:object object_ref="object_sshd_not_required" />
      <ns5:state state_ref="state_sshd_not_required" />
    </ns5:variable_test>
    <ns5:variable_test id="test_sshd_required" version="1" check="all" comment="Verify if Profile set Value sshd_required as required" state_operator="AND">
      <ns5:object object_ref="object_sshd_required" />
      <ns5:state state_ref="state_sshd_required" />
    </ns5:variable_test>
    <ns5:variable_test id="test_sshd_requirement_unset" version="1" check="all" comment="Verify if Value of sshd_required is the default" state_operator="AND">
      <ns5:object object_ref="object_sshd_requirement_unknown" />
      <ns5:state state_ref="state_sshd_requirement_unset" />
    </ns5:variable_test>
    <ns3:dpkginfo_test id="test_openssh-server_version" version="1" check="at least one" comment="OpenSSH is version 7.4 or higher" check_existence="any_exist" state_operator="AND">
      <ns3:object object_ref="obj_openssh-server_version" />
      <ns3:state state_ref="state_openssh-server_version" />
    </ns3:dpkginfo_test>
    <ns4:uname_test id="test_system_info_architecture_aarch_64" version="1" check="all" comment="64 bit architecture" state_operator="AND">
      <ns4:object object_ref="object_system_info_architecture_aarch_64" />
      <ns4:state state_ref="state_system_info_architecture_aarch_64" />
    </ns4:uname_test>
    <ns4:uname_test id="test_system_info_architecture_ppc_64" version="1" check="all" comment="64 bit architecture" state_operator="AND">
      <ns4:object object_ref="object_system_info_architecture_ppc_64" />
      <ns4:state state_ref="state_system_info_architecture_ppc_64" />
    </ns4:uname_test>
    <ns4:uname_test id="test_system_info_architecture_ppcle_64" version="1" check="all" comment="64 bit architecture" state_operator="AND">
      <ns4:object object_ref="object_system_info_architecture_ppcle_64" />
      <ns4:state state_ref="state_system_info_architecture_ppcle_64" />
    </ns4:uname_test>
    <ns4:uname_test id="test_system_info_architecture_s390_64" version="1" check="all" comment="64 bit architecture" state_operator="AND">
      <ns4:object object_ref="object_system_info_architecture_s390_64" />
      <ns4:state state_ref="state_system_info_architecture_s390_64" />
    </ns4:uname_test>
    <ns4:uname_test id="test_system_info_architecture_x86" version="1" check="all" comment="32 bit architecture" state_operator="AND">
      <ns4:object object_ref="object_system_info_architecture_x86" />
      <ns4:state state_ref="state_system_info_architecture_x86" />
    </ns4:uname_test>
    <ns4:uname_test id="test_system_info_architecture_x86_64" version="1" check="all" comment="64 bit architecture" state_operator="AND">
      <ns4:object object_ref="object_system_info_architecture_x86_64" />
      <ns4:state state_ref="state_system_info_architecture_x86_64" />
    </ns4:uname_test>
    <ns4:file_test id="test_tmux_conf_readable_by_others" version="1" check="all" comment="Check /etc/tmux.conf is readable by others" state_operator="AND">
      <ns4:object object_ref="object_tmux_conf_readable_by_others" />
      <ns4:state state_ref="state_tmux_conf_readable_by_others" />
    </ns4:file_test>
    <ns5:textfilecontent54_test id="test_usbguard_rules_nonempty" version="1" check="all" comment="Check the usbguard rules in either /etc/usbguard/rules.conf or /etc/usbguard/rules.d/ contain at least one non whitespace character and exists" state_operator="AND">
      <ns5:object object_ref="obj_usbguard_rules_nonempty" />
    </ns5:textfilecontent54_test>
    <ns5:variable_test id="test_existence_of_var_accounts_user_umask_as_number_variable" version="1" check="all" comment="Verify the existence of var_accounts_user_umask_as_number variable" state_operator="AND">
      <ns5:object object_ref="object_var_accounts_user_umask_umask_as_number" />
    </ns5:variable_test>
    <ns5:variable_test id="test_var_removable_partition_is_cd_dvd_drive" version="1" check="all" comment="Check if removable partition variable value represents CD/DVD drive" state_operator="AND">
      <ns5:object object_ref="object_var_removable_partition_is_cd_dvd_drive" />
      <ns5:state state_ref="state_var_removable_partition_is_cd_dvd_drive" />
    </ns5:variable_test>
    <ns5:variable_test id="test_existence_of_var_umask_for_daemons_as_number_variable" version="1" check="all" comment="Verify the existence of var_umask_for_daemons_as_number variable" state_operator="AND">
      <ns5:object object_ref="object_var_umask_for_daemons_umask_as_number" />
    </ns5:variable_test>
    <ns5:textfilecontent54_test id="test_grub2_ipv6_disable_is_correct" version="1" check="all" comment="check GRUB_CMDLINE_LINUX parameters in /etc/default/grub" check_existence="all_exist" state_operator="AND">
      <ns5:object object_ref="object_grub2_ipv6_disable_parameter" />
      <ns5:state state_ref="state_grub2_ipv6_disable_argument" />
    </ns5:textfilecontent54_test>
    <ns5:textfilecontent54_test id="test_grub2_ipv6_disable_is_absent" version="1" check="all" comment="ipv6.disable is not defined in /etc/default/grub" check_existence="none_exist" state_operator="AND">
      <ns5:object object_ref="object_grub2_ipv6_disable_parameter" />
    </ns5:textfilecontent54_test>
    <ns3:partition_test id="test_mount_active_boot_efi_exists" version="1" check="all" comment="Mountpoint /boot/efi exists" check_existence="all_exist" state_operator="AND">
      <ns3:object object_ref="object_mount_active_boot_efi_exists" />
    </ns3:partition_test>
    <ns5:textfilecontent54_test id="test_mount_configured_fstab_boot_efi_exists" version="1" check="all" comment="Mountpoint /boot/efi is configured" check_existence="all_exist" state_operator="AND">
      <ns5:object object_ref="object_mount_configured_fstab_boot_efi_exists" />
    </ns5:textfilecontent54_test>
    <ns3:partition_test id="test_mount_active_home_exists" version="1" check="all" comment="Mountpoint /home exists" check_existence="all_exist" state_operator="AND">
      <ns3:object object_ref="object_mount_active_home_exists" />
    </ns3:partition_test>
    <ns5:textfilecontent54_test id="test_mount_configured_fstab_home_exists" version="1" check="all" comment="Mountpoint /home is configured" check_existence="all_exist" state_operator="AND">
      <ns5:object object_ref="object_mount_configured_fstab_home_exists" />
    </ns5:textfilecontent54_test>
    <ns3:partition_test id="test_mount_active_opt_exists" version="1" check="all" comment="Mountpoint /opt exists" check_existence="all_exist" state_operator="AND">
      <ns3:object object_ref="object_mount_active_opt_exists" />
    </ns3:partition_test>
    <ns5:textfilecontent54_test id="test_mount_configured_fstab_opt_exists" version="1" check="all" comment="Mountpoint /opt is configured" check_existence="all_exist" state_operator="AND">
      <ns5:object object_ref="object_mount_configured_fstab_opt_exists" />
    </ns5:textfilecontent54_test>
    <ns3:partition_test id="test_mount_active_srv_exists" version="1" check="all" comment="Mountpoint /srv exists" check_existence="all_exist" state_operator="AND">
      <ns3:object object_ref="object_mount_active_srv_exists" />
    </ns3:partition_test>
    <ns5:textfilecontent54_test id="test_mount_configured_fstab_srv_exists" version="1" check="all" comment="Mountpoint /srv is configured" check_existence="all_exist" state_operator="AND">
      <ns5:object object_ref="object_mount_configured_fstab_srv_exists" />
    </ns5:textfilecontent54_test>
    <ns3:partition_test id="test_mount_active_tmp_exists" version="1" check="all" comment="Mountpoint /tmp exists" check_existence="all_exist" state_operator="AND">
      <ns3:object object_ref="object_mount_active_tmp_exists" />
    </ns3:partition_test>
    <ns5:textfilecontent54_test id="test_mount_configured_fstab_tmp_exists" version="1" check="all" comment="Mountpoint /tmp is configured" check_existence="all_exist" state_operator="AND">
      <ns5:object object_ref="object_mount_configured_fstab_tmp_exists" />
    </ns5:textfilecontent54_test>
    <ns3:partition_test id="test_mount_active_var_log_audit_exists" version="1" check="all" comment="Mountpoint /var/log/audit exists" check_existence="all_exist" state_operator="AND">
      <ns3:object object_ref="object_mount_active_var_log_audit_exists" />
    </ns3:partition_test>
    <ns5:textfilecontent54_test id="test_mount_configured_fstab_var_log_audit_exists" version="1" check="all" comment="Mountpoint /var/log/audit is configured" check_existence="all_exist" state_operator="AND">
      <ns5:object object_ref="object_mount_configured_fstab_var_log_audit_exists" />
    </ns5:textfilecontent54_test>
    <ns3:partition_test id="test_mount_active_var_log_exists" version="1" check="all" comment="Mountpoint /var/log exists" check_existence="all_exist" state_operator="AND">
      <ns3:object object_ref="object_mount_active_var_log_exists" />
    </ns3:partition_test>
    <ns5:textfilecontent54_test id="test_mount_configured_fstab_var_log_exists" version="1" check="all" comment="Mountpoint /var/log is configured" check_existence="all_exist" state_operator="AND">
      <ns5:object object_ref="object_mount_configured_fstab_var_log_exists" />
    </ns5:textfilecontent54_test>
    <ns3:partition_test id="test_mount_active_var_tmp_exists" version="1" check="all" comment="Mountpoint /var/tmp exists" check_existence="all_exist" state_operator="AND">
      <ns3:object object_ref="object_mount_active_var_tmp_exists" />
    </ns3:partition_test>
    <ns5:textfilecontent54_test id="test_mount_configured_fstab_var_tmp_exists" version="1" check="all" comment="Mountpoint /var/tmp is configured" check_existence="all_exist" state_operator="AND">
      <ns5:object object_ref="object_mount_configured_fstab_var_tmp_exists" />
    </ns5:textfilecontent54_test>
    <ns3:partition_test id="test_mount_active_var_exists" version="1" check="all" comment="Mountpoint /var exists" check_existence="all_exist" state_operator="AND">
      <ns3:object object_ref="object_mount_active_var_exists" />
    </ns3:partition_test>
    <ns5:textfilecontent54_test id="test_mount_configured_fstab_var_exists" version="1" check="all" comment="Mountpoint /var is configured" check_existence="all_exist" state_operator="AND">
      <ns5:object object_ref="object_mount_configured_fstab_var_exists" />
    </ns5:textfilecontent54_test>
    <ns5:textfilecontent54_test id="test_os_id_is_os_linux_ol_gt_or_eq_8_7" version="1" check="all" comment="ID in os-release is ol" state_operator="AND">
      <ns5:object object_ref="obj_os_id_is_os_linux_ol_gt_or_eq_8_7" />
      <ns5:state state_ref="state_os_id_is_os_linux_ol_gt_or_eq_8_7" />
    </ns5:textfilecontent54_test>
    <ns5:textfilecontent54_test id="test_os_linux_ol_gt_or_eq_8_7_gt_or_eq_8_7" version="1" check="all" comment="VERSION_ID in os-release is greater than or equal 8.7" state_operator="AND">
      <ns5:object object_ref="obj_os_linux_ol_gt_or_eq_8_7_gt_or_eq_8_7" />
      <ns5:state state_ref="state_os_linux_ol_gt_or_eq_8_7_gt_or_eq_8_7" />
    </ns5:textfilecontent54_test>
    <ns5:textfilecontent54_test id="test_os_id_is_os_linux_ol_gt_or_eq_9_0" version="1" check="all" comment="ID in os-release is ol" state_operator="AND">
      <ns5:object object_ref="obj_os_id_is_os_linux_ol_gt_or_eq_9_0" />
      <ns5:state state_ref="state_os_id_is_os_linux_ol_gt_or_eq_9_0" />
    </ns5:textfilecontent54_test>
    <ns5:textfilecontent54_test id="test_os_linux_ol_gt_or_eq_9_0_gt_or_eq_9_0" version="1" check="all" comment="VERSION_ID in os-release is greater than or equal 9.0" state_operator="AND">
      <ns5:object object_ref="obj_os_linux_ol_gt_or_eq_9_0_gt_or_eq_9_0" />
      <ns5:state state_ref="state_os_linux_ol_gt_or_eq_9_0_gt_or_eq_9_0" />
    </ns5:textfilecontent54_test>
    <ns5:textfilecontent54_test id="test_os_id_is_os_linux_rhel_gt_or_eq_8_7" version="1" check="all" comment="ID in os-release is rhel" state_operator="AND">
      <ns5:object object_ref="obj_os_id_is_os_linux_rhel_gt_or_eq_8_7" />
      <ns5:state state_ref="state_os_id_is_os_linux_rhel_gt_or_eq_8_7" />
    </ns5:textfilecontent54_test>
    <ns5:textfilecontent54_test id="test_os_linux_rhel_gt_or_eq_8_7_gt_or_eq_8_7" version="1" check="all" comment="VERSION_ID in os-release is greater than or equal 8.7" state_operator="AND">
      <ns5:object object_ref="obj_os_linux_rhel_gt_or_eq_8_7_gt_or_eq_8_7" />
      <ns5:state state_ref="state_os_linux_rhel_gt_or_eq_8_7_gt_or_eq_8_7" />
    </ns5:textfilecontent54_test>
    <ns5:textfilecontent54_test id="test_os_id_is_os_linux_rhel_gt_or_eq_9_0" version="1" check="all" comment="ID in os-release is rhel" state_operator="AND">
      <ns5:object object_ref="obj_os_id_is_os_linux_rhel_gt_or_eq_9_0" />
      <ns5:state state_ref="state_os_id_is_os_linux_rhel_gt_or_eq_9_0" />
    </ns5:textfilecontent54_test>
    <ns5:textfilecontent54_test id="test_os_linux_rhel_gt_or_eq_9_0_gt_or_eq_9_0" version="1" check="all" comment="VERSION_ID in os-release is greater than or equal 9.0" state_operator="AND">
      <ns5:object object_ref="obj_os_linux_rhel_gt_or_eq_9_0_gt_or_eq_9_0" />
      <ns5:state state_ref="state_os_linux_rhel_gt_or_eq_9_0_gt_or_eq_9_0" />
    </ns5:textfilecontent54_test>
    <ns5:textfilecontent54_test id="test_os_id_is_os_linux_rhel_le_or_eq_8_4" version="1" check="all" comment="ID in os-release is rhel" state_operator="AND">
      <ns5:object object_ref="obj_os_id_is_os_linux_rhel_le_or_eq_8_4" />
      <ns5:state state_ref="state_os_id_is_os_linux_rhel_le_or_eq_8_4" />
    </ns5:textfilecontent54_test>
    <ns5:textfilecontent54_test id="test_os_linux_rhel_le_or_eq_8_4_le_or_eq_8_4" version="1" check="all" comment="VERSION_ID in os-release is less than or equal 8.4" state_operator="AND">
      <ns5:object object_ref="obj_os_linux_rhel_le_or_eq_8_4_le_or_eq_8_4" />
      <ns5:state state_ref="state_os_linux_rhel_le_or_eq_8_4_le_or_eq_8_4" />
    </ns5:textfilecontent54_test>
    <ns5:textfilecontent54_test id="test_os_id_is_os_linux_rhel_ne_9_0" version="1" check="all" comment="ID in os-release is rhel" state_operator="AND">
      <ns5:object object_ref="obj_os_id_is_os_linux_rhel_ne_9_0" />
      <ns5:state state_ref="state_os_id_is_os_linux_rhel_ne_9_0" />
    </ns5:textfilecontent54_test>
    <ns5:textfilecontent54_test id="test_os_linux_rhel_ne_9_0_ne_9_0" version="1" check="all" comment="VERSION_ID in os-release is not equal 9.0" state_operator="AND">
      <ns5:object object_ref="obj_os_linux_rhel_ne_9_0_ne_9_0" />
      <ns5:state state_ref="state_os_linux_rhel_ne_9_0_ne_9_0" />
    </ns5:textfilecontent54_test>
    <ns5:textfilecontent54_test id="test_os_id_is_os_linux_sles_gt_or_eq_15" version="1" check="all" comment="ID in os-release is sles" state_operator="AND">
      <ns5:object object_ref="obj_os_id_is_os_linux_sles_gt_or_eq_15" />
      <ns5:state state_ref="state_os_id_is_os_linux_sles_gt_or_eq_15" />
    </ns5:textfilecontent54_test>
    <ns5:textfilecontent54_test id="test_os_linux_sles_gt_or_eq_15_gt_or_eq_15" version="1" check="all" comment="VERSION_ID in os-release is greater than or equal 15" state_operator="AND">
      <ns5:object object_ref="obj_os_linux_sles_gt_or_eq_15_gt_or_eq_15" />
      <ns5:state state_ref="state_os_linux_sles_gt_or_eq_15_gt_or_eq_15" />
    </ns5:textfilecontent54_test>
    <ns3:dpkginfo_test id="inventory_test_package_aide_installed" version="1" check="all" comment="package aide is installed" check_existence="all_exist" state_operator="AND">
      <ns3:object object_ref="obj_inventory_test_package_aide_installed" />
    </ns3:dpkginfo_test>
    <ns3:dpkginfo_test id="inventory_test_package_apparmor_installed" version="1" check="all" comment="package apparmor is installed" check_existence="all_exist" state_operator="AND">
      <ns3:object object_ref="obj_inventory_test_package_apparmor_installed" />
    </ns3:dpkginfo_test>
    <ns3:dpkginfo_test id="inventory_test_package_apport_installed" version="1" check="all" comment="package apport is installed" check_existence="all_exist" state_operator="AND">
      <ns3:object object_ref="obj_inventory_test_package_apport_installed" />
    </ns3:dpkginfo_test>
    <ns3:dpkginfo_test id="inventory_test_package_apt_get_installed" version="1" check="all" comment="package apt is installed" check_existence="all_exist" state_operator="AND">
      <ns3:object object_ref="obj_inventory_test_package_apt_get_installed" />
    </ns3:dpkginfo_test>
    <ns3:dpkginfo_test id="inventory_test_package_audit_installed" version="1" check="all" comment="package auditd is installed" check_existence="all_exist" state_operator="AND">
      <ns3:object object_ref="obj_inventory_test_package_audit_installed" />
    </ns3:dpkginfo_test>
    <ns3:dpkginfo_test id="inventory_test_package_autofs_installed" version="1" check="all" comment="package autofs is installed" check_existence="all_exist" state_operator="AND">
      <ns3:object object_ref="obj_inventory_test_package_autofs_installed" />
    </ns3:dpkginfo_test>
    <ns3:dpkginfo_test id="inventory_test_package_avahi_installed" version="1" check="all" comment="package avahi-daemon is installed" check_existence="all_exist" state_operator="AND">
      <ns3:object object_ref="obj_inventory_test_package_avahi_installed" />
    </ns3:dpkginfo_test>
    <ns3:dpkginfo_test id="inventory_test_package_bash_installed" version="1" check="all" comment="package bash is installed" check_existence="all_exist" state_operator="AND">
      <ns3:object object_ref="obj_inventory_test_package_bash_installed" />
    </ns3:dpkginfo_test>
    <ns3:dpkginfo_test id="inventory_test_package_bind_installed" version="1" check="all" comment="package bind is installed" check_existence="all_exist" state_operator="AND">
      <ns3:object object_ref="obj_inventory_test_package_bind_installed" />
    </ns3:dpkginfo_test>
    <ns3:dpkginfo_test id="inventory_test_package_chrony_installed" version="1" check="all" comment="package chrony is installed" check_existence="all_exist" state_operator="AND">
      <ns3:object object_ref="obj_inventory_test_package_chrony_installed" />
    </ns3:dpkginfo_test>
    <ns3:dpkginfo_test id="inventory_test_package_firewalld_installed" version="1" check="all" comment="package firewalld is installed" check_existence="all_exist" state_operator="AND">
      <ns3:object object_ref="obj_inventory_test_package_firewalld_installed" />
    </ns3:dpkginfo_test>
    <ns3:dpkginfo_test id="inventory_test_package_gdm_installed" version="1" check="all" comment="package gdm3 is installed" check_existence="all_exist" state_operator="AND">
      <ns3:object object_ref="obj_inventory_test_package_gdm_installed" />
    </ns3:dpkginfo_test>
    <ns3:dpkginfo_test id="inventory_test_package_iptables_installed" version="1" check="all" comment="package iptables is installed" check_existence="all_exist" state_operator="AND">
      <ns3:object object_ref="obj_inventory_test_package_iptables_installed" />
    </ns3:dpkginfo_test>
    <ns3:dpkginfo_test id="inventory_test_package_libpwquality_installed" version="1" check="all" comment="package libpwquality1 is installed" check_existence="all_exist" state_operator="AND">
      <ns3:object object_ref="obj_inventory_test_package_libpwquality_installed" />
    </ns3:dpkginfo_test>
    <ns3:dpkginfo_test id="inventory_test_package_libreswan_installed" version="1" check="all" comment="package libreswan is installed" check_existence="all_exist" state_operator="AND">
      <ns3:object object_ref="obj_inventory_test_package_libreswan_installed" />
    </ns3:dpkginfo_test>
    <ns3:dpkginfo_test id="inventory_test_package_libuser_installed" version="1" check="all" comment="package libuser is installed" check_existence="all_exist" state_operator="AND">
      <ns3:object object_ref="obj_inventory_test_package_libuser_installed" />
    </ns3:dpkginfo_test>
    <ns3:dpkginfo_test id="inventory_test_package_logrotate_installed" version="1" check="all" comment="package logrotate is installed" check_existence="all_exist" state_operator="AND">
      <ns3:object object_ref="obj_inventory_test_package_logrotate_installed" />
    </ns3:dpkginfo_test>
    <ns3:dpkginfo_test id="inventory_test_package_net-snmp_installed" version="1" check="all" comment="package snmp is installed" check_existence="all_exist" state_operator="AND">
      <ns3:object object_ref="obj_inventory_test_package_net-snmp_installed" />
    </ns3:dpkginfo_test>
    <ns3:dpkginfo_test id="inventory_test_package_networkmanager_installed" version="1" check="all" comment="package network-manager is installed" check_existence="all_exist" state_operator="AND">
      <ns3:object object_ref="obj_inventory_test_package_networkmanager_installed" />
    </ns3:dpkginfo_test>
    <ns3:dpkginfo_test id="inventory_test_package_nftables_installed" version="1" check="all" comment="package nftables is installed" check_existence="all_exist" state_operator="AND">
      <ns3:object object_ref="obj_inventory_test_package_nftables_installed" />
    </ns3:dpkginfo_test>
    <ns3:dpkginfo_test id="inventory_test_package_nss-pam-ldapd_installed" version="1" check="all" comment="package libpam-ldapd is installed" check_existence="all_exist" state_operator="AND">
      <ns3:object object_ref="obj_inventory_test_package_nss-pam-ldapd_installed" />
    </ns3:dpkginfo_test>
    <ns3:dpkginfo_test id="inventory_test_package_ntp_installed" version="1" check="all" comment="package ntp is installed" check_existence="all_exist" state_operator="AND">
      <ns3:object object_ref="obj_inventory_test_package_ntp_installed" />
    </ns3:dpkginfo_test>
    <ns3:dpkginfo_test id="inventory_test_package_openssh-server_le_7_0_le_7_0_installed" version="1" check="all" comment="package openssh-server is installed" check_existence="all_exist" state_operator="AND">
      <ns3:object object_ref="obj_inventory_test_package_openssh-server_le_7_0_le_7_0_installed" />
      <ns3:state state_ref="ste_inventory_test_package_openssh-server_le_7_0_le_7_0_installed" />
    </ns3:dpkginfo_test>
    <ns3:dpkginfo_test id="inventory_test_package_openssh-server_le_7_5_le_7_5_installed" version="1" check="all" comment="package openssh-server is installed" check_existence="all_exist" state_operator="AND">
      <ns3:object object_ref="obj_inventory_test_package_openssh-server_le_7_5_le_7_5_installed" />
      <ns3:state state_ref="ste_inventory_test_package_openssh-server_le_7_5_le_7_5_installed" />
    </ns3:dpkginfo_test>
    <ns3:dpkginfo_test id="inventory_test_package_openssh_installed" version="1" check="all" comment="package openssh is installed" check_existence="all_exist" state_operator="AND">
      <ns3:object object_ref="obj_inventory_test_package_openssh_installed" />
    </ns3:dpkginfo_test>
    <ns3:dpkginfo_test id="inventory_test_package_pam_installed" version="1" check="all" comment="package libpam-runtime is installed" check_existence="all_exist" state_operator="AND">
      <ns3:object object_ref="obj_inventory_test_package_pam_installed" />
    </ns3:dpkginfo_test>
    <ns3:dpkginfo_test id="inventory_test_package_pam_apparmor_installed" version="1" check="all" comment="package pam_apparmor is installed" check_existence="all_exist" state_operator="AND">
      <ns3:object object_ref="obj_inventory_test_package_pam_apparmor_installed" />
    </ns3:dpkginfo_test>
    <ns3:dpkginfo_test id="inventory_test_package_polkit_installed" version="1" check="all" comment="package polkit is installed" check_existence="all_exist" state_operator="AND">
      <ns3:object object_ref="obj_inventory_test_package_polkit_installed" />
    </ns3:dpkginfo_test>
    <ns3:dpkginfo_test id="inventory_test_package_postfix_installed" version="1" check="all" comment="package postfix is installed" check_existence="all_exist" state_operator="AND">
      <ns3:object object_ref="obj_inventory_test_package_postfix_installed" />
    </ns3:dpkginfo_test>
    <ns3:dpkginfo_test id="inventory_test_package_rootfiles_installed" version="1" check="all" comment="package rootfiles is installed" check_existence="all_exist" state_operator="AND">
      <ns3:object object_ref="obj_inventory_test_package_rootfiles_installed" />
    </ns3:dpkginfo_test>
    <ns3:dpkginfo_test id="inventory_test_package_rsh-server_installed" version="1" check="all" comment="package rsh-server is installed" check_existence="all_exist" state_operator="AND">
      <ns3:object object_ref="obj_inventory_test_package_rsh-server_installed" />
    </ns3:dpkginfo_test>
    <ns3:dpkginfo_test id="inventory_test_package_rsyslog_installed" version="1" check="all" comment="package rsyslog is installed" check_existence="all_exist" state_operator="AND">
      <ns3:object object_ref="obj_inventory_test_package_rsyslog_installed" />
    </ns3:dpkginfo_test>
    <ns3:dpkginfo_test id="inventory_test_package_shadow-utils_installed" version="1" check="all" comment="package login is installed" check_existence="all_exist" state_operator="AND">
      <ns3:object object_ref="obj_inventory_test_package_shadow-utils_installed" />
    </ns3:dpkginfo_test>
    <ns3:dpkginfo_test id="inventory_test_package_snmpd_installed" version="1" check="all" comment="package net-snmp is installed" check_existence="all_exist" state_operator="AND">
      <ns3:object object_ref="obj_inventory_test_package_snmpd_installed" />
    </ns3:dpkginfo_test>
    <ns3:dpkginfo_test id="inventory_test_package_squid_installed" version="1" check="all" comment="package squid is installed" check_existence="all_exist" state_operator="AND">
      <ns3:object object_ref="obj_inventory_test_package_squid_installed" />
    </ns3:dpkginfo_test>
    <ns3:dpkginfo_test id="inventory_test_package_sssd_installed" version="1" check="all" comment="package sssd is installed" check_existence="all_exist" state_operator="AND">
      <ns3:object object_ref="obj_inventory_test_package_sssd_installed" />
    </ns3:dpkginfo_test>
    <ns3:dpkginfo_test id="inventory_test_package_sudo_installed" version="1" check="all" comment="package sudo is installed" check_existence="all_exist" state_operator="AND">
      <ns3:object object_ref="obj_inventory_test_package_sudo_installed" />
    </ns3:dpkginfo_test>
    <ns3:dpkginfo_test id="inventory_test_package_systemd-journal-remote_installed" version="1" check="all" comment="package systemd-journal-remote is installed" check_existence="all_exist" state_operator="AND">
      <ns3:object object_ref="obj_inventory_test_package_systemd-journal-remote_installed" />
    </ns3:dpkginfo_test>
    <ns3:dpkginfo_test id="inventory_test_package_systemd-timesyncd_installed" version="1" check="all" comment="package systemd-timesyncd is installed" check_existence="all_exist" state_operator="AND">
      <ns3:object object_ref="obj_inventory_test_package_systemd-timesyncd_installed" />
    </ns3:dpkginfo_test>
    <ns3:dpkginfo_test id="inventory_test_package_systemd_installed" version="1" check="all" comment="package systemd is installed" check_existence="all_exist" state_operator="AND">
      <ns3:object object_ref="obj_inventory_test_package_systemd_installed" />
    </ns3:dpkginfo_test>
    <ns3:dpkginfo_test id="inventory_test_package_telnet-server_installed" version="1" check="all" comment="package telnet-server is installed" check_existence="all_exist" state_operator="AND">
      <ns3:object object_ref="obj_inventory_test_package_telnet-server_installed" />
    </ns3:dpkginfo_test>
    <ns3:dpkginfo_test id="inventory_test_package_tftp-server_installed" version="1" check="all" comment="package tftp-server is installed" check_existence="all_exist" state_operator="AND">
      <ns3:object object_ref="obj_inventory_test_package_tftp-server_installed" />
    </ns3:dpkginfo_test>
    <ns3:dpkginfo_test id="inventory_test_package_tmux_installed" version="1" check="all" comment="package tmux is installed" check_existence="all_exist" state_operator="AND">
      <ns3:object object_ref="obj_inventory_test_package_tmux_installed" />
    </ns3:dpkginfo_test>
    <ns3:dpkginfo_test id="inventory_test_package_ufw_installed" version="1" check="all" comment="package ufw is installed" check_existence="all_exist" state_operator="AND">
      <ns3:object object_ref="obj_inventory_test_package_ufw_installed" />
    </ns3:dpkginfo_test>
    <ns3:dpkginfo_test id="inventory_test_package_usbguard_installed" version="1" check="all" comment="package usbguard is installed" check_existence="all_exist" state_operator="AND">
      <ns3:object object_ref="obj_inventory_test_package_usbguard_installed" />
    </ns3:dpkginfo_test>
    <ns3:systemdunitproperty_test id="test_service_not_running_service_disabled_firewalld_firewalld" version="1" check="all" comment="Test that the firewalld service is not running" check_existence="any_exist" state_operator="AND">
      <ns3:object object_ref="obj_service_not_running_service_disabled_firewalld_firewalld" />
      <ns3:state state_ref="state_service_not_running_service_disabled_firewalld_firewalld" />
    </ns3:systemdunitproperty_test>
    <ns3:systemdunitproperty_test id="test_service_loadstate_is_masked_service_disabled_firewalld_firewalld" version="1" check="all" comment="Test that the property LoadState from the service firewalld is masked" check_existence="any_exist" state_operator="AND">
      <ns3:object object_ref="obj_service_loadstate_is_masked_service_disabled_firewalld_firewalld" />
      <ns3:state state_ref="state_service_loadstate_is_masked_service_disabled_firewalld_firewalld" />
    </ns3:systemdunitproperty_test>
    <ns3:systemdunitproperty_test id="test_service_not_found_service_disabled_firewalld_firewalld" version="1" check="all" comment="Test that the service firewalld is not found" check_existence="any_exist" state_operator="AND">
      <ns3:object object_ref="obj_service_loadstate_is_masked_service_disabled_firewalld_firewalld" />
      <ns3:state state_ref="state_service_is_not_found_service_disabled_firewalld_firewalld" />
    </ns3:systemdunitproperty_test>
    <ns3:dpkginfo_test id="service_disabled_firewalldtest_service_firewalld_package_firewalld_removed" version="1" check="all" comment="package firewalld is removed" check_existence="none_exist" state_operator="AND">
      <ns3:object object_ref="obj_service_disabled_firewalldtest_service_firewalld_package_firewalld_removed" />
    </ns3:dpkginfo_test>
    <ns3:systemdunitproperty_test id="test_service_not_running_service_disabled_iptables_iptables" version="1" check="all" comment="Test that the iptables service is not running" check_existence="any_exist" state_operator="AND">
      <ns3:object object_ref="obj_service_not_running_service_disabled_iptables_iptables" />
      <ns3:state state_ref="state_service_not_running_service_disabled_iptables_iptables" />
    </ns3:systemdunitproperty_test>
    <ns3:systemdunitproperty_test id="test_service_loadstate_is_masked_service_disabled_iptables_iptables" version="1" check="all" comment="Test that the property LoadState from the service iptables is masked" check_existence="any_exist" state_operator="AND">
      <ns3:object object_ref="obj_service_loadstate_is_masked_service_disabled_iptables_iptables" />
      <ns3:state state_ref="state_service_loadstate_is_masked_service_disabled_iptables_iptables" />
    </ns3:systemdunitproperty_test>
    <ns3:systemdunitproperty_test id="test_service_not_found_service_disabled_iptables_iptables" version="1" check="all" comment="Test that the service iptables is not found" check_existence="any_exist" state_operator="AND">
      <ns3:object object_ref="obj_service_loadstate_is_masked_service_disabled_iptables_iptables" />
      <ns3:state state_ref="state_service_is_not_found_service_disabled_iptables_iptables" />
    </ns3:systemdunitproperty_test>
    <ns3:dpkginfo_test id="service_disabled_iptablestest_service_iptables_package_iptables_removed" version="1" check="all" comment="package iptables is removed" check_existence="none_exist" state_operator="AND">
      <ns3:object object_ref="obj_service_disabled_iptablestest_service_iptables_package_iptables_removed" />
    </ns3:dpkginfo_test>
    <ns3:systemdunitproperty_test id="test_service_not_running_service_disabled_nftables_nftables" version="1" check="all" comment="Test that the nftables service is not running" check_existence="any_exist" state_operator="AND">
      <ns3:object object_ref="obj_service_not_running_service_disabled_nftables_nftables" />
      <ns3:state state_ref="state_service_not_running_service_disabled_nftables_nftables" />
    </ns3:systemdunitproperty_test>
    <ns3:systemdunitproperty_test id="test_service_loadstate_is_masked_service_disabled_nftables_nftables" version="1" check="all" comment="Test that the property LoadState from the service nftables is masked" check_existence="any_exist" state_operator="AND">
      <ns3:object object_ref="obj_service_loadstate_is_masked_service_disabled_nftables_nftables" />
      <ns3:state state_ref="state_service_loadstate_is_masked_service_disabled_nftables_nftables" />
    </ns3:systemdunitproperty_test>
    <ns3:systemdunitproperty_test id="test_service_not_found_service_disabled_nftables_nftables" version="1" check="all" comment="Test that the service nftables is not found" check_existence="any_exist" state_operator="AND">
      <ns3:object object_ref="obj_service_loadstate_is_masked_service_disabled_nftables_nftables" />
      <ns3:state state_ref="state_service_is_not_found_service_disabled_nftables_nftables" />
    </ns3:systemdunitproperty_test>
    <ns3:dpkginfo_test id="service_disabled_nftablestest_service_nftables_package_nftables_removed" version="1" check="all" comment="package nftables is removed" check_existence="none_exist" state_operator="AND">
      <ns3:object object_ref="obj_service_disabled_nftablestest_service_nftables_package_nftables_removed" />
    </ns3:dpkginfo_test>
    <ns3:systemdunitproperty_test id="test_service_not_running_service_disabled_rsyslog_rsyslog" version="1" check="all" comment="Test that the rsyslog service is not running" check_existence="any_exist" state_operator="AND">
      <ns3:object object_ref="obj_service_not_running_service_disabled_rsyslog_rsyslog" />
      <ns3:state state_ref="state_service_not_running_service_disabled_rsyslog_rsyslog" />
    </ns3:systemdunitproperty_test>
    <ns3:systemdunitproperty_test id="test_service_loadstate_is_masked_service_disabled_rsyslog_rsyslog" version="1" check="all" comment="Test that the property LoadState from the service rsyslog is masked" check_existence="any_exist" state_operator="AND">
      <ns3:object object_ref="obj_service_loadstate_is_masked_service_disabled_rsyslog_rsyslog" />
      <ns3:state state_ref="state_service_loadstate_is_masked_service_disabled_rsyslog_rsyslog" />
    </ns3:systemdunitproperty_test>
    <ns3:systemdunitproperty_test id="test_service_not_found_service_disabled_rsyslog_rsyslog" version="1" check="all" comment="Test that the service rsyslog is not found" check_existence="any_exist" state_operator="AND">
      <ns3:object object_ref="obj_service_loadstate_is_masked_service_disabled_rsyslog_rsyslog" />
      <ns3:state state_ref="state_service_is_not_found_service_disabled_rsyslog_rsyslog" />
    </ns3:systemdunitproperty_test>
    <ns3:dpkginfo_test id="service_disabled_rsyslogtest_service_rsyslog_package_rsyslog_removed" version="1" check="all" comment="package rsyslog is removed" check_existence="none_exist" state_operator="AND">
      <ns3:object object_ref="obj_service_disabled_rsyslogtest_service_rsyslog_package_rsyslog_removed" />
    </ns3:dpkginfo_test>
    <ns3:systemdunitproperty_test id="test_service_not_running_service_disabled_ufw_ufw" version="1" check="all" comment="Test that the ufw service is not running" check_existence="any_exist" state_operator="AND">
      <ns3:object object_ref="obj_service_not_running_service_disabled_ufw_ufw" />
      <ns3:state state_ref="state_service_not_running_service_disabled_ufw_ufw" />
    </ns3:systemdunitproperty_test>
    <ns3:systemdunitproperty_test id="test_service_loadstate_is_masked_service_disabled_ufw_ufw" version="1" check="all" comment="Test that the property LoadState from the service ufw is masked" check_existence="any_exist" state_operator="AND">
      <ns3:object object_ref="obj_service_loadstate_is_masked_service_disabled_ufw_ufw" />
      <ns3:state state_ref="state_service_loadstate_is_masked_service_disabled_ufw_ufw" />
    </ns3:systemdunitproperty_test>
    <ns3:systemdunitproperty_test id="test_service_not_found_service_disabled_ufw_ufw" version="1" check="all" comment="Test that the service ufw is not found" check_existence="any_exist" state_operator="AND">
      <ns3:object object_ref="obj_service_loadstate_is_masked_service_disabled_ufw_ufw" />
      <ns3:state state_ref="state_service_is_not_found_service_disabled_ufw_ufw" />
    </ns3:systemdunitproperty_test>
    <ns3:dpkginfo_test id="service_disabled_ufwtest_service_ufw_package_ufw_removed" version="1" check="all" comment="package ufw is removed" check_existence="none_exist" state_operator="AND">
      <ns3:object object_ref="obj_service_disabled_ufwtest_service_ufw_package_ufw_removed" />
    </ns3:dpkginfo_test>
  </ns0:tests>
  <ns0:objects>
    <ns3:dpkginfo_object id="obj_bootc_platform_test_kernel_installed" version="1">
      <ns3:name>kernel</ns3:name>
    </ns3:dpkginfo_object>
    <ns3:dpkginfo_object id="obj_bootc_platform_test_rpm_ostree_installed" version="1">
      <ns3:name>rpm-ostree</ns3:name>
    </ns3:dpkginfo_object>
    <ns3:dpkginfo_object id="obj_bootc_platform_test_bootc_installed" version="1">
      <ns3:name>bootc</ns3:name>
    </ns3:dpkginfo_object>
    <ns3:dpkginfo_object id="obj_bootc_platform_test_openshift_kubelet_removed" version="1">
      <ns3:name>openshift-kubelet</ns3:name>
    </ns3:dpkginfo_object>
    <ns4:file_object id="bootc_platform_obj_run_ostree_booted_exists" version="1" comment="The file /run/ostree-booted exists">
      <ns4:filepath operation="equals">/run/ostree-booted</ns4:filepath>
    </ns4:file_object>
    <ns4:file_object id="bootc_platform_obj_ostree_symlink_exists" version="1" comment="The file /ostree exists">
      <ns4:filepath operation="equals">/ostree</ns4:filepath>
    </ns4:file_object>
    <ns3:rpminfo_object id="obj_alinux2" version="1">
      <ns3:name>alinux-release</ns3:name>
    </ns3:rpminfo_object>
    <ns3:rpminfo_object id="obj_alinux3" version="1">
      <ns3:name>alinux-release</ns3:name>
    </ns3:rpminfo_object>
    <ns3:rpminfo_object id="obj_anolis8" version="1">
      <ns3:name>anolis-release</ns3:name>
    </ns3:rpminfo_object>
    <ns5:textfilecontent54_object id="obj_debian_11" version="1" comment="Check Debian version">
      <ns5:filepath>/etc/debian_version</ns5:filepath>
      <ns5:pattern operation="pattern match">^11.[0-9]+$</ns5:pattern>
      <ns5:instance datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns5:textfilecontent54_object id="obj_debian_12" version="1" comment="Check Debian version">
      <ns5:filepath>/etc/debian_version</ns5:filepath>
      <ns5:pattern operation="pattern match">^12.[0-9]+$</ns5:pattern>
      <ns5:instance datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns5:textfilecontent54_object id="obj_debian_13" version="1" comment="Check Debian version">
      <ns5:filepath>/etc/debian_version</ns5:filepath>
      <ns5:pattern operation="pattern match">^13.[0-9]+$</ns5:pattern>
      <ns5:instance datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns3:rpminfo_object id="obj_rhevm4_version" version="1">
      <ns3:name>rhvm-appliance</ns3:name>
    </ns3:rpminfo_object>
    <ns3:dpkginfo_object id="obj_env_has_grub2_installed" version="1">
      <ns3:name>grub2-common</ns3:name>
    </ns3:dpkginfo_object>
    <ns4:file_object id="object_system_using_opal" version="1">
      <ns4:filepath>/sys/firmware/opal</ns4:filepath>
    </ns4:file_object>
    <ns3:dpkginfo_object id="obj_env_has_login_defs_installed" version="1">
      <ns3:name>login</ns3:name>
    </ns3:dpkginfo_object>
    <ns3:rpminfo_object id="obj_env_has_ovirt-host_installed" version="1">
      <ns3:name>ovirt-host</ns3:name>
    </ns3:rpminfo_object>
    <ns3:rpminfo_object id="obj_env_has_ovirt-engine_installed" version="1">
      <ns3:name>ovirt-engine</ns3:name>
    </ns3:rpminfo_object>
    <ns4:file_object id="object_proc_net_wireless_exists" version="1" comment="/proc/net/wireless file">
      <ns4:filepath>/proc/net/wireless</ns4:filepath>
    </ns4:file_object>
    <ns4:file_object id="object_installed_env_is_a_docker_container" version="1" comment="Check file /.dockerenv">
      <ns4:filepath datatype="string">/.dockerenv</ns4:filepath>
    </ns4:file_object>
    <ns4:file_object id="object_installed_env_is_a_podman_container" version="1" comment="Check file /run/.containerenv">
      <ns4:filepath datatype="string">/run/.containerenv</ns4:filepath>
    </ns4:file_object>
    <ns4:uname_object id="obj_kernel_uek" version="1" />
    <ns3:dpkginfo_object id="obj_krb5_server_version_1_17_18" version="1">
      <ns3:name>krb5-server</ns3:name>
    </ns3:dpkginfo_object>
    <ns3:dpkginfo_object id="obj_krb5_workstation_version_1_17_18" version="1">
      <ns3:name>krb5-workstation</ns3:name>
    </ns3:dpkginfo_object>
    <ns5:textfilecontent54_object id="object_nfs_mount_defined" version="1">
      <ns5:filepath>/etc/fstab</ns5:filepath>
      <ns5:pattern operation="pattern match">^\s*\[?[\.\w:-]+\]?[:=][/\w-]+\s+[/\w\\-]+\s+nfs[4]?\s+(.*)$</ns5:pattern>
      <ns5:instance datatype="int" operation="greater than or equal">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns5:textfilecontent54_object id="object_proc_sys_kernel_osrelease_arch_aarch64" version="1">
      <ns5:filepath operation="pattern match">^/proc/sys/kernel/(osrelease|arch)</ns5:filepath>
      <ns5:pattern operation="pattern match">^.*\.aarch64$|^aarch64$</ns5:pattern>
      <ns5:instance datatype="int" operation="greater than or equal">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns5:textfilecontent54_object id="object_proc_sys_kernel_osrelease_arch_ppc64le" version="1">
      <ns5:filepath operation="pattern match">^/proc/sys/kernel/(osrelease|arch)</ns5:filepath>
      <ns5:pattern operation="pattern match">^.*\.ppc64le$|^ppc64le$</ns5:pattern>
      <ns5:instance datatype="int" operation="greater than or equal">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns5:textfilecontent54_object id="object_proc_sys_kernel_osrelease_arch_s390x" version="1">
      <ns5:filepath operation="pattern match">^/proc/sys/kernel/(osrelease|arch)</ns5:filepath>
      <ns5:pattern operation="pattern match">^.*\.s390x$|^s390x$</ns5:pattern>
      <ns5:instance datatype="int" operation="greater than or equal">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns5:textfilecontent54_object id="object_proc_sys_kernel_osrelease_arch_x86_64" version="1">
      <ns5:filepath operation="pattern match">^/proc/sys/kernel/(osrelease|arch)</ns5:filepath>
      <ns5:pattern operation="pattern match">^.*\.x86_64$|^x86_64$</ns5:pattern>
      <ns5:instance datatype="int" operation="greater than or equal">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns4:sysctl_object id="obj_runtime_kernel_fips_enabled" version="1">
      <ns4:name>crypto.fips_enabled</ns4:name>
    </ns4:sysctl_object>
    <ns5:filehash58_object id="obj_secure_boot_enabled" version="1">
      <ns5:filepath operation="pattern match">^/sys/firmware/efi/efivars/SecureBoot-.*</ns5:filepath>
      <ns5:hash_type>SHA-256</ns5:hash_type>
    </ns5:filehash58_object>
    <ns5:textfilecontent54_object id="object_etc_selinux_configured" version="1">
      <ns5:filepath>/etc/selinux/config</ns5:filepath>
      <ns5:pattern operation="pattern match">^SELINUX=(.*)$</ns5:pattern>
      <ns5:instance datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns4:file_object id="object_selinux_sys_fs_exist" version="1" comment="/sys/fs/selinux">
      <ns4:path>/sys/fs/selinux</ns4:path>
      <ns4:filename xsi:nil="true" />
    </ns4:file_object>
    <ns5:textfilecontent54_object id="object_id_provider_is_set_to_ldap" version="1">
      <ns5:filepath>/etc/sssd/sssd.conf</ns5:filepath>
      <ns5:pattern operation="pattern match">^[\s]*\[domain\/[^]]*]([^\n\[\]]*\n+)+?[\s]*id_provider[ \t]*=[ \t]*((?i)ldap)[ \t]*$</ns5:pattern>
      <ns5:instance datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns4:file_object id="object_file_sys_firmware_efi" version="1" comment="/sys/firmware/efi">
      <ns4:path>/sys/firmware/efi</ns4:path>
      <ns4:filename xsi:nil="true" />
    </ns4:file_object>
    <ns3:dpkginfo_object id="obj_inventory_test_kernel_installed" version="1">
      <ns3:name>linux-base</ns3:name>
    </ns3:dpkginfo_object>
    <ns5:textfilecontent54_object id="obj_accounts_password_pam_faillock" version="1">
      <ns5:filepath>/etc/pam.d/system-auth</ns5:filepath>
      <ns5:pattern operation="pattern match">^\s*password\s+(?:(?:required)|(?:requisite))\s+pam_faillock\.so.*$</ns5:pattern>
      <ns5:instance datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns5:textfilecontent54_object id="obj_password_pam_pwquality" version="1">
      <ns5:filepath var_ref="var_pam_pwquality_config_path" var_check="at least one" />
      <ns5:pattern operation="pattern match">^\s*password\s+(?:(?:required)|(?:requisite))\s+pam_pwquality\.so.*$</ns5:pattern>
      <ns5:instance datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns5:textfilecontent54_object id="object_audit_rules_auditctl" version="1">
      <ns5:filepath>/usr/lib/systemd/system/auditd.service</ns5:filepath>
      <ns5:pattern operation="pattern match">^ExecStartPost=\-\/sbin\/auditctl.*$</ns5:pattern>
      <ns5:instance datatype="int" operation="greater than or equal">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns5:textfilecontent54_object id="object_audit_rules_augenrules" version="1">
      <ns5:filepath>/usr/lib/systemd/system/auditd.service</ns5:filepath>
      <ns5:pattern operation="pattern match">^(ExecStartPost=\-\/sbin\/augenrules.*$|Requires=augenrules.service)</ns5:pattern>
      <ns5:instance datatype="int" operation="greater than or equal">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns5:textfilecontent54_object id="object_32bit_setdomainname_augenrules" version="1">
      <ns5:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ns5:filepath>
      <ns5:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+setdomainname[\s]+|([\s]+|[,])setdomainname([\s]+|[,]))).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ns5:pattern>
      <ns5:instance datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns5:textfilecontent54_object id="object_64bit_setdomainname_augenrules" version="1">
      <ns5:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ns5:filepath>
      <ns5:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+setdomainname[\s]+|([\s]+|[,])setdomainname([\s]+|[,]))).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ns5:pattern>
      <ns5:instance datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns5:textfilecontent54_object id="object_32bit_setdomainname_auditctl" version="1">
      <ns5:filepath>/etc/audit/audit.rules</ns5:filepath>
      <ns5:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+setdomainname[\s]+|([\s]+|[,])setdomainname([\s]+|[,]))).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ns5:pattern>
      <ns5:instance datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns5:textfilecontent54_object id="object_64bit_setdomainname_auditctl" version="1">
      <ns5:filepath>/etc/audit/audit.rules</ns5:filepath>
      <ns5:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+setdomainname[\s]+|([\s]+|[,])setdomainname([\s]+|[,]))).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ns5:pattern>
      <ns5:instance datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns5:textfilecontent54_object id="object_32bit_sethostname_augenrules" version="1">
      <ns5:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ns5:filepath>
      <ns5:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+sethostname[\s]+|([\s]+|[,])sethostname([\s]+|[,]))).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ns5:pattern>
      <ns5:instance datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns5:textfilecontent54_object id="object_64bit_sethostname_augenrules" version="1">
      <ns5:filepath operation="pattern match">^/etc/audit/rules\.d/.*\.rules$</ns5:filepath>
      <ns5:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+sethostname[\s]+|([\s]+|[,])sethostname([\s]+|[,]))).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ns5:pattern>
      <ns5:instance datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns5:textfilecontent54_object id="object_32bit_sethostname_auditctl" version="1">
      <ns5:filepath>/etc/audit/audit.rules</ns5:filepath>
      <ns5:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b32[\s]+)(?:.*(-S[\s]+sethostname[\s]+|([\s]+|[,])sethostname([\s]+|[,]))).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ns5:pattern>
      <ns5:instance datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns5:textfilecontent54_object id="object_64bit_sethostname_auditctl" version="1">
      <ns5:filepath>/etc/audit/audit.rules</ns5:filepath>
      <ns5:pattern operation="pattern match">^[\s]*-a[\s]+always,exit[\s]+(?:.*-F[\s]+arch=b64[\s]+)(?:.*(-S[\s]+sethostname[\s]+|([\s]+|[,])sethostname([\s]+|[,]))).*(-k[\s]+|-F[\s]+key=)[\S]+[\s]*$</ns5:pattern>
      <ns5:instance datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns5:textfilecontent54_object id="object_auditd_conf_log_file" version="1">
      <ns5:filepath operation="equals">/etc/audit/auditd.conf</ns5:filepath>
      <ns5:pattern operation="pattern match">^(log_file\s*=\s*.*)$</ns5:pattern>
      <ns5:instance datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns5:textfilecontent54_object id="object_auditd_conf_log_group_root" version="1" comment="log_group = root">
      <ns5:filepath operation="equals">/etc/audit/auditd.conf</ns5:filepath>
      <ns5:pattern operation="pattern match">^[ ]*log_group[ ]+=[ ]+root[ ]*$</ns5:pattern>
      <ns5:instance datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns5:textfilecontent54_object id="object_auditd_conf_log_group_is_set" version="1" comment="log_group is set">
      <ns5:filepath operation="equals">/etc/audit/auditd.conf</ns5:filepath>
      <ns5:pattern operation="pattern match">^[ ]*log_group[ ]+=.*$</ns5:pattern>
      <ns5:instance datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns5:textfilecontent54_object id="object_bootloader_disable_recovery_argument" version="1">
      <ns5:filepath operation="pattern match">^/etc/default/grub(\.d/[^/]+\.cfg)?$</ns5:filepath>
      <ns5:pattern operation="pattern match">^\s*GRUB_DISABLE_RECOVERY=(.*)$</ns5:pattern>
      <ns5:instance datatype="int" operation="greater than or equal">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns5:textfilecontent54_object id="object_chronyd_multiple_servers" version="1" comment="Ensure more than one chronyd NTP server is set">
      <ns5:filepath operation="pattern match">^/etc/chrony\.(conf|d/.+\.conf)$</ns5:filepath>
      <ns5:pattern operation="pattern match">^([\s]*server[\s]+.+$){2,}$</ns5:pattern>
      <ns5:instance datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns5:textfilecontent54_object id="object_grub2_default_exists" version="1">
      <ns5:filepath>/etc/default/grub</ns5:filepath>
      <ns5:pattern operation="pattern match">^\s*GRUB_CMDLINE_LINUX_DEFAULT=.*$</ns5:pattern>
      <ns5:instance datatype="int" operation="greater than or equal">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns5:textfilecontent54_object id="object_grub2_entries_reference_kernelopts" version="1">
      <ns5:path>/boot/loader/entries/</ns5:path>
      <ns5:filename operation="pattern match">^.*\.conf$</ns5:filename>
      <ns5:pattern operation="pattern match">^options(?:\s+.*)?\s+\$kernelopts\b.*$</ns5:pattern>
      <ns5:instance datatype="int" operation="greater than or equal">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns5:textfilecontent54_object id="obj_name_al2023" version="1" comment="Check os-release ID">
      <ns5:filepath>/etc/os-release</ns5:filepath>
      <ns5:pattern operation="pattern match">^ID=\"(\w+)\"$</ns5:pattern>
      <ns5:instance datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns5:textfilecontent54_object id="obj_version_al2023" version="1" comment="Check os-release VERSION_ID">
      <ns5:filepath>/etc/os-release</ns5:filepath>
      <ns5:pattern operation="pattern match">^VERSION_ID=\"(\w+)\"$</ns5:pattern>
      <ns5:instance datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns4:file_object id="obj_almalinux" version="1" comment="check /etc/almalinux file">
      <ns4:filepath>/etc/almalinux-release</ns4:filepath>
    </ns4:file_object>
    <ns5:textfilecontent54_object id="obj_almalinux9" version="1" comment="Check AlmaLinux OS version">
      <ns5:filepath>/etc/almalinux-release</ns5:filepath>
      <ns5:pattern operation="pattern match">^AlmaLinux release 9.[0-9]+ .*$</ns5:pattern>
      <ns5:instance datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns3:rpminfo_object id="obj_anolis23" version="1">
      <ns3:name>anolis-release</ns3:name>
    </ns3:rpminfo_object>
    <ns5:textfilecontent54_object id="obj_name_centos10" version="1" comment="Check os-release ID">
      <ns5:filepath>/etc/os-release</ns5:filepath>
      <ns5:pattern operation="pattern match">^ID="(\w+)"$</ns5:pattern>
      <ns5:instance datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns5:textfilecontent54_object id="obj_version_centos10" version="1" comment="Check os-release VERSION_ID">
      <ns5:filepath>/etc/os-release</ns5:filepath>
      <ns5:pattern operation="pattern match">^VERSION_ID="(\d+)"$</ns5:pattern>
      <ns5:instance datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns5:textfilecontent54_object id="obj_name_centos8" version="1" comment="Check os-release ID">
      <ns5:filepath>/etc/os-release</ns5:filepath>
      <ns5:pattern operation="pattern match">^ID="(\w+)"$</ns5:pattern>
      <ns5:instance datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns5:textfilecontent54_object id="obj_version_centos8" version="1" comment="Check os-release VERSION_ID">
      <ns5:filepath>/etc/os-release</ns5:filepath>
      <ns5:pattern operation="pattern match">^VERSION_ID="(\d)"$</ns5:pattern>
      <ns5:instance datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns5:textfilecontent54_object id="obj_name_centos9" version="1" comment="Check os-release ID">
      <ns5:filepath>/etc/os-release</ns5:filepath>
      <ns5:pattern operation="pattern match">^ID="(\w+)"$</ns5:pattern>
      <ns5:instance datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns5:textfilecontent54_object id="obj_version_centos9" version="1" comment="Check os-release VERSION_ID">
      <ns5:filepath>/etc/os-release</ns5:filepath>
      <ns5:pattern operation="pattern match">^VERSION_ID="(\d)"$</ns5:pattern>
      <ns5:instance datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns4:file_object id="obj_debian" version="1" comment="check /etc/debian_version file">
      <ns4:filepath>/etc/debian_version</ns4:filepath>
    </ns4:file_object>
    <ns3:rpminfo_object id="object_fedora_release_rpm" version="1">
      <ns3:name operation="pattern match">fedora-release.*</ns3:name>
    </ns3:rpminfo_object>
    <ns5:textfilecontent54_object id="object_fedora_vendor_product" version="1">
      <ns5:filepath>/etc/system-release-cpe</ns5:filepath>
      <ns5:pattern operation="pattern match">^cpe:\/o:fedoraproject:fedora:[\d]+$</ns5:pattern>
      <ns5:instance datatype="int" operation="equals">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns3:rpminfo_object id="obj_kylinserver10_installed" version="1">
      <ns3:name>kylin-release</ns3:name>
    </ns3:rpminfo_object>
    <ns4:file_object id="obj_os_oeharden" version="1" comment="check /etc/os-release file">
      <ns4:filepath>/etc/os-release</ns4:filepath>
    </ns4:file_object>
    <ns5:textfilecontent54_object id="obj_oeharden" version="1" comment="Check OE Harden">
      <ns5:filepath>/etc/os-release</ns5:filepath>
      <ns5:pattern operation="pattern match">^ID=harden$</ns5:pattern>
      <ns5:instance datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns5:textfilecontent54_object id="obj_os_id_is_ol" version="1">
      <ns5:filepath>/etc/os-release</ns5:filepath>
      <ns5:pattern operation="pattern match">^ID=["']?(\w+)["']?$</ns5:pattern>
      <ns5:instance operation="greater than or equal" datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns3:rpminfo_object id="obj_ol10_system" version="1">
      <ns3:name>oraclelinux-release</ns3:name>
    </ns3:rpminfo_object>
    <ns3:rpminfo_object id="obj_ol7_system" version="1">
      <ns3:name>oraclelinux-release</ns3:name>
    </ns3:rpminfo_object>
    <ns3:rpminfo_object id="obj_ol8_system" version="1">
      <ns3:name>oraclelinux-release</ns3:name>
    </ns3:rpminfo_object>
    <ns3:rpminfo_object id="obj_ol9_system" version="1">
      <ns3:name>oraclelinux-release</ns3:name>
    </ns3:rpminfo_object>
    <ns4:file_object id="obj_os_openembedded" version="1" comment="check /etc/os-release file">
      <ns4:filepath>/etc/os-release</ns4:filepath>
    </ns4:file_object>
    <ns5:textfilecontent54_object id="obj_openembedded" version="1" comment="Check OpenEmbedded">
      <ns5:filepath>/etc/os-release</ns5:filepath>
      <ns5:pattern operation="pattern match">^ID=nodistro$</ns5:pattern>
      <ns5:instance datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns3:rpminfo_object id="obj_openeuler2203_installed" version="1">
      <ns3:name>openEuler-release</ns3:name>
    </ns3:rpminfo_object>
    <ns3:rpminfo_object id="obj_opensuse_installed" version="1">
      <ns3:name>openSUSE-release</ns3:name>
    </ns3:rpminfo_object>
    <ns3:rpminfo_object id="obj_opensuse_leap15_installed" version="1">
      <ns3:name>openSUSE-release</ns3:name>
    </ns3:rpminfo_object>
    <ns3:rpminfo_object id="obj_opensuse_leap16_installed" version="1">
      <ns3:name>Leap-release</ns3:name>
    </ns3:rpminfo_object>
    <ns5:family_object id="object_unix_family" version="1" />
    <ns4:file_object id="obj_os_petalinux" version="1" comment="check /etc/os-release file">
      <ns4:filepath>/etc/os-release</ns4:filepath>
    </ns4:file_object>
    <ns5:textfilecontent54_object id="obj_petalinux" version="1" comment="Check Petalinux">
      <ns5:filepath>/etc/os-release</ns5:filepath>
      <ns5:pattern operation="pattern match">^ID=petalinux$</ns5:pattern>
      <ns5:instance datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns4:file_object id="obj_os_poky" version="1" comment="check /etc/os-release file">
      <ns4:filepath>/etc/os-release</ns4:filepath>
    </ns4:file_object>
    <ns5:textfilecontent54_object id="obj_poky" version="1" comment="Check Poky">
      <ns5:filepath>/etc/os-release</ns5:filepath>
      <ns5:pattern operation="pattern match">^ID=poky$</ns5:pattern>
      <ns5:instance datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns5:textfilecontent54_object id="obj_rhcos" version="1">
      <ns5:filepath>/etc/os-release</ns5:filepath>
      <ns5:pattern operation="pattern match">^ID="(\w+)"$</ns5:pattern>
      <ns5:instance operation="greater than or equal" datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns5:textfilecontent54_object id="obj_rhel_coreos_variant" version="1">
      <ns5:filepath>/etc/os-release</ns5:filepath>
      <ns5:pattern operation="pattern match">^VARIANT_ID=(\S+)$</ns5:pattern>
      <ns5:instance operation="greater than or equal" datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns5:textfilecontent54_object id="obj_rhel_coreos_version9" version="1">
      <ns5:filepath>/etc/os-release</ns5:filepath>
      <ns5:pattern operation="pattern match">^VERSION_ID="(\d+\.\d+)"$</ns5:pattern>
      <ns5:instance operation="greater than or equal" datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns5:textfilecontent54_object id="obj_rhel_coreos_version10" version="1">
      <ns5:filepath>/etc/os-release</ns5:filepath>
      <ns5:pattern operation="pattern match">^VERSION_ID="(\d+\.\d+)"$</ns5:pattern>
      <ns5:instance operation="greater than or equal" datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns5:textfilecontent54_object id="obj_rhcos4" version="1">
      <ns5:filepath>/etc/os-release</ns5:filepath>
      <ns5:pattern operation="pattern match">^OPENSHIFT_VERSION="(\d)\.\d+"$</ns5:pattern>
      <ns5:instance operation="greater than or equal" datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns5:textfilecontent54_object id="obj_rhcos4_rhel8_rhel_version" version="1">
      <ns5:filepath>/etc/os-release</ns5:filepath>
      <ns5:pattern operation="pattern match">^RHEL_VERSION="?(\d+\.?\d*)"?$</ns5:pattern>
      <ns5:instance datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns5:textfilecontent54_object id="obj_rhel_id" version="1">
      <ns5:filepath>/etc/os-release</ns5:filepath>
      <ns5:pattern operation="pattern match">^ID="(\w+)"$</ns5:pattern>
      <ns5:instance operation="greater than or equal" datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns5:textfilecontent54_object id="obj_rhcos4_rhel9_rhel_version" version="1">
      <ns5:filepath>/etc/os-release</ns5:filepath>
      <ns5:pattern operation="pattern match">^RHEL_VERSION="?(\d+\.?\d*)"?$</ns5:pattern>
      <ns5:instance datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns5:textfilecontent54_object id="obj_os_id_is_rhel" version="1">
      <ns5:filepath>/etc/os-release</ns5:filepath>
      <ns5:pattern operation="pattern match">^ID=["']?(\w+)["']?$</ns5:pattern>
      <ns5:instance operation="greater than or equal" datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns5:family_object id="obj_rhel10_unix_family" version="1" />
    <ns3:rpminfo_object id="obj_rhel10" version="1">
      <ns3:name>redhat-release</ns3:name>
    </ns3:rpminfo_object>
    <ns5:textfilecontent54_object id="obj_rhevh_rhel10_version" version="1">
      <ns5:filepath>/etc/redhat-release</ns5:filepath>
      <ns5:pattern operation="pattern match">^Red Hat Enterprise Linux release (\d)\.\d+$</ns5:pattern>
      <ns5:instance operation="greater than or equal" datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns5:family_object id="obj_rhel8_unix_family" version="1" />
    <ns3:rpminfo_object id="obj_rhel8" version="1">
      <ns3:name>redhat-release</ns3:name>
    </ns3:rpminfo_object>
    <ns3:rpminfo_object id="obj_rhel8_0" version="1">
      <ns3:name>redhat-release</ns3:name>
    </ns3:rpminfo_object>
    <ns3:rpminfo_object id="obj_rhel8_1" version="1">
      <ns3:name>redhat-release</ns3:name>
    </ns3:rpminfo_object>
    <ns3:rpminfo_object id="obj_rhel8_2" version="1">
      <ns3:name>redhat-release</ns3:name>
    </ns3:rpminfo_object>
    <ns3:rpminfo_object id="obj_rhel8_3" version="1">
      <ns3:name>redhat-release</ns3:name>
    </ns3:rpminfo_object>
    <ns3:rpminfo_object id="obj_rhel8_4" version="1">
      <ns3:name>redhat-release</ns3:name>
    </ns3:rpminfo_object>
    <ns3:rpminfo_object id="obj_rhel8_5" version="1">
      <ns3:name>redhat-release</ns3:name>
    </ns3:rpminfo_object>
    <ns3:rpminfo_object id="obj_rhel8_6" version="1">
      <ns3:name>redhat-release</ns3:name>
    </ns3:rpminfo_object>
    <ns3:rpminfo_object id="obj_rhel8_7" version="1">
      <ns3:name>redhat-release</ns3:name>
    </ns3:rpminfo_object>
    <ns3:rpminfo_object id="obj_rhel8_8" version="1">
      <ns3:name>redhat-release</ns3:name>
    </ns3:rpminfo_object>
    <ns3:rpminfo_object id="obj_rhel8_9" version="1">
      <ns3:name>redhat-release</ns3:name>
    </ns3:rpminfo_object>
    <ns3:rpminfo_object id="obj_rhel8_10" version="1">
      <ns3:name>redhat-release</ns3:name>
    </ns3:rpminfo_object>
    <ns5:textfilecontent54_object id="obj_rhevh_rhel8_version" version="1">
      <ns5:filepath>/etc/redhat-release</ns5:filepath>
      <ns5:pattern operation="pattern match">^Red Hat Enterprise Linux release (\d)\.\d+$</ns5:pattern>
      <ns5:instance operation="greater than or equal" datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns5:family_object id="obj_rhel9_unix_family" version="1" />
    <ns3:rpminfo_object id="obj_rhel9" version="1">
      <ns3:name>redhat-release</ns3:name>
    </ns3:rpminfo_object>
    <ns5:textfilecontent54_object id="obj_rhevh_rhel9_version" version="1">
      <ns5:filepath>/etc/redhat-release</ns5:filepath>
      <ns5:pattern operation="pattern match">^Red Hat Enterprise Linux release (\d)\.\d+$</ns5:pattern>
      <ns5:instance operation="greater than or equal" datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns3:rpminfo_object id="obj_rhvh4_version" version="1">
      <ns3:name>redhat-release-virtualization-host</ns3:name>
    </ns3:rpminfo_object>
    <ns5:family_object id="obj_sle12_unix_family" version="1" />
    <ns3:rpminfo_object id="obj_sle12_desktop" version="1">
      <ns3:name>sled-release</ns3:name>
    </ns3:rpminfo_object>
    <ns3:rpminfo_object id="obj_sle12_server" version="1">
      <ns3:name>sles-release</ns3:name>
    </ns3:rpminfo_object>
    <ns3:rpminfo_object id="obj_sles_12_for_sap" version="1">
      <ns3:name>SLES_SAP-release</ns3:name>
    </ns3:rpminfo_object>
    <ns5:family_object id="obj_sle15_unix_family" version="1" />
    <ns3:rpminfo_object id="obj_sle15_desktop" version="1">
      <ns3:name>sled-release</ns3:name>
    </ns3:rpminfo_object>
    <ns3:rpminfo_object id="obj_sle15_server" version="1">
      <ns3:name>sles-release</ns3:name>
    </ns3:rpminfo_object>
    <ns3:rpminfo_object id="obj_sles_15_for_sap" version="1">
      <ns3:name>SLES_SAP-release</ns3:name>
    </ns3:rpminfo_object>
    <ns3:rpminfo_object id="obj_suma_4" version="1">
      <ns3:name>SUSE-Manager-Server-release</ns3:name>
    </ns3:rpminfo_object>
    <ns3:rpminfo_object id="obj_sle_hpc" version="1">
      <ns3:name>SLE_HPC-release</ns3:name>
    </ns3:rpminfo_object>
    <ns5:family_object id="obj_sle16_unix_family" version="1" />
    <ns3:rpminfo_object id="obj_sle16_server" version="1">
      <ns3:name>SLES-release</ns3:name>
    </ns3:rpminfo_object>
    <ns3:rpminfo_object id="obj_sles_16_for_sap" version="1">
      <ns3:name>SLES_SAP-release</ns3:name>
    </ns3:rpminfo_object>
    <ns3:rpminfo_object id="obj_sles_16_for_ha" version="1">
      <ns3:name>sle-ha-release</ns3:name>
    </ns3:rpminfo_object>
    <ns5:family_object id="obj_slmicro5_unix_family" version="1" />
    <ns3:rpminfo_object id="obj_slmicroos5" version="1">
      <ns3:name>SUSE-MicroOS-release</ns3:name>
    </ns3:rpminfo_object>
    <ns3:rpminfo_object id="obj_slmicro5" version="1">
      <ns3:name>SLE-Micro-release</ns3:name>
    </ns3:rpminfo_object>
    <ns5:family_object id="obj_slmicro6_unix_family" version="1" />
    <ns3:rpminfo_object id="obj_slmicro6" version="1">
      <ns3:name>SL-Micro-release</ns3:name>
    </ns3:rpminfo_object>
    <ns3:rpminfo_object id="obj_tencentos4" version="1">
      <ns3:name>tencentos-release</ns3:name>
    </ns3:rpminfo_object>
    <ns4:file_object id="obj_lsb" version="1" comment="check /etc/lsb-release file">
      <ns4:filepath>/etc/lsb-release</ns4:filepath>
    </ns4:file_object>
    <ns5:textfilecontent54_object id="obj_ubuntu" version="1" comment="Check Ubuntu">
      <ns5:filepath>/etc/lsb-release</ns5:filepath>
      <ns5:pattern operation="pattern match">^DISTRIB_ID=Ubuntu$</ns5:pattern>
      <ns5:instance datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns5:textfilecontent54_object id="obj_ubuntu_jammy" version="1" comment="Check Ubuntu version">
      <ns5:filepath>/etc/lsb-release</ns5:filepath>
      <ns5:pattern operation="pattern match">^DISTRIB_CODENAME=jammy$</ns5:pattern>
      <ns5:instance datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns5:textfilecontent54_object id="obj_ubuntu_noble" version="1" comment="Check Ubuntu version">
      <ns5:filepath>/etc/lsb-release</ns5:filepath>
      <ns5:pattern operation="pattern match">^DISTRIB_CODENAME=noble$</ns5:pattern>
      <ns5:instance datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns3:dpkginfo_object id="obj_env_has_zipl_installed" version="1">
      <ns3:name>s390utils-base</ns3:name>
    </ns3:dpkginfo_object>
    <ns5:environmentvariable58_object id="object_installed_env_is_osbuild" version="1">
      <ns5:pid xsi:nil="true" datatype="int" />
      <ns5:name>container</ns5:name>
    </ns5:environmentvariable58_object>
    <ns5:textfilecontent54_object id="object_no_cd_dvd_drive_in_etc_fstab" version="1">
      <ns5:filepath>/etc/fstab</ns5:filepath>
      <ns5:pattern operation="pattern match" datatype="string" var_ref="variable_cd_dvd_drive_alternative_names" var_check="at least one" />
      <ns5:instance datatype="int" operation="greater than or equal">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns4:file_object id="object_removable_partition_doesnt_exist" version="1">
      <ns4:filepath var_ref="var_removable_partition" var_check="at least one" />
    </ns4:file_object>
    <ns5:variable_object id="object_sshd_not_required" version="1">
      <ns5:var_ref>sshd_required</ns5:var_ref>
    </ns5:variable_object>
    <ns5:variable_object id="object_sshd_required" version="1">
      <ns5:var_ref>sshd_required</ns5:var_ref>
    </ns5:variable_object>
    <ns5:variable_object id="object_sshd_requirement_unknown" version="1">
      <ns5:var_ref>sshd_required</ns5:var_ref>
    </ns5:variable_object>
    <ns3:dpkginfo_object id="obj_openssh-server_version" version="1">
      <ns3:name>openssh-server</ns3:name>
    </ns3:dpkginfo_object>
    <ns4:uname_object id="object_system_info_architecture_aarch_64" version="1" comment="64 bit architecture" />
    <ns4:uname_object id="object_system_info_architecture_ppc_64" version="1" comment="64 bit architecture" />
    <ns4:uname_object id="object_system_info_architecture_ppcle_64" version="1" comment="64 bit architecture" />
    <ns4:uname_object id="object_system_info_architecture_s390_64" version="1" comment="64 bit architecture" />
    <ns4:uname_object id="object_system_info_architecture_x86" version="1" comment="32 bit architecture" />
    <ns4:uname_object id="object_system_info_architecture_x86_64" version="1" comment="64 bit architecture" />
    <ns4:file_object id="object_tmux_conf_readable_by_others" version="1" comment="/etc/tmux.conf">
      <ns4:filepath operation="equals">/etc/tmux.conf</ns4:filepath>
    </ns4:file_object>
    <ns5:textfilecontent54_object id="obj_usbguard_rules_nonempty" version="1">
      <ns5:filepath operation="pattern match">^/etc/usbguard/(rules|rules\.d/.*)\.conf$</ns5:filepath>
      <ns5:pattern operation="pattern match">^.*\S+.*$</ns5:pattern>
      <ns5:instance datatype="int" operation="greater than or equal">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns5:variable_object id="object_var_accounts_user_umask_umask_as_number" version="1">
      <ns5:var_ref>var_accounts_user_umask_umask_as_number</ns5:var_ref>
    </ns5:variable_object>
    <ns5:variable_object id="object_var_removable_partition_is_cd_dvd_drive" version="1">
      <ns5:var_ref>var_removable_partition</ns5:var_ref>
    </ns5:variable_object>
    <ns5:variable_object id="object_var_umask_for_daemons_umask_as_number" version="1">
      <ns5:var_ref>var_umask_for_daemons_umask_as_number</ns5:var_ref>
    </ns5:variable_object>
    <ns5:textfilecontent54_object id="object_grub2_ipv6_disable_parameter" version="1">
      <ns5:filepath>/etc/default/grub</ns5:filepath>
      <ns5:pattern operation="pattern match">^\s*GRUB_CMDLINE_LINUX=".*ipv6\.disable=(\d).*$</ns5:pattern>
      <ns5:instance datatype="int" operation="greater than or equal">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns3:partition_object id="object_mount_active_boot_efi_exists" version="1">
      <ns3:mount_point>/boot/efi</ns3:mount_point>
    </ns3:partition_object>
    <ns5:textfilecontent54_object id="object_mount_configured_fstab_boot_efi_exists" version="1">
      <ns5:filepath>/etc/fstab</ns5:filepath>
      <ns5:pattern operation="pattern match">^[\s]*[\S]+[\s]+/boot/efi[\s]+[\S]+[\s]+([\S]+)</ns5:pattern>
      <ns5:instance datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns3:partition_object id="object_mount_active_home_exists" version="1">
      <ns3:mount_point>/home</ns3:mount_point>
    </ns3:partition_object>
    <ns5:textfilecontent54_object id="object_mount_configured_fstab_home_exists" version="1">
      <ns5:filepath>/etc/fstab</ns5:filepath>
      <ns5:pattern operation="pattern match">^[\s]*[\S]+[\s]+/home[\s]+[\S]+[\s]+([\S]+)</ns5:pattern>
      <ns5:instance datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns3:partition_object id="object_mount_active_opt_exists" version="1">
      <ns3:mount_point>/opt</ns3:mount_point>
    </ns3:partition_object>
    <ns5:textfilecontent54_object id="object_mount_configured_fstab_opt_exists" version="1">
      <ns5:filepath>/etc/fstab</ns5:filepath>
      <ns5:pattern operation="pattern match">^[\s]*[\S]+[\s]+/opt[\s]+[\S]+[\s]+([\S]+)</ns5:pattern>
      <ns5:instance datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns3:partition_object id="object_mount_active_srv_exists" version="1">
      <ns3:mount_point>/srv</ns3:mount_point>
    </ns3:partition_object>
    <ns5:textfilecontent54_object id="object_mount_configured_fstab_srv_exists" version="1">
      <ns5:filepath>/etc/fstab</ns5:filepath>
      <ns5:pattern operation="pattern match">^[\s]*[\S]+[\s]+/srv[\s]+[\S]+[\s]+([\S]+)</ns5:pattern>
      <ns5:instance datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns3:partition_object id="object_mount_active_tmp_exists" version="1">
      <ns3:mount_point>/tmp</ns3:mount_point>
    </ns3:partition_object>
    <ns5:textfilecontent54_object id="object_mount_configured_fstab_tmp_exists" version="1">
      <ns5:filepath>/etc/fstab</ns5:filepath>
      <ns5:pattern operation="pattern match">^[\s]*[\S]+[\s]+/tmp[\s]+[\S]+[\s]+([\S]+)</ns5:pattern>
      <ns5:instance datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns3:partition_object id="object_mount_active_var_log_audit_exists" version="1">
      <ns3:mount_point>/var/log/audit</ns3:mount_point>
    </ns3:partition_object>
    <ns5:textfilecontent54_object id="object_mount_configured_fstab_var_log_audit_exists" version="1">
      <ns5:filepath>/etc/fstab</ns5:filepath>
      <ns5:pattern operation="pattern match">^[\s]*[\S]+[\s]+/var/log/audit[\s]+[\S]+[\s]+([\S]+)</ns5:pattern>
      <ns5:instance datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns3:partition_object id="object_mount_active_var_log_exists" version="1">
      <ns3:mount_point>/var/log</ns3:mount_point>
    </ns3:partition_object>
    <ns5:textfilecontent54_object id="object_mount_configured_fstab_var_log_exists" version="1">
      <ns5:filepath>/etc/fstab</ns5:filepath>
      <ns5:pattern operation="pattern match">^[\s]*[\S]+[\s]+/var/log[\s]+[\S]+[\s]+([\S]+)</ns5:pattern>
      <ns5:instance datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns3:partition_object id="object_mount_active_var_tmp_exists" version="1">
      <ns3:mount_point>/var/tmp</ns3:mount_point>
    </ns3:partition_object>
    <ns5:textfilecontent54_object id="object_mount_configured_fstab_var_tmp_exists" version="1">
      <ns5:filepath>/etc/fstab</ns5:filepath>
      <ns5:pattern operation="pattern match">^[\s]*[\S]+[\s]+/var/tmp[\s]+[\S]+[\s]+([\S]+)</ns5:pattern>
      <ns5:instance datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns3:partition_object id="object_mount_active_var_exists" version="1">
      <ns3:mount_point>/var</ns3:mount_point>
    </ns3:partition_object>
    <ns5:textfilecontent54_object id="object_mount_configured_fstab_var_exists" version="1">
      <ns5:filepath>/etc/fstab</ns5:filepath>
      <ns5:pattern operation="pattern match">^[\s]*[\S]+[\s]+/var[\s]+[\S]+[\s]+([\S]+)</ns5:pattern>
      <ns5:instance datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns5:textfilecontent54_object id="obj_os_id_is_os_linux_ol_gt_or_eq_8_7" version="1">
      <ns5:filepath>/etc/os-release</ns5:filepath>
      <ns5:pattern operation="pattern match">^ID=["']?(\w+)["']?$</ns5:pattern>
      <ns5:instance operation="greater than or equal" datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns5:textfilecontent54_object id="obj_os_linux_ol_gt_or_eq_8_7_gt_or_eq_8_7" version="1">
      <ns5:filepath>/etc/os-release</ns5:filepath>
      <ns5:pattern operation="pattern match">^VERSION_ID=["']?([\w.]+)["']?$</ns5:pattern>
      <ns5:instance operation="greater than or equal" datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns5:textfilecontent54_object id="obj_os_id_is_os_linux_ol_gt_or_eq_9_0" version="1">
      <ns5:filepath>/etc/os-release</ns5:filepath>
      <ns5:pattern operation="pattern match">^ID=["']?(\w+)["']?$</ns5:pattern>
      <ns5:instance operation="greater than or equal" datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns5:textfilecontent54_object id="obj_os_linux_ol_gt_or_eq_9_0_gt_or_eq_9_0" version="1">
      <ns5:filepath>/etc/os-release</ns5:filepath>
      <ns5:pattern operation="pattern match">^VERSION_ID=["']?([\w.]+)["']?$</ns5:pattern>
      <ns5:instance operation="greater than or equal" datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns5:textfilecontent54_object id="obj_os_id_is_os_linux_rhel_gt_or_eq_8_7" version="1">
      <ns5:filepath>/etc/os-release</ns5:filepath>
      <ns5:pattern operation="pattern match">^ID=["']?(\w+)["']?$</ns5:pattern>
      <ns5:instance operation="greater than or equal" datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns5:textfilecontent54_object id="obj_os_linux_rhel_gt_or_eq_8_7_gt_or_eq_8_7" version="1">
      <ns5:filepath>/etc/os-release</ns5:filepath>
      <ns5:pattern operation="pattern match">^VERSION_ID=["']?([\w.]+)["']?$</ns5:pattern>
      <ns5:instance operation="greater than or equal" datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns5:textfilecontent54_object id="obj_os_id_is_os_linux_rhel_gt_or_eq_9_0" version="1">
      <ns5:filepath>/etc/os-release</ns5:filepath>
      <ns5:pattern operation="pattern match">^ID=["']?(\w+)["']?$</ns5:pattern>
      <ns5:instance operation="greater than or equal" datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns5:textfilecontent54_object id="obj_os_linux_rhel_gt_or_eq_9_0_gt_or_eq_9_0" version="1">
      <ns5:filepath>/etc/os-release</ns5:filepath>
      <ns5:pattern operation="pattern match">^VERSION_ID=["']?([\w.]+)["']?$</ns5:pattern>
      <ns5:instance operation="greater than or equal" datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns5:textfilecontent54_object id="obj_os_id_is_os_linux_rhel_le_or_eq_8_4" version="1">
      <ns5:filepath>/etc/os-release</ns5:filepath>
      <ns5:pattern operation="pattern match">^ID=["']?(\w+)["']?$</ns5:pattern>
      <ns5:instance operation="greater than or equal" datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns5:textfilecontent54_object id="obj_os_linux_rhel_le_or_eq_8_4_le_or_eq_8_4" version="1">
      <ns5:filepath>/etc/os-release</ns5:filepath>
      <ns5:pattern operation="pattern match">^VERSION_ID=["']?([\w.]+)["']?$</ns5:pattern>
      <ns5:instance operation="greater than or equal" datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns5:textfilecontent54_object id="obj_os_id_is_os_linux_rhel_ne_9_0" version="1">
      <ns5:filepath>/etc/os-release</ns5:filepath>
      <ns5:pattern operation="pattern match">^ID=["']?(\w+)["']?$</ns5:pattern>
      <ns5:instance operation="greater than or equal" datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns5:textfilecontent54_object id="obj_os_linux_rhel_ne_9_0_ne_9_0" version="1">
      <ns5:filepath>/etc/os-release</ns5:filepath>
      <ns5:pattern operation="pattern match">^VERSION_ID=["']?([\w.]+)["']?$</ns5:pattern>
      <ns5:instance operation="greater than or equal" datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns5:textfilecontent54_object id="obj_os_id_is_os_linux_sles_gt_or_eq_15" version="1">
      <ns5:filepath>/etc/os-release</ns5:filepath>
      <ns5:pattern operation="pattern match">^ID=["']?(\w+)["']?$</ns5:pattern>
      <ns5:instance operation="greater than or equal" datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns5:textfilecontent54_object id="obj_os_linux_sles_gt_or_eq_15_gt_or_eq_15" version="1">
      <ns5:filepath>/etc/os-release</ns5:filepath>
      <ns5:pattern operation="pattern match">^VERSION_ID=["']?([\w.]+)["']?$</ns5:pattern>
      <ns5:instance operation="greater than or equal" datatype="int">1</ns5:instance>
    </ns5:textfilecontent54_object>
    <ns3:dpkginfo_object id="obj_inventory_test_package_aide_installed" version="1">
      <ns3:name>aide</ns3:name>
    </ns3:dpkginfo_object>
    <ns3:dpkginfo_object id="obj_inventory_test_package_apparmor_installed" version="1">
      <ns3:name>apparmor</ns3:name>
    </ns3:dpkginfo_object>
    <ns3:dpkginfo_object id="obj_inventory_test_package_apport_installed" version="1">
      <ns3:name>apport</ns3:name>
    </ns3:dpkginfo_object>
    <ns3:dpkginfo_object id="obj_inventory_test_package_apt_get_installed" version="1">
      <ns3:name>apt</ns3:name>
    </ns3:dpkginfo_object>
    <ns3:dpkginfo_object id="obj_inventory_test_package_audit_installed" version="1">
      <ns3:name>auditd</ns3:name>
    </ns3:dpkginfo_object>
    <ns3:dpkginfo_object id="obj_inventory_test_package_autofs_installed" version="1">
      <ns3:name>autofs</ns3:name>
    </ns3:dpkginfo_object>
    <ns3:dpkginfo_object id="obj_inventory_test_package_avahi_installed" version="1">
      <ns3:name>avahi-daemon</ns3:name>
    </ns3:dpkginfo_object>
    <ns3:dpkginfo_object id="obj_inventory_test_package_bash_installed" version="1">
      <ns3:name>bash</ns3:name>
    </ns3:dpkginfo_object>
    <ns3:dpkginfo_object id="obj_inventory_test_package_bind_installed" version="1">
      <ns3:name>bind</ns3:name>
    </ns3:dpkginfo_object>
    <ns3:dpkginfo_object id="obj_inventory_test_package_chrony_installed" version="1">
      <ns3:name>chrony</ns3:name>
    </ns3:dpkginfo_object>
    <ns3:dpkginfo_object id="obj_inventory_test_package_firewalld_installed" version="1">
      <ns3:name>firewalld</ns3:name>
    </ns3:dpkginfo_object>
    <ns3:dpkginfo_object id="obj_inventory_test_package_gdm_installed" version="1">
      <ns3:name>gdm3</ns3:name>
    </ns3:dpkginfo_object>
    <ns3:dpkginfo_object id="obj_inventory_test_package_iptables_installed" version="1">
      <ns3:name>iptables</ns3:name>
    </ns3:dpkginfo_object>
    <ns3:dpkginfo_object id="obj_inventory_test_package_libpwquality_installed" version="1">
      <ns3:name>libpwquality1</ns3:name>
    </ns3:dpkginfo_object>
    <ns3:dpkginfo_object id="obj_inventory_test_package_libreswan_installed" version="1">
      <ns3:name>libreswan</ns3:name>
    </ns3:dpkginfo_object>
    <ns3:dpkginfo_object id="obj_inventory_test_package_libuser_installed" version="1">
      <ns3:name>libuser</ns3:name>
    </ns3:dpkginfo_object>
    <ns3:dpkginfo_object id="obj_inventory_test_package_logrotate_installed" version="1">
      <ns3:name>logrotate</ns3:name>
    </ns3:dpkginfo_object>
    <ns3:dpkginfo_object id="obj_inventory_test_package_net-snmp_installed" version="1">
      <ns3:name>snmp</ns3:name>
    </ns3:dpkginfo_object>
    <ns3:dpkginfo_object id="obj_inventory_test_package_networkmanager_installed" version="1">
      <ns3:name>network-manager</ns3:name>
    </ns3:dpkginfo_object>
    <ns3:dpkginfo_object id="obj_inventory_test_package_nftables_installed" version="1">
      <ns3:name>nftables</ns3:name>
    </ns3:dpkginfo_object>
    <ns3:dpkginfo_object id="obj_inventory_test_package_nss-pam-ldapd_installed" version="1">
      <ns3:name>libpam-ldapd</ns3:name>
    </ns3:dpkginfo_object>
    <ns3:dpkginfo_object id="obj_inventory_test_package_ntp_installed" version="1">
      <ns3:name>ntp</ns3:name>
    </ns3:dpkginfo_object>
    <ns3:dpkginfo_object id="obj_inventory_test_package_openssh-server_le_7_0_le_7_0_installed" version="1">
      <ns3:name>openssh-server</ns3:name>
    </ns3:dpkginfo_object>
    <ns3:dpkginfo_object id="obj_inventory_test_package_openssh-server_le_7_5_le_7_5_installed" version="1">
      <ns3:name>openssh-server</ns3:name>
    </ns3:dpkginfo_object>
    <ns3:dpkginfo_object id="obj_inventory_test_package_openssh_installed" version="1">
      <ns3:name>openssh</ns3:name>
    </ns3:dpkginfo_object>
    <ns3:dpkginfo_object id="obj_inventory_test_package_pam_installed" version="1">
      <ns3:name>libpam-runtime</ns3:name>
    </ns3:dpkginfo_object>
    <ns3:dpkginfo_object id="obj_inventory_test_package_pam_apparmor_installed" version="1">
      <ns3:name>pam_apparmor</ns3:name>
    </ns3:dpkginfo_object>
    <ns3:dpkginfo_object id="obj_inventory_test_package_polkit_installed" version="1">
      <ns3:name>polkit</ns3:name>
    </ns3:dpkginfo_object>
    <ns3:dpkginfo_object id="obj_inventory_test_package_postfix_installed" version="1">
      <ns3:name>postfix</ns3:name>
    </ns3:dpkginfo_object>
    <ns3:dpkginfo_object id="obj_inventory_test_package_rootfiles_installed" version="1">
      <ns3:name>rootfiles</ns3:name>
    </ns3:dpkginfo_object>
    <ns3:dpkginfo_object id="obj_inventory_test_package_rsh-server_installed" version="1">
      <ns3:name>rsh-server</ns3:name>
    </ns3:dpkginfo_object>
    <ns3:dpkginfo_object id="obj_inventory_test_package_rsyslog_installed" version="1">
      <ns3:name>rsyslog</ns3:name>
    </ns3:dpkginfo_object>
    <ns3:dpkginfo_object id="obj_inventory_test_package_shadow-utils_installed" version="1">
      <ns3:name>login</ns3:name>
    </ns3:dpkginfo_object>
    <ns3:dpkginfo_object id="obj_inventory_test_package_snmpd_installed" version="1">
      <ns3:name>net-snmp</ns3:name>
    </ns3:dpkginfo_object>
    <ns3:dpkginfo_object id="obj_inventory_test_package_squid_installed" version="1">
      <ns3:name>squid</ns3:name>
    </ns3:dpkginfo_object>
    <ns3:dpkginfo_object id="obj_inventory_test_package_sssd_installed" version="1">
      <ns3:name>sssd</ns3:name>
    </ns3:dpkginfo_object>
    <ns3:dpkginfo_object id="obj_inventory_test_package_sudo_installed" version="1">
      <ns3:name>sudo</ns3:name>
    </ns3:dpkginfo_object>
    <ns3:dpkginfo_object id="obj_inventory_test_package_systemd-journal-remote_installed" version="1">
      <ns3:name>systemd-journal-remote</ns3:name>
    </ns3:dpkginfo_object>
    <ns3:dpkginfo_object id="obj_inventory_test_package_systemd-timesyncd_installed" version="1">
      <ns3:name>systemd-timesyncd</ns3:name>
    </ns3:dpkginfo_object>
    <ns3:dpkginfo_object id="obj_inventory_test_package_systemd_installed" version="1">
      <ns3:name>systemd</ns3:name>
    </ns3:dpkginfo_object>
    <ns3:dpkginfo_object id="obj_inventory_test_package_telnet-server_installed" version="1">
      <ns3:name>telnet-server</ns3:name>
    </ns3:dpkginfo_object>
    <ns3:dpkginfo_object id="obj_inventory_test_package_tftp-server_installed" version="1">
      <ns3:name>tftp-server</ns3:name>
    </ns3:dpkginfo_object>
    <ns3:dpkginfo_object id="obj_inventory_test_package_tmux_installed" version="1">
      <ns3:name>tmux</ns3:name>
    </ns3:dpkginfo_object>
    <ns3:dpkginfo_object id="obj_inventory_test_package_ufw_installed" version="1">
      <ns3:name>ufw</ns3:name>
    </ns3:dpkginfo_object>
    <ns3:dpkginfo_object id="obj_inventory_test_package_usbguard_installed" version="1">
      <ns3:name>usbguard</ns3:name>
    </ns3:dpkginfo_object>
    <ns3:systemdunitproperty_object id="obj_service_not_running_service_disabled_firewalld_firewalld" version="1" comment="Retrieve the ActiveState property of firewalld">
      <ns3:unit operation="pattern match">^firewalld\.(service|socket)$</ns3:unit>
      <ns3:property>ActiveState</ns3:property>
    </ns3:systemdunitproperty_object>
    <ns3:systemdunitproperty_object id="obj_service_loadstate_is_masked_service_disabled_firewalld_firewalld" version="1" comment="Retrieve the LoadState property of firewalld">
      <ns3:unit operation="pattern match">^firewalld\.(service|socket)$</ns3:unit>
      <ns3:property>LoadState</ns3:property>
    </ns3:systemdunitproperty_object>
    <ns3:dpkginfo_object id="obj_service_disabled_firewalldtest_service_firewalld_package_firewalld_removed" version="1">
      <ns3:name>firewalld</ns3:name>
    </ns3:dpkginfo_object>
    <ns3:systemdunitproperty_object id="obj_service_not_running_service_disabled_iptables_iptables" version="1" comment="Retrieve the ActiveState property of iptables">
      <ns3:unit operation="pattern match">^iptables\.(service|socket)$</ns3:unit>
      <ns3:property>ActiveState</ns3:property>
    </ns3:systemdunitproperty_object>
    <ns3:systemdunitproperty_object id="obj_service_loadstate_is_masked_service_disabled_iptables_iptables" version="1" comment="Retrieve the LoadState property of iptables">
      <ns3:unit operation="pattern match">^iptables\.(service|socket)$</ns3:unit>
      <ns3:property>LoadState</ns3:property>
    </ns3:systemdunitproperty_object>
    <ns3:dpkginfo_object id="obj_service_disabled_iptablestest_service_iptables_package_iptables_removed" version="1">
      <ns3:name>iptables</ns3:name>
    </ns3:dpkginfo_object>
    <ns3:systemdunitproperty_object id="obj_service_not_running_service_disabled_nftables_nftables" version="1" comment="Retrieve the ActiveState property of nftables">
      <ns3:unit operation="pattern match">^nftables\.(service|socket)$</ns3:unit>
      <ns3:property>ActiveState</ns3:property>
    </ns3:systemdunitproperty_object>
    <ns3:systemdunitproperty_object id="obj_service_loadstate_is_masked_service_disabled_nftables_nftables" version="1" comment="Retrieve the LoadState property of nftables">
      <ns3:unit operation="pattern match">^nftables\.(service|socket)$</ns3:unit>
      <ns3:property>LoadState</ns3:property>
    </ns3:systemdunitproperty_object>
    <ns3:dpkginfo_object id="obj_service_disabled_nftablestest_service_nftables_package_nftables_removed" version="1">
      <ns3:name>nftables</ns3:name>
    </ns3:dpkginfo_object>
    <ns3:systemdunitproperty_object id="obj_service_not_running_service_disabled_rsyslog_rsyslog" version="1" comment="Retrieve the ActiveState property of rsyslog">
      <ns3:unit operation="pattern match">^rsyslog\.(service|socket)$</ns3:unit>
      <ns3:property>ActiveState</ns3:property>
    </ns3:systemdunitproperty_object>
    <ns3:systemdunitproperty_object id="obj_service_loadstate_is_masked_service_disabled_rsyslog_rsyslog" version="1" comment="Retrieve the LoadState property of rsyslog">
      <ns3:unit operation="pattern match">^rsyslog\.(service|socket)$</ns3:unit>
      <ns3:property>LoadState</ns3:property>
    </ns3:systemdunitproperty_object>
    <ns3:dpkginfo_object id="obj_service_disabled_rsyslogtest_service_rsyslog_package_rsyslog_removed" version="1">
      <ns3:name>rsyslog</ns3:name>
    </ns3:dpkginfo_object>
    <ns3:systemdunitproperty_object id="obj_service_not_running_service_disabled_ufw_ufw" version="1" comment="Retrieve the ActiveState property of ufw">
      <ns3:unit operation="pattern match">^ufw\.(service|socket)$</ns3:unit>
      <ns3:property>ActiveState</ns3:property>
    </ns3:systemdunitproperty_object>
    <ns3:systemdunitproperty_object id="obj_service_loadstate_is_masked_service_disabled_ufw_ufw" version="1" comment="Retrieve the LoadState property of ufw">
      <ns3:unit operation="pattern match">^ufw\.(service|socket)$</ns3:unit>
      <ns3:property>LoadState</ns3:property>
    </ns3:systemdunitproperty_object>
    <ns3:dpkginfo_object id="obj_service_disabled_ufwtest_service_ufw_package_ufw_removed" version="1">
      <ns3:name>ufw</ns3:name>
    </ns3:dpkginfo_object>
  </ns0:objects>
  <ns0:states>
    <ns4:file_state id="bootc_platform_ste_ostree_symlink_exists" version="1" operator="AND" comment="The file /ostree is a symlink">
      <ns4:filepath operation="equals">/ostree</ns4:filepath>
      <ns4:type operation="equals">symbolic link</ns4:type>
    </ns4:file_state>
    <ns3:rpminfo_state id="state_alinux2" version="1" operator="AND">
      <ns3:version operation="pattern match">^2.*$</ns3:version>
    </ns3:rpminfo_state>
    <ns3:rpminfo_state id="state_alinux3" version="1" operator="AND">
      <ns3:version operation="pattern match">^3.*$</ns3:version>
    </ns3:rpminfo_state>
    <ns3:rpminfo_state id="state_anolis8" version="1" operator="AND">
      <ns3:version operation="pattern match">^8.*$</ns3:version>
    </ns3:rpminfo_state>
    <ns3:rpminfo_state id="state_rhevm4_version" version="1" operator="AND">
      <ns3:version operation="pattern match">^4.*$</ns3:version>
    </ns3:rpminfo_state>
    <ns4:uname_state id="state_kernel_uek" version="1" operator="AND">
      <ns4:os_release operation="pattern match">^.*uek.*</ns4:os_release>
    </ns4:uname_state>
    <ns3:dpkginfo_state id="state_krb5_server_version_1_17_18" version="1" operator="AND">
      <ns3:evr datatype="evr_string" operation="less than">0:1.17-18</ns3:evr>
    </ns3:dpkginfo_state>
    <ns3:dpkginfo_state id="state_krb5_workstation_version_1_17_18" version="1" operator="AND">
      <ns3:evr datatype="evr_string" operation="less than">0:1.17-18</ns3:evr>
    </ns3:dpkginfo_state>
    <ns4:sysctl_state id="state_runtime_kernel_fips_enabled" version="1" operator="AND">
      <ns4:value datatype="int" operation="equals">1</ns4:value>
    </ns4:sysctl_state>
    <ns5:filehash58_state id="state_secure_boot_enabled" version="1" operator="AND">
      <ns5:hash>b401b4bd7e4f321db95fcae00d274ab8aa2cf1852d1495c382356d981f63d771</ns5:hash>
    </ns5:filehash58_state>
    <ns5:textfilecontent54_state id="state_etc_selinux_configured" version="1" operator="AND">
      <ns5:subexpression datatype="string" operation="pattern match">^(enforcing|permissive)$</ns5:subexpression>
    </ns5:textfilecontent54_state>
    <ns5:textfilecontent54_state id="state_bootloader_disable_recovery_argument" version="1" operator="AND">
      <ns5:subexpression datatype="string" operation="pattern match">^(true|"true")$</ns5:subexpression>
    </ns5:textfilecontent54_state>
    <ns5:textfilecontent54_state id="state_name_al2023" version="1" operator="AND">
      <ns5:subexpression>amzn</ns5:subexpression>
    </ns5:textfilecontent54_state>
    <ns5:textfilecontent54_state id="state_version_al2023" version="1" operator="AND">
      <ns5:subexpression>2023</ns5:subexpression>
    </ns5:textfilecontent54_state>
    <ns3:rpminfo_state id="state_anolis23" version="1" operator="AND">
      <ns3:version operation="pattern match">^23.*$</ns3:version>
    </ns3:rpminfo_state>
    <ns5:textfilecontent54_state id="state_name_centos10" version="1" operator="AND">
      <ns5:subexpression>centos</ns5:subexpression>
    </ns5:textfilecontent54_state>
    <ns5:textfilecontent54_state id="state_version_centos10" version="1" operator="AND">
      <ns5:subexpression>10</ns5:subexpression>
    </ns5:textfilecontent54_state>
    <ns5:textfilecontent54_state id="state_name_centos8" version="1" operator="AND">
      <ns5:subexpression>centos</ns5:subexpression>
    </ns5:textfilecontent54_state>
    <ns5:textfilecontent54_state id="state_version_centos8" version="1" operator="AND">
      <ns5:subexpression>8</ns5:subexpression>
    </ns5:textfilecontent54_state>
    <ns5:textfilecontent54_state id="state_name_centos9" version="1" operator="AND">
      <ns5:subexpression>centos</ns5:subexpression>
    </ns5:textfilecontent54_state>
    <ns5:textfilecontent54_state id="state_version_centos9" version="1" operator="AND">
      <ns5:subexpression>9</ns5:subexpression>
    </ns5:textfilecontent54_state>
    <ns3:rpminfo_state id="state_kylinserver10_installed" version="1" operator="AND">
      <ns3:version operation="pattern match">^10.*$</ns3:version>
    </ns3:rpminfo_state>
    <ns5:textfilecontent54_state id="state_os_id_is_ol" version="1" operator="AND">
      <ns5:subexpression operation="pattern match">ol</ns5:subexpression>
    </ns5:textfilecontent54_state>
    <ns3:rpminfo_state id="state_ol10_system" version="1" operator="AND">
      <ns3:version operation="pattern match">^10.*$</ns3:version>
    </ns3:rpminfo_state>
    <ns3:rpminfo_state id="state_ol7_system" version="1" operator="AND">
      <ns3:version operation="pattern match">^7.*$</ns3:version>
    </ns3:rpminfo_state>
    <ns3:rpminfo_state id="state_ol8_system" version="1" operator="AND">
      <ns3:version operation="pattern match">^8.*$</ns3:version>
    </ns3:rpminfo_state>
    <ns3:rpminfo_state id="state_ol9_system" version="1" operator="AND">
      <ns3:version operation="pattern match">^9.*$</ns3:version>
    </ns3:rpminfo_state>
    <ns3:rpminfo_state id="state_openeuler2203_installed" version="1" operator="AND">
      <ns3:version operation="pattern match">^22\.03.*$</ns3:version>
    </ns3:rpminfo_state>
    <ns3:rpminfo_state id="state_opensuse_installed" version="1" operator="AND">
      <ns3:name operation="pattern match">openSUSE-release</ns3:name>
    </ns3:rpminfo_state>
    <ns3:rpminfo_state id="state_opensuse_leap15_installed" version="1" operator="AND">
      <ns3:version operation="pattern match">^15.*$</ns3:version>
    </ns3:rpminfo_state>
    <ns3:rpminfo_state id="state_opensuse_leap16_installed" version="1" operator="AND">
      <ns3:version operation="pattern match">^16.*$</ns3:version>
    </ns3:rpminfo_state>
    <ns5:family_state id="state_unix_family" version="1" operator="AND">
      <ns5:family>unix</ns5:family>
    </ns5:family_state>
    <ns5:textfilecontent54_state id="state_rhcos" version="1" operator="AND">
      <ns5:subexpression operation="pattern match">rhcos</ns5:subexpression>
    </ns5:textfilecontent54_state>
    <ns5:textfilecontent54_state id="state_rhel_coreos_variant" version="1" operator="AND">
      <ns5:subexpression operation="pattern match">coreos</ns5:subexpression>
    </ns5:textfilecontent54_state>
    <ns5:textfilecontent54_state id="state_rhel_coreos_version9" version="1" operator="AND">
      <ns5:subexpression operation="pattern match">^9\.</ns5:subexpression>
    </ns5:textfilecontent54_state>
    <ns5:textfilecontent54_state id="state_rhel_coreos_version10" version="1" operator="AND">
      <ns5:subexpression operation="pattern match">^10\.</ns5:subexpression>
    </ns5:textfilecontent54_state>
    <ns5:textfilecontent54_state id="state_rhcos4" version="1" operator="AND">
      <ns5:subexpression operation="pattern match">4</ns5:subexpression>
    </ns5:textfilecontent54_state>
    <ns5:textfilecontent54_state id="state_rhcos4_rhel8_rhel_version" version="1" operator="AND">
      <ns5:subexpression operation="pattern match">^8\.</ns5:subexpression>
    </ns5:textfilecontent54_state>
    <ns5:textfilecontent54_state id="state_rhel_id" version="1" operator="AND">
      <ns5:subexpression operation="pattern match">rhel</ns5:subexpression>
    </ns5:textfilecontent54_state>
    <ns5:textfilecontent54_state id="state_rhcos4_rhel9_rhel_version" version="1" operator="AND">
      <ns5:subexpression operation="pattern match">^9\.</ns5:subexpression>
    </ns5:textfilecontent54_state>
    <ns5:textfilecontent54_state id="state_os_id_is_rhel" version="1" operator="AND">
      <ns5:subexpression operation="pattern match">rhel</ns5:subexpression>
    </ns5:textfilecontent54_state>
    <ns5:family_state id="state_rhel10_unix_family" version="1" operator="AND">
      <ns5:family>unix</ns5:family>
    </ns5:family_state>
    <ns3:rpminfo_state id="state_rhel10" version="1" operator="AND">
      <ns3:version operation="pattern match">^10.*$</ns3:version>
    </ns3:rpminfo_state>
    <ns5:textfilecontent54_state id="state_rhevh_rhel10_version" version="1" operator="AND">
      <ns5:subexpression operation="pattern match">10</ns5:subexpression>
    </ns5:textfilecontent54_state>
    <ns5:family_state id="state_rhel8_unix_family" version="1" operator="AND">
      <ns5:family>unix</ns5:family>
    </ns5:family_state>
    <ns3:rpminfo_state id="state_rhel8" version="1" operator="AND">
      <ns3:version operation="pattern match">^8\.\d{1,2}$</ns3:version>
    </ns3:rpminfo_state>
    <ns3:rpminfo_state id="state_rhel8_0" version="1" operator="AND">
      <ns3:version operation="pattern match">^8.0*$</ns3:version>
    </ns3:rpminfo_state>
    <ns3:rpminfo_state id="state_rhel8_1" version="1" operator="AND">
      <ns3:version operation="pattern match">^8.1*$</ns3:version>
    </ns3:rpminfo_state>
    <ns3:rpminfo_state id="state_rhel8_2" version="1" operator="AND">
      <ns3:version operation="pattern match">^8.2*$</ns3:version>
    </ns3:rpminfo_state>
    <ns3:rpminfo_state id="state_rhel8_3" version="1" operator="AND">
      <ns3:version operation="pattern match">^8.3*$</ns3:version>
    </ns3:rpminfo_state>
    <ns3:rpminfo_state id="state_rhel8_4" version="1" operator="AND">
      <ns3:version operation="pattern match">^8.4*$</ns3:version>
    </ns3:rpminfo_state>
    <ns3:rpminfo_state id="state_rhel8_5" version="1" operator="AND">
      <ns3:version operation="pattern match">^8.5*$</ns3:version>
    </ns3:rpminfo_state>
    <ns3:rpminfo_state id="state_rhel8_6" version="1" operator="AND">
      <ns3:version operation="pattern match">^8.6*$</ns3:version>
    </ns3:rpminfo_state>
    <ns3:rpminfo_state id="state_rhel8_7" version="1" operator="AND">
      <ns3:version operation="pattern match">^8.7*$</ns3:version>
    </ns3:rpminfo_state>
    <ns3:rpminfo_state id="state_rhel8_8" version="1" operator="AND">
      <ns3:version operation="pattern match">^8.8*$</ns3:version>
    </ns3:rpminfo_state>
    <ns3:rpminfo_state id="state_rhel8_9" version="1" operator="AND">
      <ns3:version operation="pattern match">^8.9*$</ns3:version>
    </ns3:rpminfo_state>
    <ns3:rpminfo_state id="state_rhel8_10" version="1" operator="AND">
      <ns3:version operation="pattern match">^8.10*$</ns3:version>
    </ns3:rpminfo_state>
    <ns5:textfilecontent54_state id="state_rhevh_rhel8_version" version="1" operator="AND">
      <ns5:subexpression operation="pattern match">8</ns5:subexpression>
    </ns5:textfilecontent54_state>
    <ns5:family_state id="state_rhel9_unix_family" version="1" operator="AND">
      <ns5:family>unix</ns5:family>
    </ns5:family_state>
    <ns3:rpminfo_state id="state_rhel9" version="1" operator="AND">
      <ns3:version operation="pattern match">^9.*$</ns3:version>
    </ns3:rpminfo_state>
    <ns5:textfilecontent54_state id="state_rhevh_rhel9_version" version="1" operator="AND">
      <ns5:subexpression operation="pattern match">9</ns5:subexpression>
    </ns5:textfilecontent54_state>
    <ns3:rpminfo_state id="state_rhvh4_version" version="1" operator="AND">
      <ns3:evr datatype="evr_string" operation="greater than or equal">0:4.4</ns3:evr>
    </ns3:rpminfo_state>
    <ns5:family_state id="state_sle12_unix_family" version="1" operator="AND">
      <ns5:family>unix</ns5:family>
    </ns5:family_state>
    <ns3:rpminfo_state id="state_sle12_desktop" version="1" operator="AND">
      <ns3:version operation="pattern match">^12.*$</ns3:version>
    </ns3:rpminfo_state>
    <ns3:rpminfo_state id="state_sle12_server" version="1" operator="AND">
      <ns3:version operation="pattern match">^12.*$</ns3:version>
    </ns3:rpminfo_state>
    <ns3:rpminfo_state id="state_sles_12_for_sap" version="1" operator="AND">
      <ns3:version operation="pattern match">^12.*$</ns3:version>
    </ns3:rpminfo_state>
    <ns5:family_state id="state_sle15_unix_family" version="1" operator="AND">
      <ns5:family>unix</ns5:family>
    </ns5:family_state>
    <ns3:rpminfo_state id="state_sle15_desktop" version="1" operator="AND">
      <ns3:version operation="pattern match">^15.*$</ns3:version>
    </ns3:rpminfo_state>
    <ns3:rpminfo_state id="state_sle15_server" version="1" operator="AND">
      <ns3:version operation="pattern match">^15.*$</ns3:version>
    </ns3:rpminfo_state>
    <ns3:rpminfo_state id="state_sles_15_for_sap" version="1" operator="AND">
      <ns3:version operation="pattern match">^15.*$</ns3:version>
    </ns3:rpminfo_state>
    <ns3:rpminfo_state id="state_suma_4" version="1" operator="AND">
      <ns3:version operation="pattern match">^4.*$</ns3:version>
    </ns3:rpminfo_state>
    <ns3:rpminfo_state id="state_sle_hpc" version="1" operator="AND">
      <ns3:version operation="pattern match">^15.*$</ns3:version>
    </ns3:rpminfo_state>
    <ns5:family_state id="state_sle16_unix_family" version="1" operator="AND">
      <ns5:family>unix</ns5:family>
    </ns5:family_state>
    <ns3:rpminfo_state id="state_sle16_server" version="1" operator="AND">
      <ns3:version operation="pattern match">^16.*$</ns3:version>
    </ns3:rpminfo_state>
    <ns3:rpminfo_state id="state_sles_16_for_sap" version="1" operator="AND">
      <ns3:version operation="pattern match">^16.*$</ns3:version>
    </ns3:rpminfo_state>
    <ns3:rpminfo_state id="state_sles_16_for_ha" version="1" operator="AND">
      <ns3:version operation="pattern match">^16.*$</ns3:version>
    </ns3:rpminfo_state>
    <ns5:family_state id="state_slmicro5_unix_family" version="1" operator="AND">
      <ns5:family>unix</ns5:family>
    </ns5:family_state>
    <ns3:rpminfo_state id="state_slmicroos5" version="1" operator="AND">
      <ns3:version operation="pattern match">^5.*$</ns3:version>
    </ns3:rpminfo_state>
    <ns3:rpminfo_state id="state_slmicro5" version="1" operator="AND">
      <ns3:version operation="pattern match">^5.*$</ns3:version>
    </ns3:rpminfo_state>
    <ns5:family_state id="state_slmicro6_unix_family" version="1" operator="AND">
      <ns5:family>unix</ns5:family>
    </ns5:family_state>
    <ns3:rpminfo_state id="state_slmicro6" version="1" operator="AND">
      <ns3:version operation="pattern match">^6.*$</ns3:version>
    </ns3:rpminfo_state>
    <ns3:rpminfo_state id="state_tencentos4" version="1" operator="AND">
      <ns3:version operation="pattern match">^4.*$</ns3:version>
    </ns3:rpminfo_state>
    <ns5:environmentvariable58_state id="state_installed_env_is_osbuild" version="1" operator="AND">
      <ns5:value>bwrap-osbuild</ns5:value>
    </ns5:environmentvariable58_state>
    <ns5:variable_state id="state_sshd_not_required" version="1" operator="AND">
      <ns5:value operation="equals" datatype="int">1</ns5:value>
    </ns5:variable_state>
    <ns5:variable_state id="state_sshd_required" version="1" operator="AND">
      <ns5:value operation="equals" datatype="int">2</ns5:value>
    </ns5:variable_state>
    <ns5:variable_state id="state_sshd_requirement_unset" version="1" operator="AND">
      <ns5:value operation="equals" datatype="int">0</ns5:value>
    </ns5:variable_state>
    <ns3:dpkginfo_state id="state_openssh-server_version" version="1" operator="AND">
      <ns3:evr datatype="evr_string" operation="greater than or equal">0:7.4</ns3:evr>
    </ns3:dpkginfo_state>
    <ns4:uname_state id="state_system_info_architecture_aarch_64" version="1" operator="AND" comment="64 bit architecture">
      <ns4:processor_type operation="equals">aarch64</ns4:processor_type>
    </ns4:uname_state>
    <ns4:uname_state id="state_system_info_architecture_ppc_64" version="1" operator="AND" comment="64 bit architecture">
      <ns4:processor_type operation="equals">ppc64</ns4:processor_type>
    </ns4:uname_state>
    <ns4:uname_state id="state_system_info_architecture_ppcle_64" version="1" operator="AND" comment="64 bit architecture">
      <ns4:processor_type operation="equals">ppc64le</ns4:processor_type>
    </ns4:uname_state>
    <ns4:uname_state id="state_system_info_architecture_s390_64" version="1" operator="AND" comment="64 bit architecture">
      <ns4:processor_type operation="equals">s390x</ns4:processor_type>
    </ns4:uname_state>
    <ns4:uname_state id="state_system_info_architecture_x86" version="1" operator="AND" comment="32 bit architecture">
      <ns4:processor_type operation="equals">i686</ns4:processor_type>
    </ns4:uname_state>
    <ns4:uname_state id="state_system_info_architecture_x86_64" version="1" operator="AND" comment="64 bit architecture">
      <ns4:processor_type operation="equals">x86_64</ns4:processor_type>
    </ns4:uname_state>
    <ns4:file_state id="state_tmux_conf_readable_by_others" version="1" operator="AND">
      <ns4:oread datatype="boolean">true</ns4:oread>
    </ns4:file_state>
    <ns5:variable_state id="state_var_removable_partition_is_cd_dvd_drive" version="1" operator="AND">
      <ns5:value operation="equals">/dev/cdrom</ns5:value>
    </ns5:variable_state>
    <ns5:textfilecontent54_state id="state_grub2_ipv6_disable_argument" version="1" operator="AND">
      <ns5:subexpression datatype="int" operation="equals">0</ns5:subexpression>
    </ns5:textfilecontent54_state>
    <ns5:textfilecontent54_state id="state_os_id_is_os_linux_ol_gt_or_eq_8_7" version="1" operator="AND">
      <ns5:subexpression operation="pattern match">ol</ns5:subexpression>
    </ns5:textfilecontent54_state>
    <ns5:textfilecontent54_state id="state_os_linux_ol_gt_or_eq_8_7_gt_or_eq_8_7" version="1" operator="AND">
      <ns5:subexpression operation="greater than or equal" datatype="version">8.7</ns5:subexpression>
    </ns5:textfilecontent54_state>
    <ns5:textfilecontent54_state id="state_os_id_is_os_linux_ol_gt_or_eq_9_0" version="1" operator="AND">
      <ns5:subexpression operation="pattern match">ol</ns5:subexpression>
    </ns5:textfilecontent54_state>
    <ns5:textfilecontent54_state id="state_os_linux_ol_gt_or_eq_9_0_gt_or_eq_9_0" version="1" operator="AND">
      <ns5:subexpression operation="greater than or equal" datatype="version">9.0</ns5:subexpression>
    </ns5:textfilecontent54_state>
    <ns5:textfilecontent54_state id="state_os_id_is_os_linux_rhel_gt_or_eq_8_7" version="1" operator="AND">
      <ns5:subexpression operation="pattern match">rhel</ns5:subexpression>
    </ns5:textfilecontent54_state>
    <ns5:textfilecontent54_state id="state_os_linux_rhel_gt_or_eq_8_7_gt_or_eq_8_7" version="1" operator="AND">
      <ns5:subexpression operation="greater than or equal" datatype="version">8.7</ns5:subexpression>
    </ns5:textfilecontent54_state>
    <ns5:textfilecontent54_state id="state_os_id_is_os_linux_rhel_gt_or_eq_9_0" version="1" operator="AND">
      <ns5:subexpression operation="pattern match">rhel</ns5:subexpression>
    </ns5:textfilecontent54_state>
    <ns5:textfilecontent54_state id="state_os_linux_rhel_gt_or_eq_9_0_gt_or_eq_9_0" version="1" operator="AND">
      <ns5:subexpression operation="greater than or equal" datatype="version">9.0</ns5:subexpression>
    </ns5:textfilecontent54_state>
    <ns5:textfilecontent54_state id="state_os_id_is_os_linux_rhel_le_or_eq_8_4" version="1" operator="AND">
      <ns5:subexpression operation="pattern match">rhel</ns5:subexpression>
    </ns5:textfilecontent54_state>
    <ns5:textfilecontent54_state id="state_os_linux_rhel_le_or_eq_8_4_le_or_eq_8_4" version="1" operator="AND">
      <ns5:subexpression operation="less than or equal" datatype="version">8.4</ns5:subexpression>
    </ns5:textfilecontent54_state>
    <ns5:textfilecontent54_state id="state_os_id_is_os_linux_rhel_ne_9_0" version="1" operator="AND">
      <ns5:subexpression operation="pattern match">rhel</ns5:subexpression>
    </ns5:textfilecontent54_state>
    <ns5:textfilecontent54_state id="state_os_linux_rhel_ne_9_0_ne_9_0" version="1" operator="AND">
      <ns5:subexpression operation="not equal" datatype="version">9.0</ns5:subexpression>
    </ns5:textfilecontent54_state>
    <ns5:textfilecontent54_state id="state_os_id_is_os_linux_sles_gt_or_eq_15" version="1" operator="AND">
      <ns5:subexpression operation="pattern match">sles</ns5:subexpression>
    </ns5:textfilecontent54_state>
    <ns5:textfilecontent54_state id="state_os_linux_sles_gt_or_eq_15_gt_or_eq_15" version="1" operator="AND">
      <ns5:subexpression operation="greater than or equal" datatype="version">15</ns5:subexpression>
    </ns5:textfilecontent54_state>
    <ns3:dpkginfo_state id="ste_inventory_test_package_openssh-server_le_7_0_le_7_0_installed" version="1" operator="AND">
      <ns3:evr datatype="debian_evr_string" operation="less than">0:7.0-0</ns3:evr>
    </ns3:dpkginfo_state>
    <ns3:dpkginfo_state id="ste_inventory_test_package_openssh-server_le_7_5_le_7_5_installed" version="1" operator="AND">
      <ns3:evr datatype="debian_evr_string" operation="less than">0:7.5-0</ns3:evr>
    </ns3:dpkginfo_state>
    <ns3:systemdunitproperty_state id="state_service_not_running_service_disabled_firewalld_firewalld" version="1" operator="AND" comment="firewalld is not running">
      <ns3:value operation="pattern match">inactive|failed</ns3:value>
    </ns3:systemdunitproperty_state>
    <ns3:systemdunitproperty_state id="state_service_loadstate_is_masked_service_disabled_firewalld_firewalld" version="1" operator="AND" comment="LoadState is set to masked">
      <ns3:value>masked</ns3:value>
    </ns3:systemdunitproperty_state>
    <ns3:systemdunitproperty_state id="state_service_is_not_found_service_disabled_firewalld_firewalld" version="1" operator="AND" comment="Service is not found">
      <ns3:value>not-found</ns3:value>
    </ns3:systemdunitproperty_state>
    <ns3:systemdunitproperty_state id="state_service_not_running_service_disabled_iptables_iptables" version="1" operator="AND" comment="iptables is not running">
      <ns3:value operation="pattern match">inactive|failed</ns3:value>
    </ns3:systemdunitproperty_state>
    <ns3:systemdunitproperty_state id="state_service_loadstate_is_masked_service_disabled_iptables_iptables" version="1" operator="AND" comment="LoadState is set to masked">
      <ns3:value>masked</ns3:value>
    </ns3:systemdunitproperty_state>
    <ns3:systemdunitproperty_state id="state_service_is_not_found_service_disabled_iptables_iptables" version="1" operator="AND" comment="Service is not found">
      <ns3:value>not-found</ns3:value>
    </ns3:systemdunitproperty_state>
    <ns3:systemdunitproperty_state id="state_service_not_running_service_disabled_nftables_nftables" version="1" operator="AND" comment="nftables is not running">
      <ns3:value operation="pattern match">inactive|failed</ns3:value>
    </ns3:systemdunitproperty_state>
    <ns3:systemdunitproperty_state id="state_service_loadstate_is_masked_service_disabled_nftables_nftables" version="1" operator="AND" comment="LoadState is set to masked">
      <ns3:value>masked</ns3:value>
    </ns3:systemdunitproperty_state>
    <ns3:systemdunitproperty_state id="state_service_is_not_found_service_disabled_nftables_nftables" version="1" operator="AND" comment="Service is not found">
      <ns3:value>not-found</ns3:value>
    </ns3:systemdunitproperty_state>
    <ns3:systemdunitproperty_state id="state_service_not_running_service_disabled_rsyslog_rsyslog" version="1" operator="AND" comment="rsyslog is not running">
      <ns3:value operation="pattern match">inactive|failed</ns3:value>
    </ns3:systemdunitproperty_state>
    <ns3:systemdunitproperty_state id="state_service_loadstate_is_masked_service_disabled_rsyslog_rsyslog" version="1" operator="AND" comment="LoadState is set to masked">
      <ns3:value>masked</ns3:value>
    </ns3:systemdunitproperty_state>
    <ns3:systemdunitproperty_state id="state_service_is_not_found_service_disabled_rsyslog_rsyslog" version="1" operator="AND" comment="Service is not found">
      <ns3:value>not-found</ns3:value>
    </ns3:systemdunitproperty_state>
    <ns3:systemdunitproperty_state id="state_service_not_running_service_disabled_ufw_ufw" version="1" operator="AND" comment="ufw is not running">
      <ns3:value operation="pattern match">inactive|failed</ns3:value>
    </ns3:systemdunitproperty_state>
    <ns3:systemdunitproperty_state id="state_service_loadstate_is_masked_service_disabled_ufw_ufw" version="1" operator="AND" comment="LoadState is set to masked">
      <ns3:value>masked</ns3:value>
    </ns3:systemdunitproperty_state>
    <ns3:systemdunitproperty_state id="state_service_is_not_found_service_disabled_ufw_ufw" version="1" operator="AND" comment="Service is not found">
      <ns3:value>not-found</ns3:value>
    </ns3:systemdunitproperty_state>
  </ns0:states>
  <ns0:variables>
    <ns0:constant_variable id="var_pam_pwquality_config_path" version="1" datatype="string" comment="correct path for pam_pwquality.so check">
      <ns0:value>/etc/pam.d/common-password</ns0:value>
    </ns0:constant_variable>
    <ns0:local_variable id="audit_log_file_path" version="1" datatype="string" comment="path to audit log files">
      <ns0:regex_capture pattern="^log_file\s*=\s*(.*)">
        <ns0:object_component item_field="subexpression" object_ref="object_auditd_conf_log_file" />
      </ns0:regex_capture>
    </ns0:local_variable>
    <ns0:constant_variable id="variable_cd_dvd_drive_alternative_names" version="1" datatype="string" comment="CD/DVD drive allowed alternative names">
      <ns0:value>/dev/cdrom</ns0:value>
      <ns0:value>/dev/dvd</ns0:value>
      <ns0:value>/dev/scd0</ns0:value>
      <ns0:value>/dev/sr0</ns0:value>
    </ns0:constant_variable>
    <ns0:external_variable id="var_removable_partition" version="1" datatype="string" comment="removable partition" />
    <ns0:external_variable id="sshd_required" version="1" datatype="int" comment="May be defined by Profiles to explicitly say if sshd is required or not" />
    <ns0:external_variable id="var_accounts_user_umask" version="1" datatype="string" comment="Value of var_accounts_user_umask (the required umask) as string" />
    <ns0:local_variable id="var_first_digit_of_umask_from_var_accounts_user_umask" version="1" datatype="int" comment="First octal digit of umask from var_accounts_user_umask">
      <ns0:substring substring_start="1" substring_length="1">
        <ns0:variable_component var_ref="var_accounts_user_umask" />
      </ns0:substring>
    </ns0:local_variable>
    <ns0:local_variable id="var_second_digit_of_umask_from_var_accounts_user_umask" version="1" datatype="int" comment="Second octal digit of umask from var_accounts_user_umask">
      <ns0:substring substring_start="2" substring_length="1">
        <ns0:variable_component var_ref="var_accounts_user_umask" />
      </ns0:substring>
    </ns0:local_variable>
    <ns0:local_variable id="var_third_digit_of_umask_from_var_accounts_user_umask" version="1" datatype="int" comment="Third octal digit of umask from var_accounts_user_umask">
      <ns0:substring substring_start="3" substring_length="1">
        <ns0:variable_component var_ref="var_accounts_user_umask" />
      </ns0:substring>
    </ns0:local_variable>
    <ns0:local_variable id="var_accounts_user_umask_umask_as_number" version="1" datatype="int" comment="var_accounts_user_umask umask converted from string to a number">
      <ns0:arithmetic arithmetic_operation="add">
        <ns0:arithmetic arithmetic_operation="multiply">
          <ns0:literal_component datatype="int">64</ns0:literal_component>
          <ns0:variable_component var_ref="var_first_digit_of_umask_from_var_accounts_user_umask" />
        </ns0:arithmetic>
        <ns0:arithmetic arithmetic_operation="multiply">
          <ns0:literal_component datatype="int">8</ns0:literal_component>
          <ns0:variable_component var_ref="var_second_digit_of_umask_from_var_accounts_user_umask" />
        </ns0:arithmetic>
        <ns0:variable_component var_ref="var_third_digit_of_umask_from_var_accounts_user_umask" />
      </ns0:arithmetic>
    </ns0:local_variable>
    <ns0:external_variable id="var_umask_for_daemons" version="1" datatype="string" comment="Value of var_umask_for_daemons (the required umask) as string" />
    <ns0:local_variable id="var_first_digit_of_umask_from_var_umask_for_daemons" version="1" datatype="int" comment="First octal digit of umask from var_umask_for_daemons">
      <ns0:substring substring_start="1" substring_length="1">
        <ns0:variable_component var_ref="var_umask_for_daemons" />
      </ns0:substring>
    </ns0:local_variable>
    <ns0:local_variable id="var_second_digit_of_umask_from_var_umask_for_daemons" version="1" datatype="int" comment="Second octal digit of umask from var_umask_for_daemons">
      <ns0:substring substring_start="2" substring_length="1">
        <ns0:variable_component var_ref="var_umask_for_daemons" />
      </ns0:substring>
    </ns0:local_variable>
    <ns0:local_variable id="var_third_digit_of_umask_from_var_umask_for_daemons" version="1" datatype="int" comment="Third octal digit of umask from var_umask_for_daemons">
      <ns0:substring substring_start="3" substring_length="1">
        <ns0:variable_component var_ref="var_umask_for_daemons" />
      </ns0:substring>
    </ns0:local_variable>
    <ns0:local_variable id="var_umask_for_daemons_umask_as_number" version="1" datatype="int" comment="var_umask_for_daemons umask converted from string to a number">
      <ns0:arithmetic arithmetic_operation="add">
        <ns0:arithmetic arithmetic_operation="multiply">
          <ns0:literal_component datatype="int">64</ns0:literal_component>
          <ns0:variable_component var_ref="var_first_digit_of_umask_from_var_umask_for_daemons" />
        </ns0:arithmetic>
        <ns0:arithmetic arithmetic_operation="multiply">
          <ns0:literal_component datatype="int">8</ns0:literal_component>
          <ns0:variable_component var_ref="var_second_digit_of_umask_from_var_umask_for_daemons" />
        </ns0:arithmetic>
        <ns0:variable_component var_ref="var_third_digit_of_umask_from_var_umask_for_daemons" />
      </ns0:arithmetic>
    </ns0:local_variable>
  </ns0:variables>
</ns0:oval_definitions>