Compliance Score
66%
Passing Checks
4
Failing Checks
2
Not Applicable
2

Compliance Checks

Disk Encryption
Output matched failure pattern: zroot.*encryption.*off
Technical Details
$ sudo geli status 2>/dev/null || doas geli status 2>/dev/null || geli status
geli: Command 'status' not available; try 'load' first.
$ sudo zfs get -H encryption zroot 2>/dev/null || doas zfs get -H encryption zroot 2>/dev/null || zfs get -H encryption zroot 2>/dev/null
zroot encryption off default
How to Fix
  1. ZFS root pool is not encrypted
  2. Create an encrypted ZFS dataset or migrate to an encrypted pool
  3. For new pools: zpool create -O encryption=on -O keyformat=passphrase zroot ...
  4. Note that existing pools cannot be encrypted in-place
Firewall
Output missing required pattern: pf\.ko
Technical Details
$ sudo pfctl -s info 2>/dev/null || doas pfctl -s info 2>/dev/null || pfctl -s info 2>/dev/null
$ kldstat
Id Refs Address Size Name 1 58 0xffffffff80200000 217bc18 kernel 2 1 0xffffffff8237d000 777728 zfs.ko 3 1 0xffffffff83220000 4250 ichsmb.ko 4 1 0xffffffff83225000 2178 smbus.ko 5 1 0xffffffff83228000 b1340 if_iwlwifi.ko 6 1 0xffffffff832da000 3378 lindebugfs.ko 7 1 0xffffffff832de000 18314 if_iwm.ko 8 1 0xffffffff832f7000 3360 uhid.ko 9 1 0xffffffff832fb000 4364 ums.ko 10 1 0xffffffff83300000 3360 wmt.ko 11 1 0xffffffff83304000 58c0 ng_ubt.ko 12 4 0xffffffff8330a000 bbb8 netgraph.ko 13 3 0xffffffff83316000 a330 ng_hci.ko 14 2 0xffffffff83321000 2670 ng_bluetooth.ko 15 1 0xffffffff83324000 2a80 mac_ntpd.ko
$ sudo ipfw list 2>/dev/null || doas ipfw list 2>/dev/null || ipfw list 2>/dev/null
How to Fix
  1. Load PF kernel module with 'sudo kldload pf'
  2. Add pf_load="YES" to /boot/loader.conf for persistence
Hostname
Check passed
Technical Details
$ hostname
sync.atomdrift.com
System Info
Check passed
Technical Details
$ uname -srm
FreeBSD 15.0-CURRENT amd64
System Uptime
Check passed
Technical Details
$ uptime | grep -oE 'up [0-9]+ days?' | grep -oE '[0-9]+' || echo "0"
34
Uname
Check passed
Technical Details
$ uname -a
FreeBSD sync.atomdrift.com 15.0-CURRENT FreeBSD 15.0-CURRENT #0 main-n277883-e6928c33f60c: Thu Jun 12 16:43:12 UTC 2025 root@releng3.nyi.freebsd.org:/usr/obj/usr/src/amd64.amd64/sys/GENERIC amd64
Screen Lock Password
Check not applicable
Technical Details
$ pgrep gnome-shell >/dev/null && gsettings get org.gnome.desktop.screensaver lock-enabled
$ pgrep mate-session >/dev/null && gsettings get org.mate.screensaver lock-enabled
$ pgrep xfce4-session >/dev/null && xfconf-query -c xfce4-screensaver -p /saver/enabled
$ pgrep xfce4-session >/dev/null && xfconf-query -c xfce4-screensaver -p /lock/enabled
$ pgrep plasmashell >/dev/null && kreadconfig5 --file kscreenlockerrc --group Daemon --key Autolock
$ pgrep cinnamon >/dev/null && gsettings get org.cinnamon.desktop.screensaver lock-enabled
$ pgrep budgie-panel >/dev/null && gsettings get org.gnome.desktop.screensaver lock-enabled
$ pgrep lxqt-session >/dev/null && grep "lockScreenCommand" ~/.config/lxqt/session.conf 2>/dev/null
$ pgrep lxsession >/dev/null && pgrep -l "light-locker|xscreensaver|xautolock|i3lock|slock|xlock"
$ pgrep i3 >/dev/null && pgrep -l "xautolock|xss-lock|xidlehook"
$ pgrep openbox >/dev/null && pgrep -l "xautolock|xss-lock|light-locker"
$ pgrep sway >/dev/null && grep "exec swayidle" ~/.config/sway/config 2>/dev/null
$ pgrep Xorg >/dev/null && ! (pgrep gnome-shell >/dev/null || pgrep mate-session >/dev/null || pgrep xfce4-session >/dev/null || pgrep plasmashell >/dev/null || pgrep cinnamon >/dev/null || pgrep budgie-panel >/dev/null || pgrep lxqt-session >/dev/null || pgrep lxsession >/dev/null || pgrep i3 >/dev/null || pgrep openbox >/dev/null || pgrep sway >/dev/null) && xset q
Screensaver Timeout
Check not applicable
Technical Details
$ pgrep gnome-shell >/dev/null && gsettings get org.gnome.desktop.session idle-delay
$ pgrep mate-session >/dev/null && gsettings get org.mate.session idle-delay
$ pgrep xfce4-session >/dev/null && xfconf-query -c xfce4-power-manager -p /xfce4-power-manager/dpms-on-ac-sleep
$ pgrep xfce4-session >/dev/null && xfconf-query -c xfce4-power-manager -p /xfce4-power-manager/dpms-on-battery-sleep
$ pgrep plasmashell >/dev/null && kreadconfig5 --file kscreenlockerrc --group Daemon --key Timeout
$ pgrep cinnamon >/dev/null && gsettings get org.cinnamon.desktop.screensaver lock-delay
$ pgrep budgie-panel >/dev/null && gsettings get org.gnome.desktop.session idle-delay
$ pgrep lxqt-session >/dev/null && grep "timeBeforeIdleMs" ~/.config/lxqt/lxqt-config-powermanagement.conf 2>/dev/null
$ pgrep lxsession >/dev/null && pgrep -fl "xautolock.*-time"
$ pgrep sway >/dev/null && grep "timeout" ~/.config/sway/config 2>/dev/null
$ pgrep i3 >/dev/null && pgrep -fl "xautolock.*-time"
$ pgrep openbox >/dev/null && pgrep -fl "xautolock.*-time"
$ pgrep Xorg >/dev/null && ! (pgrep gnome-shell >/dev/null || pgrep mate-session >/dev/null || pgrep xfce4-session >/dev/null || pgrep plasmashell >/dev/null || pgrep cinnamon >/dev/null || pgrep budgie-panel >/dev/null || pgrep lxqt-session >/dev/null || pgrep lxsession >/dev/null || pgrep i3 >/dev/null || pgrep openbox >/dev/null || pgrep sway >/dev/null) && xset q
Powered by gitMDM