Skip to content

2026

UNSTIG: Undoing STIG Lockdowns on RHEL

If you've ever been handed a RHEL box that's been hardened against the Security Technical Implementation Guide (STIG), you know the pain. Things that should just work — mounting a USB drive, running a script you just downloaded, sudo not asking for your password every five seconds — suddenly don't, and the error messages rarely point you at the actual cause.

This post is a running list of STIG-enforced settings I've run into and how to undo them. This is meant for personal labs, dev boxes, or environments where you have the authority to make this call — not for production systems still under a compliance mandate. Always check with whoever owns the STIG policy before changing any of this on a system you don't fully control.