Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

implement V-72095 for stig #5985

Merged

Conversation

vojtapolasek
Copy link
Collaborator

Description:

  • add audit_rules_privileged_commands_mount into stig profile

  • make rule audit_rules_media_export templated

  • modify audit_rules_dac_modifications oval template so taht it can be used with vider set of rules (problem with rule names)

Rationale:

stig effort

@@ -1,5 +1,7 @@
documentation_complete: true

prodtype: fedora,ol7,ol8,rhel6,rhel7,rhel8
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

rhcos4 product selects this rule too.
This is such a broad rule that I wonder if it makes sense to have prodtype in this rule.

Copy link
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I am not against, I changed it.

@mildas
Copy link
Contributor

mildas commented Aug 10, 2020

Changes identified:
Rule audit_rules_media_export:
 OVAL check for audit_rules_media_export was deleted.
 Bash remediation was deleted. No test for it will be selected.
 Ansible remediation for audit_rules_media_export was deleted.
Profile stig on rhel7:
 Rule audit_rules_privileged_commands_mount added to stig profile.

Recommended tests to execute:
 build_product rhel7
 tests/test_suite.py profile --libvirt qemu:///system test-suite-vm --datastream build/ssg-rhel7-ds.xml stig

@openshift-ci-robot
Copy link
Collaborator

@vojtapolasek: The following tests failed, say /retest to rerun all failed tests:

Test name Commit Details Rerun command
ci/prow/e2e-aws-rhcos4-moderate 583adc4 link /test e2e-aws-rhcos4-moderate
ci/prow/e2e-aws-rhcos4-e8 583adc4 link /test e2e-aws-rhcos4-e8

Full PR test history. Your PR dashboard.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. I understand the commands that are listed here.

@yuumasato yuumasato self-assigned this Aug 13, 2020
Copy link
Member

@yuumasato yuumasato left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@yuumasato yuumasato merged commit c2a49dd into ComplianceAsCode:master Aug 13, 2020
@marcusburghardt marcusburghardt added RHEL7 Red Hat Enterprise Linux 7 product related. STIG STIG Benchmark related. labels Jun 23, 2022
# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
RHEL7 Red Hat Enterprise Linux 7 product related. STIG STIG Benchmark related.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

5 participants