Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Revert back OVAL check for sshd_disable_compression to use xccdf variable. #6031

Merged

Conversation

ggbecker
Copy link
Member

@ggbecker ggbecker commented Aug 31, 2020

Description:

  • Revert back OVAL check for sshd_disable_compression to use xccdf variable. Previously it would accept both no and delayed values even though in the profile the selected value is no (default one).

Rationale:

@redhatrises Does this change make sense?

Reference: https://vaulted.io/library/disa-stigs-srgs/red_hat_enterprise_linux_7_security_technical_implementation_guide/V-72267?version=v2r7

@mildas
Copy link
Contributor

mildas commented Aug 31, 2020

Changes identified:
Rule sshd_disable_compression:
 Templatization usage changed in linux_os/guide/services/ssh/ssh_server/sshd_disable_compression/oval/shared.xml.

Recommended tests to execute:
 build_product ol8
 tests/test_suite.py rule --libvirt qemu:///system test-suite-vm --remediate-using bash --datastream build/ssg-ol8-ds.xml sshd_disable_compression

@ggbecker ggbecker requested a review from redhatrises August 31, 2020 15:18
@openshift-ci-robot
Copy link
Collaborator

@ggbecker: The following tests failed, say /retest to rerun all failed tests:

Test name Commit Details Rerun command
ci/prow/e2e-aws-rhcos4-moderate 8219412 link /test e2e-aws-rhcos4-moderate
ci/prow/e2e-aws-rhcos4-e8 8219412 link /test e2e-aws-rhcos4-e8

Full PR test history. Your PR dashboard.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. I understand the commands that are listed here.

@redhatrises
Copy link
Contributor

Description:

  • Revert back OVAL check for sshd_disable_compression to use xccdf variable. Previously it would accept both no and delayed values even though in the profile the selected value is no (default one).

Rationale:

  • Changes based on this comment since they are very similar: #6022 (comment)

@redhatrises Does this change make sense?

Reference: https://vaulted.io/library/disa-stigs-srgs/red_hat_enterprise_linux_7_security_technical_implementation_guide/V-72267?version=v2r7

@ggbecker yes it does. I think my brain was fried when I reviewed this originally.

@redhatrises redhatrises merged commit d090530 into ComplianceAsCode:master Aug 31, 2020
@marcusburghardt marcusburghardt added RHEL7 Red Hat Enterprise Linux 7 product related. STIG STIG Benchmark related. labels Jun 23, 2022
# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
RHEL7 Red Hat Enterprise Linux 7 product related. STIG STIG Benchmark related.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

5 participants