Skip to content

Commit

Permalink
Merge pull request #10736 from jhrozek/rhcos_stig_ia
Browse files Browse the repository at this point in the history
SRG-APP-000148-CTR-000335,SRG-APP-000190-CTR-000500: Covered by sshd_disable_root_login
  • Loading branch information
rhmdnd authored Jun 30, 2023
2 parents b9d1388 + 930512d commit 8947d30
Show file tree
Hide file tree
Showing 5 changed files with 10 additions and 13 deletions.
15 changes: 4 additions & 11 deletions controls/srg_ctr/SRG-APP-000148-CTR-000335.yml
Original file line number Diff line number Diff line change
Expand Up @@ -3,18 +3,11 @@ controls:
levels:
- medium
title: {{{ full_name }}} must uniquely identify and authenticate users.
rules:
- sshd_disable_root_login
related_rules:
- idp_is_configured
- ocp_idp_no_htpasswd
- kubeadmin_removed
status: inherently met
status_justification: |-
Users of the OpenShift Platform must be uniquely identified and
authenticated in order to access the platform's console. Anonymous
users are prohibited, and authorization is enforced by the platform's
RBAC policies. Refer to
https://docs.openshift.com/container-platform/latest/authentication/index.html
for more information.
artifact_description: |-
Supporting evidence is in the following documentation
https://docs.openshift.com/container-platform/latest/authentication/index.html
status: automated

1 change: 1 addition & 0 deletions controls/srg_ctr/SRG-APP-000190-CTR-000500.yml
Original file line number Diff line number Diff line change
Expand Up @@ -8,4 +8,5 @@ controls:
of inactivity;'
status: automated
rules:
- sshd_disable_root_login
- oauthclient_inactivity_timeout
Original file line number Diff line number Diff line change
Expand Up @@ -19,6 +19,7 @@ rationale: |-
severity: medium

identifiers:
cce@rhcos4: CCE-89550-8
cce@rhel7: CCE-27445-6
cce@rhel8: CCE-80901-2
cce@rhel9: CCE-90800-4
Expand Down Expand Up @@ -51,7 +52,7 @@ references:
ospp: FAU_GEN.1
pcidss: Req-2.2.4
pcidss4: "2.2.6"
srg: SRG-OS-000109-GPOS-00056,SRG-OS-000480-GPOS-00227
srg: SRG-OS-000109-GPOS-00056,SRG-OS-000480-GPOS-00227,SRG-APP-000148-CTR-000335,SRG-APP-000190-CTR-000500
stigid@ol7: OL07-00-040370
stigid@ol8: OL08-00-010550
stigid@rhel7: RHEL-07-040370
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
---
default_result: FAIL
result_after_remediation: PASS
1 change: 0 additions & 1 deletion shared/references/cce-redhat-avail.txt
Original file line number Diff line number Diff line change
Expand Up @@ -2860,7 +2860,6 @@ CCE-89546-6
CCE-89547-4
CCE-89548-2
CCE-89549-0
CCE-89550-8
CCE-89551-6
CCE-89552-4
CCE-89553-2
Expand Down

0 comments on commit 8947d30

Please sign in to comment.