-
Notifications
You must be signed in to change notification settings - Fork 717
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Rule service_rpcbind_disabled is failing after CIS workstation L2 kickstart installation #10901
Comments
I don't remember where, but I think this was already discussed in the past. Maybe it is related to a dependency relationship with another package or service? |
@marcusburghardt you are probably right: #10143 might be good to read. |
Maybe it was "not applicable" during the installation phase. Then fails right after the install. I wonder if it would be properly fixed if a second round of scan / remediation happens after reboot. |
For some reason, the This rule replaced the However, regardless of the fix I will propose, the rule seems to be working as expected:
It seems another case of rule dependencies which can be solved with a second round of scan/remediation, like reported in this issue: OpenSCAP/openscap#1880 @mildas and @vojtapolasek , could you confirm this case, please? |
Still present in last productization review. |
I can confirm that the problem can be solved by one more remediation after the installation. |
Great. So we can update the waivers and close this issue. I will work on this. Thanks for the confirmation @vojtapolasek |
It manifested also during the latest stabilization with kickstart installation of cis_ws_l1 and cis_ws_l2. |
RHSecurityCompliance/contest#55 was merged yesterday. It should be good for the next round of tests. |
Description of problem:
After you perform an installation of RHEL 8 with kickstart for CIS workstation level 2, the rule service_rpcbind_disabled fails during the oscap scan.
SCAP Security Guide Version:
stabilization-v0.1.69 branch as of 2023-07-20
Operating System Version:
RHEL 8
Steps to Reproduce:
Actual Results:
rule service_rpcbind_disabled is reported as "fail"
Expected Results:
rule service_rpcbind_disabled is reported as "pass"
Additional Information/Debugging Steps:
The text was updated successfully, but these errors were encountered: