-
Notifications
You must be signed in to change notification settings - Fork 710
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
kdump
is not disabled via Kickstart remediations on RHEL-10
#12832
Comments
OpenSCAP should be able to generate this section to the generated kickstart when a rule has a kickstart type remediation with the following contents:
|
Well, seeing how these tests failed:
it seems that |
Yes, it doesn't use it |
This change will cause that the kickstart file generated by OpenSCAP will contain `%addon com_redhat_kdump --disable` section. Fixes: ComplianceAsCode#12832
This change will cause that the kickstart file generated by OpenSCAP will contain `%addon com_redhat_kdump --disable` section. Fixes: ComplianceAsCode#12832
This change will cause that the kickstart file generated by OpenSCAP will contain `%addon com_redhat_kdump --disable` section. Fixes: ComplianceAsCode#12832
This change will cause that the kickstart file generated by OpenSCAP will contain `%addon com_redhat_kdump --disable` section. Fixes: ComplianceAsCode#12832
I have created PR #12856 where I will add the |
The PR #12856 has been merged, but the rule still fails - see the description there. |
So what are the next steps if this is Is there an Anaconda installer issue filed to change the behavior of the Or do we "fix" it on the content side by checking service start failure and treating it as valid for "service disabled"? |
Description of problem:
According to oscap HTML report,
kdump.service
hasActiveState
asfailed
, not asdisabled
(?).This is possibly because RHEL-10 Anaconda forcibly activates kdump even if the (oscap-generated) kickstart has
Maybe it can be fixed in content, maybe adding
would fix it (in OpenSCAP code?).
This
%addon
syntax is compatible with older RHELs too, and should arguably be present in those kickstarts as well.There was a similar issue in the past with Anaconda: rhinstaller/kdump-anaconda-addon@06ad891 , so this may also be an Anaconda bug - we should probably contact their devel team to figure out a solution.
SCAP Security Guide Version:
master @ 60a184a
Operating System Version:
RHEL-10
Steps to Reproduce:
custom
productization ashipaa
,stig
andstig_gui
)Additional Information/Debugging Steps:
The text was updated successfully, but these errors were encountered: