Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

file_permission_user_init_files_root is misaligned with DISA #13033

Open
4 tasks
jan-cerny opened this issue Feb 12, 2025 · 0 comments
Open
4 tasks

file_permission_user_init_files_root is misaligned with DISA #13033

jan-cerny opened this issue Feb 12, 2025 · 0 comments
Labels
productization-issue Issue found in upstream stabilization process. RHEL8 Red Hat Enterprise Linux 8 product related. STIG STIG Benchmark related. triaged

Comments

@jan-cerny
Copy link
Collaborator

Description of problem:

On 2025-02-12, the daily productization run shows the following fails on RHEL 8.10:

  • /scanning/disa-alignment/ansible/file_permission_user_init_files_root
  • /scanning/disa-alignment/oscap/file_permission_user_init_files_root

The content is misaligned with an external (third party) content that targets the same policy - typically, this means that a system hardened by our content doesn't pass the scan by the external content.

Details:

Our rule file_permission_user_init_files_root passed
Their rule SV-230325r1017136_rule failed because it didn't file any file in / matching ^\.[^\s\.]+.

There was a ticket about this rule but for RHEL 9, but the ticket is now closed: #11778

Outcome:

  • This project's content can be improved:
    • Check needs to be improved.
    • Remediation needs to be improved.
  • The external content's check is faulty - the other party needs to be notified, they have work to do.

SCAP Security Guide Version:

current upstream master as of 2025-02-12 as of HEAD 0f151a1

External Content's Version:

V2R2

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
productization-issue Issue found in upstream stabilization process. RHEL8 Red Hat Enterprise Linux 8 product related. STIG STIG Benchmark related. triaged
Projects
None yet
Development

No branches or pull requests

2 participants