Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Change sshd_disable_compression applicability #10072

Merged

Conversation

jan-cerny
Copy link
Collaborator

Description:

Makes the rule sshd_disable_compression not applicable for RHEL 7.4 and newer.

Rationale:

RHEL 7 STIG v3r10 says in STIG ID RHEL-07-040470 that "for RHEL 7.4 and above, this requirement is not applicable.".

@github-actions
Copy link

Start a new ephemeral environment with changes proposed in this pull request:

Fedora Environment
Open in Gitpod

Oracle Linux 8 Environment
Open in Gitpod

@jan-cerny
Copy link
Collaborator Author

Discussion/question: This applicability change is done for RHEL 7 STIG and will affect also other RHEL 7 profiles, eg. HIPAA, NCP, rhelh-stig, rhelh-vpp. Should we instead create a different rule just for STIG to not affect the other profiles?

@jan-cerny jan-cerny added STIG STIG Benchmark related. RHEL7 Red Hat Enterprise Linux 7 product related. labels Jan 17, 2023
@yuumasato yuumasato self-assigned this Jan 18, 2023
@yuumasato
Copy link
Member

Discussion/question: This applicability change is done for RHEL 7 STIG and will affect also other RHEL 7 profiles, eg. HIPAA, NCP, rhelh-stig, rhelh-vpp. Should we instead create a different rule just for STIG to not affect the other profiles?

I don't think we need a new rule.
The applicability is related to a behavior that changed in RHEL 7.4 and the profiles should be fine incorporating the new applicability.

@jan-cerny jan-cerny added this to the 0.1.66 milestone Jan 19, 2023
Makes the rule sshd_disable_compression not applicable
for RHEL 7.4 and newer.
RHEL 7 STIG v3r10 says in STIG ID RHEL-07-040470 that
"for RHEL 7.4 and above, this requirement is not applicable.".
@jan-cerny jan-cerny force-pushed the sshd_disable_compression branch from 31d2f73 to 070b12e Compare January 20, 2023 15:53
@codeclimate
Copy link

codeclimate bot commented Jan 20, 2023

Code Climate has analyzed commit 070b12e and detected 0 issues on this pull request.

The test coverage on the diff in this pull request is 100.0% (50% is the threshold).

This pull request will bring the total coverage in the repository to 49.7% (0.0% change).

View more on Code Climate.

@jan-cerny
Copy link
Collaborator Author

I have changed the data types in the applicability OVAL file.

@jan-cerny
Copy link
Collaborator Author

/retest

@openshift-ci
Copy link

openshift-ci bot commented Jan 23, 2023

@jan-cerny: The following tests failed, say /retest to rerun all failed tests or /retest-required to rerun all mandatory failed tests:

Test name Commit Details Required Rerun command
ci/prow/e2e-aws-ocp4-high 070b12e link true /test e2e-aws-ocp4-high
ci/prow/e2e-aws-rhcos4-moderate 070b12e link true /test e2e-aws-rhcos4-moderate

Full PR test history. Your PR dashboard.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. I understand the commands that are listed here.

@yuumasato yuumasato merged commit b5dceba into ComplianceAsCode:master Jan 23, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
RHEL7 Red Hat Enterprise Linux 7 product related. STIG STIG Benchmark related.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants