-
Notifications
You must be signed in to change notification settings - Fork 706
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
OL7 stig v2r10 update #10125
OL7 stig v2r10 update #10125
Conversation
Bump version on both stig and stig_gui OL7 profiles to v2r10 Update the XCCDF manual reference Add rule package_screen_installed to OL7 stig profile Signed-off-by: Federico Ramirez <federico.r.ramirez@oracle.com>
Signed-off-by: Federico Ramirez <federico.r.ramirez@oracle.com>
Select the printk (1) value for the var_audit_failure_mode var for OL7. Using the panic (2) value results in the system being shut down when there is an audit failure. This meassure is too harsh and will impact the system's availability. Signed-off-by: Federico Ramirez <federico.r.ramirez@oracle.com>
Signed-off-by: Federico Ramirez <federico.r.ramirez@oracle.com>
Makes the rule sshd_disable_compression not applicable for OL 7.4 and newer. This makes the rule in sync with OL7 DISA STIG v2r10 requirement OL07-00-040470 Signed-off-by: Federico Ramirez <federico.r.ramirez@oracle.com>
Code Climate has analyzed commit af36153 and detected 0 issues on this pull request. The test coverage on the diff in this pull request is 100.0% (50% is the threshold). This pull request will bring the total coverage in the repository to 49.7%. View more on Code Climate. |
/packit retest-failed |
/retest |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks for the PR!
I am overriding the CODEOWNERS file as @freddieRv can not merge this PR. |
Description:
sysctl_kernel_dmesg_restric
andpackage_screen_installed
to OL7 sitg profilepanic
toprintk
ol7_older_than_7_4
applicability CPE and added it to thesshd_disable_compression
ruleRationale: