Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Sync rules that contain a stig ID to those in stig profiles for ol products #10632

Merged
merged 2 commits into from
May 25, 2023
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -31,7 +31,6 @@ references:
nist: CM-6(a)
nist@sle12: AU-5(a),AU-5.1(ii)
srg: SRG-OS-000046-GPOS-00022
stigid@ol8: OL08-00-030030
stigid@sle12: SLES-12-020050
stigid@sle15: SLES-15-030580

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -57,7 +57,6 @@ references:
pcidss: Req-8.1.8
pcidss4: "8.2.8"
srg: SRG-OS-000163-GPOS-00072,SRG-OS-000279-GPOS-00109
stigid@ol7: OL07-00-040340
stigid@rhel8: RHEL-08-010200
stigid@sle12: SLES-12-030191
stigid@ubuntu2004: UBTU-20-010036
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -40,7 +40,6 @@ references:
anssi: BP28(R32)
disa: CCI-000196
srg: SRG-OS-000073-GPOS-00041
stigid@ol8: OL08-00-010130

ocil_clause: 'rounds is not set to {{{ xccdf_value("var_password_pam_unix_rounds") }}} or is commented out'

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -34,7 +34,6 @@ references:
anssi: BP28(R32)
disa: CCI-000196
srg: SRG-OS-000073-GPOS-00041
stigid@ol8: OL08-00-010130

ocil_clause: 'rounds is not set to {{{ xccdf_value("var_password_pam_unix_rounds") }}} or is commented out'

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -29,7 +29,6 @@ identifiers:
references:
disa: CCI-000366
srg: SRG-OS-000480-GPOS-00227
stigid@ol7: OL07-00-020600
stigid@ol8: OL08-00-010720
stigid@rhel7: RHEL-07-020600
stigid@rhel8: RHEL-08-010720
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -54,7 +54,6 @@ references:
pcidss: Req-10.7
pcidss4: "10.5.1"
srg: SRG-OS-000343-GPOS-00134
stigid@ol7: OL07-00-030340

ocil_clause: 'there is no evidence that real-time alerts are configured on the system'

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -59,7 +59,6 @@ references:
pcidss: Req-10.7
pcidss4: "10.5.1"
srg: SRG-OS-000047-GPOS-00023
stigid@ol8: OL08-00-030050

ocil_clause: 'the value of the "max_log_file_action" option is set to "ignore", "rotate", or "suspend", or the line is commented out'

Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
documentation_complete: true

prodtype: alinux2,ol9,rhel8,rhel9
prodtype: alinux2,ol8,ol9,rhel8,rhel9

title: 'Firewalld Must Employ a Deny-all, Allow-by-exception Policy for Allowing Connections to Other Systems'

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,7 @@ references:
disa: CCI-000381
nist: CM-7 (a),CM-7 (5) (b)
srg: SRG-OS-000095-GPOS-00049,SRG-OS-000370-GPOS-00155
stigid@l8: OL08-00-040020
stigid@ol8: OL08-00-040020
stigid@rhel8: RHEL-08-040020

platform: machine
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -28,7 +28,6 @@ references:
nist: CM-6(a),SC-28,SI-3(a)
nist-csf: DE.CM-4,DE.DP-3,PR.DS-1
srg: SRG-OS-000480-GPOS-00227
stigid@ol7: OL07-00-032000
stigid@rhel7: RHEL-07-032000

ocil_clause: 'virus scanning software is not installed or running'
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,6 @@ identifiers:
references:
disa: CCI-000381
srg: SRG-OS-000095-GPOS-00049
stigid@ol8: OL08-00-040001
stigid@rhel8: RHEL-08-040001

{{{ complete_ocil_entry_package(package="libreport-plugin-rhtsupport") }}}
Expand Down
2 changes: 1 addition & 1 deletion products/ol7/profiles/stig.profile
Original file line number Diff line number Diff line change
Expand Up @@ -334,7 +334,7 @@ selections:
- auditd_audispd_remote_daemon_type
- account_temp_expire_date
- package_screen_installed
- sysctl_kernel_dmesg_restric
- sysctl_kernel_dmesg_restrict
- authconfig_config_files_symlinks
- ensure_oracle_gpgkey_installed
- dconf_gnome_disable_user_list
Expand Down
2 changes: 1 addition & 1 deletion products/ol8/profiles/stig.profile
Original file line number Diff line number Diff line change
Expand Up @@ -126,7 +126,6 @@ selections:

# OL08-00-010130
- set_password_hashing_min_rounds_logindefs
- accounts_password_pam_unix_rounds_system_auth

# OL08-00-010140
- grub2_uefi_password
Expand Down Expand Up @@ -965,6 +964,7 @@ selections:
- package_abrt_removed
- package_abrt-libs_removed
- package_abrt-server-info-page_removed
- package_libreport-plugin-logger_removed

# OL08-00-040002
- package_sendmail_removed
Expand Down