-
Notifications
You must be signed in to change notification settings - Fork 698
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Improve sshd_use_approved_kex_ordered_stig #11053
Improve sshd_use_approved_kex_ordered_stig #11053
Conversation
80f6fd7
to
ec3c38e
Compare
ec3c38e
to
c9c6c27
Compare
linux_os/guide/services/ssh/ssh_server/sshd_use_approved_kex_ordered_stig/oval/shared.xml
Outdated
Show resolved
Hide resolved
...e/services/ssh/ssh_server/sshd_use_approved_kex_ordered_stig/tests/correct_scrambled.fail.sh
Show resolved
Hide resolved
This commit will add UBTU-20-010045 for sshd_use_approved_kex_ordered_stig rule. Additionally, ubuntu2004 has been included in the tests
b6f67d1
to
12df498
Compare
Code Climate has analyzed commit 12df498 and detected 0 issues on this pull request. The test coverage on the diff in this pull request is 100.0% (50% is the threshold). This pull request will bring the total coverage in the repository to 53.8% (0.0% change). View more on Code Climate. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Changes LGTM.
Thanks for the efforts!
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I noticed the remediations are not enabled for RHEL 8 while the assessment is. I believe this is intentional but I will take a look to confirm. In any case this doesn't block the PR.
in rule.yml you have this entry:
|
Perfect. I overlooked this warning. Thanks |
fe26446
into
ComplianceAsCode:master
Description:
sshd_use_approved_kex_ordered_stig
. Its OVAL wasn't checking the value against anything and tests were passing for cases that should be failing.correct_scrambled.fail.sh
test.multi_platform_ubuntu
to testssshd_use_strong_kex
variable state commentRationale: