Skip to content

Add rules to Ubuntu 22.04 STIG to align with V2R7#14427

Merged
dodys merged 1 commit intoComplianceAsCode:masterfrom
mpurg:ubuntu_stig_654224_254030_211000
Feb 20, 2026
Merged

Add rules to Ubuntu 22.04 STIG to align with V2R7#14427
dodys merged 1 commit intoComplianceAsCode:masterfrom
mpurg:ubuntu_stig_654224_254030_211000

Conversation

@mpurg
Copy link
Copy Markdown
Contributor

@mpurg mpurg commented Feb 19, 2026

Description:

Add these rules to Ubuntu 22.04 STIG control file:

  • UBTU-22-211000: Ubuntu 22.04 LTS must be a vendor-supported release.
  • UBTU-22-254010: Ubuntu 22.04 LTS must have the "SSSD" package installed.
  • UBTU-22-254015: Ubuntu 22.04 LTS must use the "SSSD" package for multifactor authentication services.
  • UBTU-22-254020: Ubuntu 22.04 LTS must ensure SSSD performs certificate path validation, including revocation checking, against a trusted anchor for PKI-based authentication.
  • UBTU-22-254030: Ubuntu 22.04 LTS must map the authenticated identity to the user or group account for PKI-based authentication.
  • UBTU-22-654224: The operating system must restrict privilege elevation to authorized personnel.

Rationale:

Aligns with STIG V2R7

- UBTU-22-211000: Ubuntu 22.04 LTS must be a vendor-supported release.
- UBTU-22-254010: Ubuntu 22.04 LTS must have the "SSSD" package installed.
- UBTU-22-254015: Ubuntu 22.04 LTS must use the "SSSD" package for multifactor authentication services.
- UBTU-22-254020: Ubuntu 22.04 LTS must ensure SSSD performs certificate path validation, including revocation checking, against a trusted anchor for PKI-based authentication.
- UBTU-22-254030: Ubuntu 22.04 LTS must map the authenticated identity to the user or group account for PKI-based authentication.
- UBTU-22-654224: The operating system must restrict privilege elevation to authorized personnel.
@mpurg mpurg requested a review from dodys February 19, 2026 10:26
@mpurg mpurg added the Ubuntu Ubuntu product related. label Feb 19, 2026
@github-actions
Copy link
Copy Markdown

This datastream diff is auto generated by the check Compare DS/Generate Diff

Click here to see the full diff
OVAL for rule 'xccdf_org.ssgproject.content_rule_installed_OS_is_vendor_supported' differs.
--- oval:ssg-installed_OS_is_vendor_supported:def:1
+++ oval:ssg-installed_OS_is_vendor_supported:def:1
@@ -11,4 +11,5 @@
 extend_definition oval:ssg-installed_OS_is_sle16:def:1
 extend_definition oval:ssg-installed_OS_is_slmicro5:def:1
 extend_definition oval:ssg-installed_OS_is_slmicro6:def:1
+extend_definition oval:ssg-installed_OS_is_ubuntu2204:def:1
 extend_definition oval:ssg-installed_OS_is_ubuntu2404:def:1

@mpurg mpurg added the STIG STIG Benchmark related. label Feb 19, 2026
@mpurg mpurg added this to the 0.1.81 milestone Feb 19, 2026
Copy link
Copy Markdown
Contributor

@dodys dodys left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm, thanks!

@dodys dodys self-assigned this Feb 20, 2026
@dodys dodys merged commit 98c01c2 into ComplianceAsCode:master Feb 20, 2026
61 of 64 checks passed
hdean3 added a commit to hdean3/content that referenced this pull request Feb 26, 2026
All V2R7 control PRs (ComplianceAsCode#14427, ComplianceAsCode#14418, ComplianceAsCode#14415, ComplianceAsCode#14416, ComplianceAsCode#14433) were
merged without updating the version metadata fields. This causes STIG
Viewer imports and auditor reports to display V2R3 while the actual
content reflects V2R7 rules.

Updated files:
- controls/stig_ubuntu2204.yml: version V2R3 → V2R7
- products/ubuntu2204/profiles/stig.profile: version, title, and
  description strings V2R3 → V2R7
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

STIG STIG Benchmark related. Ubuntu Ubuntu product related.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants