Skip to content

Improve pam_options SLE16 -related behaviour#14716

Open
teacup-on-rockingchair wants to merge 3 commits into
ComplianceAsCode:masterfrom
teacup-on-rockingchair:sle16_pam_options_enhance_patch
Open

Improve pam_options SLE16 -related behaviour#14716
teacup-on-rockingchair wants to merge 3 commits into
ComplianceAsCode:masterfrom
teacup-on-rockingchair:sle16_pam_options_enhance_patch

Conversation

@teacup-on-rockingchair
Copy link
Copy Markdown
Contributor

Description:

  • Improve pam_options related rules behaviour for SLE16. Make sure distro default configuration files from /usr/etc are not used in hardening for anything else but for source of generating default configuration in /etc from remediation scripts. Anything in /usr/etc will be changed or wiped out on upgrade so we should not rely on it for hardening

Rationale:

  • Remove the special case for sle16 in OVAL, if file is missing test will FAIL
  • Add preserve option when copy distro defaults to /etc for bash and ansible
  • Fix tests for use_pam_wheel_group_for_su and set_password_hashing_algorithm_commonauth
  • Add test for accounts_password_pam_pwhistory_remember

- remove the special case for sle16 in OVAL, if file is missing test will FAIL
- Fix tests for use_pam_wheel_group_for_su and set_password_hashing_algorithm_commonauth
- Add test for accounts_password_pam_pwhistory_remember
@openshift-ci openshift-ci Bot added the do-not-merge/work-in-progress Used by openshift-ci bot. label May 17, 2026
@openshift-ci
Copy link
Copy Markdown

openshift-ci Bot commented May 17, 2026

Skipping CI for Draft Pull Request.
If you want CI signal for your change, please convert it to an actual PR.
You can still manually trigger a test run with /test all

@teacup-on-rockingchair teacup-on-rockingchair added this to the 0.1.81 milestone May 17, 2026
@teacup-on-rockingchair teacup-on-rockingchair added SLES SUSE Linux Enterprise Server product related. Update Template Issues or pull requests related to Templates updates. labels May 17, 2026
@teacup-on-rockingchair teacup-on-rockingchair marked this pull request as ready for review May 17, 2026 13:18
@openshift-ci openshift-ci Bot removed the do-not-merge/work-in-progress Used by openshift-ci bot. label May 17, 2026
@openshift-ci
Copy link
Copy Markdown

openshift-ci Bot commented May 17, 2026

@teacup-on-rockingchair: The following tests failed, say /retest to rerun all failed tests or /retest-required to rerun all mandatory failed tests:

Test name Commit Details Required Rerun command
ci/prow/4.19-images 250b05f link true /test 4.19-images
ci/prow/e2e-aws-openshift-platform-compliance 250b05f link true /test e2e-aws-openshift-platform-compliance

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

SLES SUSE Linux Enterprise Server product related. Update Template Issues or pull requests related to Templates updates.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant