Skip to content

Comments

Add remaining STIG XCCDF content for RHEL6 and RHEL7#2439

Merged
shawndwells merged 4 commits intoComplianceAsCode:masterfrom
redhatrises:add_remaining_xccdf
Oct 30, 2017
Merged

Add remaining STIG XCCDF content for RHEL6 and RHEL7#2439
shawndwells merged 4 commits intoComplianceAsCode:masterfrom
redhatrises:add_remaining_xccdf

Conversation

@redhatrises
Copy link
Contributor

Description:

  • Add remaining lastest STIG XCCDF content for RHEL6 and RHEL7

Rationale:

  • Moving forward the remaining STIG content for both OS versions.

@redhatrises redhatrises added bugfix Fixes to reported bugs. enhancement General enhancements to the project. RHEL6 RHEL Red Hat Enterprise Linux product related. labels Oct 26, 2017
@redhatrises redhatrises added this to the 0.1.36 milestone Oct 26, 2017
be forwarded to at least one monitored email address.
</rationale>
<ident cce="80508-5"/>
<oval id="postfix_client_configure_mail_alias" value="var_postfix_root_mail_alias" />
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Wouldn't this check fail unless root aliases are set to system.administrator@mail.mil?

Copy link
Member

@shawndwells shawndwells Oct 30, 2017

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Because postfix_client_configure_mail_alias doesn't have OVAL yet, should this line be removed? Would rather have notchecked and not have to think there is unlinked OVAL lurking around

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Shouldn't:
WARNING: OVAL check 'postfix_client_configure_mail_alias' was not found, removing <check-content> element from the XCCDF rule.

<ref nist="AC-2" disa="178" />
</Rule>

<Rule id="no_password_auth_for_systemaccounts" severity="medium">
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why is this a medium severity? Shouldn't it be low, given there are no logins permitted to system accounts in the first place?

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Edit: Nevermind. I see this is just to fall in line with DISA

run the following command:
<pre>$ sudo grep "set root='hd0" /boot/grub2/grub.cfg</pre>
The output should return something similar to:
<pre>set root='hd0,msdos1'</pre>
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Should we give examples of removable media?

set root='hd0,msdos1,cdrom' is similar to the example output

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@shawndwells added this:

<tt>usb0</tt>, <tt>cd</tt>, <tt>fd0</tt>, etc. are some examples of removeable
media which should not exist in the line:
<pre>set root='hd0,msdos1'</pre>

run the following command:
<pre>$ sudo grep "set root='hd0" /boot/efi/EFI/redhat/grub.cfg</pre>
The output should return something similar to:
<pre>set root='hd0,msdos1'</pre>
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Example of what a removable media entry would be?

Copy link
Contributor Author

@redhatrises redhatrises Oct 30, 2017

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@shawndwells added this:

<tt>usb0</tt>, <tt>cd</tt>, <tt>fd0</tt>, etc. are some examples of removeable
media which should not exist in the line:
<pre>set root='hd0,msdos1'</pre>

@shawndwells shawndwells self-assigned this Oct 30, 2017
@shawndwells shawndwells merged commit 49640c1 into ComplianceAsCode:master Oct 30, 2017
@redhatrises
Copy link
Contributor Author

Thanks @shawndwells

@redhatrises redhatrises deleted the add_remaining_xccdf branch October 30, 2017 19:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bugfix Fixes to reported bugs. enhancement General enhancements to the project. RHEL Red Hat Enterprise Linux product related.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants