Skip to content

Conversation

@iankko
Copy link

@iankko iankko commented Jun 11, 2015

This patchset is doing the following:

  • patch 276d4b9 updates the RHEL/7 and Fedora XCCDF prose for display_login_attempts rule it to recommend proper pam_lastlog.so module setting (it has been verified with Tomas Mraz, PAM package maintainer that on RHEL-7 and Fedora systems the proper pam_lastlog.so PAM module setting should happen in /etc/pam.d/postlogin configuration file, and not, like currently recommended in /etc/pam.d/system-auth file. The /etc/pam.d/system-auth recommendation is still correct for the case of RHEL/6 system though, therefore the corresponding RHEL/6 XCCDF object for this rule hasn't been modified),

This change fixes pam_lastlog.so issue (leading to invalid PAM configuration) as reported in:
    [1] https://lists.fedorahosted.org/pipermail/scap-security-guide/2015-June/006449.html

  • patch 28c5758 adds /shared version of OVAL checks for RHEL/7 and Fedora products for this rule (display_login_attempts). Also switches using of that rule on for Fedora's common profile and RHEL-7's PCI-DSS profile.

Testing report:

The proposed OVAL check has been manually tested on both products (RHEL-7 && Fedora 20), and seems to be working fine (AFAICT), therefore also added test_attestations for these two systems.

Please review.

Thank you, Jan.

Jan Lieskovsky added 2 commits June 11, 2015 12:18
…mpts"

rule for RHEL-7 and Fedora products to provide correct recommendation wrt
to pam_lastlog settings on these products

Fixes issue reported in:
  https://lists.fedorahosted.org/pipermail/scap-security-guide/2015-June/006449.html
…_attempts'

OVAL check for RHEL-7 and Fedora products

Testing report:
---------------
Verified manually on both products the proposed OVAL works fine
(=> added test attestations for RHEL-7 && Fedora 20)
@iankko iankko added bugfix Fixes to reported bugs. enhancement General enhancements to the project. Fedora Fedora product related. RHEL Red Hat Enterprise Linux product related. labels Jun 11, 2015
@iankko iankko added this to the 0.1.23 milestone Jun 11, 2015
@landscape-bot
Copy link

Code Health
Code quality remained the same when pulling 28c5758 on iankko:rhel7_fedora_display_login_attempts_fix into d20ee32 on OpenSCAP:master.

@mpreisler mpreisler self-assigned this Jun 11, 2015
@mpreisler
Copy link
Member

Builds successfully on RHEL6, tested the result on Fedora 22 and it seems to work.

ACK.

mpreisler added a commit that referenced this pull request Jun 11, 2015
…ts_fix

[BugFix] [Enhancement] Fix 'display_login_attempts' rule for RHEL-7 and Fedora
@mpreisler mpreisler merged commit c74bfad into ComplianceAsCode:master Jun 11, 2015
@iankko iankko deleted the rhel7_fedora_display_login_attempts_fix branch June 12, 2015 07:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bugfix Fixes to reported bugs. enhancement General enhancements to the project. Fedora Fedora product related. RHEL Red Hat Enterprise Linux product related.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants