Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Linux disk encryption :: Update standard-query-library.yml #22498

Merged
merged 1 commit into from
Oct 2, 2024

Conversation

mikermcneil
Copy link
Member

Credit: @jbilling

@mikermcneil
Copy link
Member Author

TODO: needs some testing

@spokanemac @nonpunctual anything we could test this one out on in the realm of eating our own dogfood?

@spokanemac
Copy link
Contributor

@spokanemac @nonpunctual anything we could test this one out on in the realm of eating our own dogfood?

@mikermcneil Issue created to dogfood after MacSysAdmin Conference.

@mikermcneil
Copy link
Member Author

JD: Issue created to dogfood after MacSysAdmin Conference.

@lukeheath @spokanemac Who should cover this so we can get the PR merged or changed quickly?

@rachaelshaw
Copy link
Member

rachaelshaw commented Sep 30, 2024

@mikermcneil @lukeheath @spokanemac I made a PR to the GitOps folder to test out the change: #22516
(Will leave it to you to verify it's working as expected.)

lukeheath pushed a commit that referenced this pull request Oct 1, 2024
@lukeheath
Copy link
Member

lukeheath commented Oct 1, 2024

@zayhanlon Can anyone on CS help us test this out while JD and Brock are traveling? I merged Rachael's PR so it's in dogfood for testing.

@zayhanlon
Copy link
Contributor

@ddribeiro can you take this one tomorrow?

@ddribeiro
Copy link
Member

I was able to get an Ubuntu VM set up with disk encryption enabled. I ran the updated query as a policy on my host and it passed.

Screenshot 2024-10-02 at 3 25 29 PM

My Ubuntu VM without disk encryption enabled failed the policy.

Screenshot 2024-10-02 at 3 28 06 PM

cc: @mikermcneil @lukeheath @zayhanlon

@lukeheath
Copy link
Member

@rachaelshaw @noahtalerman Since this is a doc change I'll wait for y'all or Mike to merge, but this has cleared QA thanks to @ddribeiro.

@rachaelshaw rachaelshaw merged commit 4de7eb9 into main Oct 2, 2024
5 checks passed
@rachaelshaw rachaelshaw deleted the mikermcneil-patch-22 branch October 2, 2024 21:20
@noahtalerman
Copy link
Member

noahtalerman commented Oct 3, 2024

Nice!

FYI looks like this new query is the one Fleet uses for the disk encryption host vital on Linux: https://github.com/fleetdm/fleet/blob/main/docs/Contributing/Understanding-host-vitals.md#disk_encryption_linux

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

Successfully merging this pull request may close these issues.

7 participants