Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Rule file_permissions_etc_audit_rulesd fails after remediation #12766

Open
jan-cerny opened this issue Jan 2, 2025 · 0 comments · May be fixed by #12786
Open

Rule file_permissions_etc_audit_rulesd fails after remediation #12766

jan-cerny opened this issue Jan 2, 2025 · 0 comments · May be fixed by #12786
Assignees
Labels
productization-issue Issue found in upstream stabilization process. RHEL8 Red Hat Enterprise Linux 8 product related. RHEL9 Red Hat Enterprise Linux 9 product related. RHEL10 Red Hat Enterprise Linux 10 product related.
Milestone

Comments

@jan-cerny
Copy link
Collaborator

Description of problem:

During daily productization review today we have discovered that rule file_permissions_etc_audit_rulesd fails after remediation.
It fails in these tests:

  • /hardening/image-builder/stig
  • /scanning/disa-alignment/anaconda
  • /hardening/anaconda/stig (except RHEL 10)
  • /hardening/anaconda/with-gui/stig_gui (except RHEL 10)
  • /hardening/kickstart/stig (only on RHEL 10)
  • /hardening/kickstart/with-gui/stig_gui (only on RHEL 10)

Also, the rule is reported as misaligned with DISA with this note: SSG result: fail, DISA result: pass.

SCAP Security Guide Version:

Current upstream master branch as of 2024-02-01 as of HEAD 8cb84dc.

Operating System Version:

8 RHEL-8.10.0-updates-20241228.1
9 RHEL-9.6.0-20241231.2
10 RHEL-10.0-20241220.0

Steps to Reproduce:

no

Actual Results:

Files /etc/audit/rules.d/delete.rules and /etc/audit/rules.d/modules.rules have permissions 0640 but the expected permissions are 0600.

Expected Results:

rule passes and aforementioned tests pass

Additional Information/Debugging Steps:

Investigate if it's related to recent PR #12737.

@jan-cerny jan-cerny added productization-issue Issue found in upstream stabilization process. RHEL9 Red Hat Enterprise Linux 9 product related. RHEL8 Red Hat Enterprise Linux 8 product related. RHEL10 Red Hat Enterprise Linux 10 product related. labels Jan 2, 2025
@Mab879 Mab879 self-assigned this Jan 7, 2025
@Mab879 Mab879 added this to the 0.1.76 milestone Jan 7, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
productization-issue Issue found in upstream stabilization process. RHEL8 Red Hat Enterprise Linux 8 product related. RHEL9 Red Hat Enterprise Linux 9 product related. RHEL10 Red Hat Enterprise Linux 10 product related.
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants