Back to bug 2176008

Who When What Removed Added
Red Hat Bugzilla 2023-03-07 06:57:24 UTC Pool ID sst_security_compliance_rhel_8
Red Hat One Jira (issues.redhat.com) 2023-03-07 07:04:00 UTC Link ID Red Hat Issue Tracker RHELPLAN-150883
Vojtech Polasek 2023-03-09 08:54:10 UTC Keywords Triaged
Ravindra Patil 2023-05-06 17:12:34 UTC CC ravpatil
Jan Černý 2023-05-09 12:29:33 UTC CC jcerny
Peter Vreman 2023-07-04 08:42:50 UTC CC peter.vreman
Jan Černý 2023-07-04 10:52:01 UTC Status NEW POST
Vojtech Polasek 2023-07-11 11:45:21 UTC Doc Type If docs needed, set a value Bug Fix
Doc Text Cause:
Following SCAP rules relevant to /var/log and /var/log/audit partitions were evaluated / remediated without first checking if the appropriate disk partition exists:
- mount_option_var_log_audit_nodev
- mount_option_var_log_audit_noexec
- mount_option_var_log_audit_nosuid
- mount_option_var_log_nodev
- mount_option_var_log_noexec
- mount_option_var_log_nosuid


Consequence:
Although directories /var/log or /var/log/audit were not mount points for individual partitions, rules were still evaluated and they were reported as failing in the final report. But they should not be evaluated at all.


Fix:
An applicability check was added so that if /var/log or /var/log/audit are not mount points for individual partitions, rules are not evaluated.

Result:
Rules are marked as "not applicable" in the final report.
Jiri Jaburek 2023-08-02 12:17:42 UTC CC jjaburek
RHEL Program Management Team 2023-08-02 12:25:43 UTC Blocks 2228473
RHEL Program Management Team 2023-08-02 12:25:55 UTC Blocks 2228474
RHEL Program Management Team 2023-08-02 12:26:02 UTC Keywords ZStream
Jan Černý 2023-08-10 11:42:44 UTC Link ID Github ComplianceAsCode/content/pull/10295
Matěj Týč 2023-08-10 14:35:00 UTC Fixed In Version scap-security-guide-0.1.69-1.el8
CC matyc
Status POST MODIFIED
AutoMiloš 2023-08-10 15:36:49 UTC Keywords AutoVerified

Back to bug 2176008