Back to bug 2210276

Who When What Removed Added
Red Hat Bugzilla 2023-05-26 12:19:24 UTC Pool ID sst_security_compliance_rhel_7
Red Hat One Jira (issues.redhat.com) 2023-05-26 12:22:10 UTC Link ID Red Hat Issue Tracker RHELPLAN-158292
Vojtech Polasek 2023-05-29 11:53:46 UTC Keywords Triaged
Marcus Burghardt 2023-07-12 05:14:24 UTC Status NEW ASSIGNED
Assignee vpolasek maburgha
CC maburgha
Marcus Burghardt 2023-07-13 06:25:02 UTC Status ASSIGNED POST
Jan Černý 2023-07-17 07:46:21 UTC CC jcerny
Doc Type If docs needed, set a value Bug Fix
Doc Text .Applicability changes of rules related to IPv6 configuration

Compliance rules that are related to IPv6 configuration will now return "notapplicable" result when IPv6 is disabled on the target system. The applicability will be determined based on presence of `ipv6.disable` in the `GRUB_CMDLINE_LINUX` value in the `/etc/default/grub` configuration file. If this option is not present there or set to 0, the rules will be considered applicable and will be evaluated.

The following rules are affected by this change:
- disabling_ipv6_autoconfig
- network_ipv6_default_gateway
- network_ipv6_privacy_extensions
- network_ipv6_static_address
- sysctl_net_ipv6_conf_all_accept_ra
- sysctl_net_ipv6_conf_all_accept_ra_defrtr
- sysctl_net_ipv6_conf_all_accept_ra_pinfo
- sysctl_net_ipv6_conf_all_accept_ra_rtr_pref
- sysctl_net_ipv6_conf_all_accept_redirects
- sysctl_net_ipv6_conf_all_accept_source_route
- sysctl_net_ipv6_conf_all_autoconf
- sysctl_net_ipv6_conf_all_forwarding
- sysctl_net_ipv6_conf_all_max_addresses
- sysctl_net_ipv6_conf_all_router_solicitations
- sysctl_net_ipv6_conf_default_accept_ra
- sysctl_net_ipv6_conf_default_accept_ra_defrtr
- sysctl_net_ipv6_conf_default_accept_ra_pinfo
- sysctl_net_ipv6_conf_default_accept_ra_rtr_pref
- sysctl_net_ipv6_conf_default_accept_redirects
- sysctl_net_ipv6_conf_default_accept_source_route
- sysctl_net_ipv6_conf_default_autoconf
- sysctl_net_ipv6_conf_default_forwarding
- sysctl_net_ipv6_conf_default_max_addresses
- sysctl_net_ipv6_conf_default_router_solicitations
Vojtech Polasek 2023-07-24 12:14:38 UTC CC vpolasek
Jiri Jaburek 2023-07-28 13:29:10 UTC Flags needinfo?(maburgha)
CC jjaburek
Jan Černý 2023-07-28 14:06:40 UTC Flags needinfo?(maburgha)
Jan Černý 2023-08-07 07:25:45 UTC Fixed In Version scap-security-guide-0.1.69-1.el7_9
Jan Černý 2023-08-07 07:29:08 UTC Status POST MODIFIED
errata-xmlrpc 2023-08-07 07:30:01 UTC Status MODIFIED ON_QA
Milan Lysonek 2023-08-10 09:07:41 UTC Status ON_QA VERIFIED
QA Contact qe-baseos-security mlysonek

Back to bug 2210276