Back to bug 2228473

Who When What Removed Added
Red Hat Bugzilla 2023-08-02 12:25:43 UTC Pool ID sst_security_compliance_rhel_8
Red Hat One Jira (issues.redhat.com) 2023-08-02 12:27:00 UTC Link ID Red Hat Issue Tracker RHELPLAN-164143
Milan Lysonek 2023-08-02 13:29:34 UTC Doc Type If docs needed, set a value Bug Fix
Doc Text Cause:
Following SCAP rules relevant to /var/log and /var/log/audit partitions were evaluated / remediated without first checking if the appropriate disk partition exists:
- mount_option_var_log_audit_nodev
- mount_option_var_log_audit_noexec
- mount_option_var_log_audit_nosuid
- mount_option_var_log_nodev
- mount_option_var_log_noexec
- mount_option_var_log_nosuid


Consequence:
Although directories /var/log or /var/log/audit were not mount points for individual partitions, rules were still evaluated and they were reported as failing in the final report. But they should not be evaluated at all.


Fix:
An applicability check was added so that if /var/log or /var/log/audit are not mount points for individual partitions, rules are not evaluated.

Result:
Rules are marked as "not applicable" in the final report.
Vojtech Polasek 2023-08-04 07:27:26 UTC Status NEW POST
Matěj Týč 2023-08-11 12:30:00 UTC Status POST MODIFIED
CC matyc

Back to bug 2228473