Bug 1465681

Summary: rule_package_aide_installed is not enabled in profile_stig-rhel7-disa
Product: Red Hat Enterprise Linux 7 Reporter: Marek Haicman <mhaicman>
Component: scap-security-guideAssignee: Watson Yuuma Sato <wsato>
Status: CLOSED ERRATA QA Contact: Marek Haicman <mhaicman>
Severity: medium Docs Contact:
Priority: medium    
Version: 7.4CC: lmiksik, mhaicman, mpreisle, openscap-maint
Target Milestone: rc   
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: scap-security-guide-0.1.35-1.el7 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2018-04-10 12:20:33 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Marek Haicman 2017-06-27 23:20:56 UTC
Description of problem:
By missing this rule, profile remediation won't install aide package, even though it is required by other aide-related rules, which are failing if aide is not installed.

Version-Release number of selected component (if applicable):
scap-security-guide-0.1.33-5.el7.noarch

How reproducible:
reliably

Steps to Reproduce:
1. Remediate freshly installed system with profile stig-rhel7-disa
2.
3.

Actual results:
aide rules are failing

Expected results:
aide rules are passing after remediation

Additional info:
Possible reason for Bug 1392683

Comment 2 Watson Yuuma Sato 2017-09-05 07:22:12 UTC
Should be fixed by: https://github.com/OpenSCAP/scap-security-guide/pull/2132

Comment 4 Marek Haicman 2018-01-22 11:52:12 UTC
Verified that scap-security-guide-0.1.36-7.el7.noarch contains fix for this issue:

OLD (scap-security-guide-0.1.33-6.el7.noarch):
[dahaic@machine]$ grep 'Profile\|package_aide_installed' 0.1.33-6/ssg-rhel7-ds.xml  | grep "stig-rhel7-disa" -A2
      <Profile id="xccdf_org.ssgproject.content_profile_stig-rhel7-disa">
      </Profile>
      <Profile id="xccdf_org.ssgproject.content_profile_stig-rhevh-upstream">



NEW (scap-security-guide-0.1.36-7.el7.noarch):
[dahaic@machine]$ grep 'Profile\|package_aide_installed' 0.1.33-6/ssg-rhel7-ds.xml | grep "stig-rhel7-disa" -A2
      <Profile id="xccdf_org.ssgproject.content_profile_stig-rhel7-disa">
        <select idref="xccdf_org.ssgproject.content_rule_package_aide_installed" selected="true"/>
      </Profile>

Comment 8 errata-xmlrpc 2018-04-10 12:20:33 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2018:0761