Bug 1691912
| Summary: | openscap doesn't properly recognize kernel module loading and unloading remediations | ||
|---|---|---|---|
| Product: | Red Hat Enterprise Linux 7 | Reporter: | Ryan Mullett <rmullett> |
| Component: | scap-security-guide | Assignee: | Watson Yuuma Sato <wsato> |
| Status: | CLOSED DUPLICATE | QA Contact: | BaseOS QE Security Team <qe-baseos-security> |
| Severity: | medium | Docs Contact: | |
| Priority: | unspecified | ||
| Version: | 7.6 | CC: | ggasparb, mhaicman, openscap-maint |
| Target Milestone: | rc | ||
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | If docs needed, set a value | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2019-03-25 12:26:44 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
Ryan Mullett
2019-03-22 19:35:58 UTC
Hello Ryan, I believe this is a duplicate of https://bugzilla.redhat.com/show_bug.cgi?id=1658136. There were fixes to the recommended remediation in rule description and also to bash scripts. Problem was that audit rules for two other syscalls are also expected to be in place: finit_module and create_module. A work around for this is to add manually the audit rules as follows: -a always,exit -F arch=32 -S init_module -S delete_module -S finit_module -S create_module -F key=modules -a always,exit -F arch=64 -S init_module -S delete_module -S finit_module -S create_module -F key=modules *** This bug has been marked as a duplicate of bug 1658136 *** Also, please note that 64 bit systems need to have the audit rule for both, 32 bits,and 64 bits. |