Bug 2130185
| Summary: | Offline remediation of fstab permissions fails in Image Builder | |||
|---|---|---|---|---|
| Product: | Red Hat Enterprise Linux 8 | Reporter: | Evgeny Kolesnikov <ekolesni> | |
| Component: | scap-security-guide | Assignee: | Vojtech Polasek <vpolasek> | |
| Status: | CLOSED ERRATA | QA Contact: | Milan Lysonek <mlysonek> | |
| Severity: | high | Docs Contact: | Petr Hybl <phybl> | |
| Priority: | high | |||
| Version: | 8.7 | CC: | cbesson, ggasparb, jcerny, jjaburek, matyc, mhaicman, mjahoda, mlysonek, vpolasek, wsato | |
| Target Milestone: | rc | Keywords: | Triaged, ZStream | |
| Target Release: | --- | Flags: | pm-rhel:
mirror+
|
|
| Hardware: | Unspecified | |||
| OS: | Unspecified | |||
| URL: | https://github.com/ComplianceAsCode/content/issues/9342 | |||
| Whiteboard: | ||||
| Fixed In Version: | scap-security-guide-0.1.69-1.el8 | Doc Type: | Bug Fix | |
| Doc Text: |
.Images can now be configured with security profiles
SCAP Security Guide rules that configure mount point options have been reworked, and you can now use them also for hardening images when building an operating system image in image builder. As a result, you can now build images with partition configuration aligned with a specific security profile.
|
Story Points: | --- | |
| Clone Of: | ||||
| : | 2228448 2228476 (view as bug list) | Environment: | ||
| Last Closed: | 2023-11-14 15:36:38 UTC | Type: | Bug | |
| Regression: | --- | Mount Type: | --- | |
| Documentation: | --- | CRM: | ||
| Verified Versions: | Category: | --- | ||
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | ||
| Cloudforms Team: | --- | Target Upstream Version: | ||
| Embargoed: | ||||
| Bug Depends On: | ||||
| Bug Blocks: | 2228448, 2228476 | |||
| Deadline: | 2023-08-28 | |||
|
Description
Evgeny Kolesnikov
2022-09-27 12:38:21 UTC
The way we evaluate and remediate mount point options in CaC content has been changed to accommodate 'offline' systems. The content would now properly detect mount point configuration and change it accordingly in the IB pipeline environment. https://github.com/ComplianceAsCode/content/pull/10200 One of our customers is experiencing the issue while applying CIS Level 1 Server while using osbuild-composer for RHEL 8.8 as well as RHEL 9.2. It also has to be fixed for RHEL 9. Setting the severity as High as we have no workaround to suggest. Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory (scap-security-guide bug fix update), and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2023:7056 |