Bug 2130185
| Summary: | Offline remediation of fstab permissions fails in Image Builder | |||
|---|---|---|---|---|
| Product: | Red Hat Enterprise Linux 8 | Reporter: | Evgeny Kolesnikov <ekolesni> | |
| Component: | scap-security-guide | Assignee: | Vojtech Polasek <vpolasek> | |
| Status: | MODIFIED --- | QA Contact: | BaseOS QE Security Team <qe-baseos-security> | |
| Severity: | high | Docs Contact: | ||
| Priority: | high | |||
| Version: | 8.7 | CC: | cbesson, ggasparb, jcerny, jjaburek, matyc, mhaicman, mlysonek, vpolasek, wsato | |
| Target Milestone: | rc | Keywords: | Triaged, ZStream | |
| Target Release: | --- | |||
| Hardware: | Unspecified | |||
| OS: | Unspecified | |||
| URL: | https://github.com/ComplianceAsCode/content/issues/9342 | |||
| Whiteboard: | ||||
| Fixed In Version: | scap-security-guide-0.1.69-1.el8 | Doc Type: | Bug Fix | |
| Doc Text: |
.Mount point options configuration in Image Builder
Rules that configure mount point options have been reworked in a way that they now are effective also when they are used for hardening images when building an operating system image in Image Builder. As a result, users of Image Builder can now build images with partition configuration aligned with the security profile of their choice.
|
Story Points: | --- | |
| Clone Of: | ||||
| : | 2228448 2228476 (view as bug list) | Environment: | ||
| Last Closed: | Type: | Bug | ||
| Regression: | --- | Mount Type: | --- | |
| Documentation: | --- | CRM: | ||
| Verified Versions: | Category: | --- | ||
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | ||
| Cloudforms Team: | --- | Target Upstream Version: | ||
| Embargoed: | ||||
| Bug Depends On: | ||||
| Bug Blocks: | 2228448, 2228476 | |||
| Deadline: | 2023-08-28 | |||
|
Description
Evgeny Kolesnikov
2022-09-27 12:38:21 UTC
The way we evaluate and remediate mount point options in CaC content has been changed to accommodate 'offline' systems. The content would now properly detect mount point configuration and change it accordingly in the IB pipeline environment. https://github.com/ComplianceAsCode/content/pull/10200 One of our customers is experiencing the issue while applying CIS Level 1 Server while using osbuild-composer for RHEL 8.8 as well as RHEL 9.2. It also has to be fixed for RHEL 9. Setting the severity as High as we have no workaround to suggest. |