Red Hat Bugzilla – Bug 1291516
USGCB STIG for RHEL 7 mentions obsolete "PROMPT=no" option in /etc/sysconfig/init
Last modified: 2016-11-04 03:33:03 EDT
Description of problem:
with the switch to systemd the "PROMPT" option is no longer a valid config option in /etc/sysconfig/init and has no effect, therefore setting it to "no" does nothing and shouldn't be checked by the guide. ("Disable Interactive Boot")
Version-Release number of selected component (if applicable):
To my understanding this has been fixed in upstream. Granting dev_ack+.
Unless I'm missing something, (And I could very well be) I don't see the changes merged for RHEL7:
RHEL7/systemd does not follow the PROMPT=no option in /etc/sysconfig/init, so that test should be removed.
RHEL7/systemd uses systemd.confirm_spawn=1 on the kernel command line to do an interactive boot, that test needs to be added.
Ah, you are right, Karl.
Proposed upstream patch:
Version scap-security-guide-0.1.30-1.el7 contains the fix. PROMPT=no is no longer suggested and checked, and instead systemd.confirm_spawn is checked.
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.
For information on the advisory, and where to find the updated
files, follow the link below.
If the solution does not work for you, open a new bug report.