Hide Forgot
When deploying a system against the DOD STIG Upstream profile, the following checklist item remains non-compliant: - CCE-27512-3: xccdf_org.ssgproject.content_rule_accounts_password_pam_maxclassrepeat Item remains non-compliant after the installation, and when attempting to remediate post-installation via "oscap xccdf eval --remediate..."
Note this has been fixed upstream via https://github.com/OpenSCAP/scap-security-guide/pull/1393
Fixed in https://github.com/OpenSCAP/scap-security-guide/pull/1393/commits/7d23c266133311edfcce6b83dae7355247a4cd40
Test performed by SSG Test Suite prototype OLD === [0 root@qeos-103 ~]# rpm -q scap-security-guide scap-security-guide-0.1.30-3.el7.noarch ./perform_remediation_checks.sh maxclassrepeat # Performing pam/accouts_password_pam_maxclassrepeat/clean FAIL: Remediation for pam/accouts_password_pam_maxclassrepeat/clean is probably missing! # Performing pam/accouts_password_pam_maxclassrepeat/comment FAIL: Remediation for pam/accouts_password_pam_maxclassrepeat/comment is probably missing! # Performing pam/accouts_password_pam_maxclassrepeat/line_not_there FAIL: Remediation for pam/accouts_password_pam_maxclassrepeat/line_not_there is probably missing! # Performing pam/accouts_password_pam_maxclassrepeat/wrong_value_greater FAIL: Remediation for pam/accouts_password_pam_maxclassrepeat/wrong_value_greater is probably missing! # Performing pam/accouts_password_pam_maxclassrepeat/wrong_value_lesser FAIL: Remediation for pam/accouts_password_pam_maxclassrepeat/wrong_value_lesser is probably missing! NEW === [0 root@qeos-106 ~]# rpm -q scap-security-guide scap-security-guide-0.1.32-1.el7.noarch ./perform_remediation_checks.sh maxclassrepeat # Performing pam/accouts_password_pam_maxclassrepeat/clean # Performing pam/accouts_password_pam_maxclassrepeat/comment # Performing pam/accouts_password_pam_maxclassrepeat/line_not_there # Performing pam/accouts_password_pam_maxclassrepeat/wrong_value_greater # Performing pam/accouts_password_pam_maxclassrepeat/wrong_value_lesser
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2017:2064