When selecting the DOD STIG UPSTREAM profile in RHEL 7.3 beta, the following rule remains non-compliant:
- CCE-27351-6: xccdf_org.ssgproject.content_rule_package_screen_installed
This is likely as the remediation has "yum install screen" and the installer does not access a yum repo to add packages.
upstream BZ https://github.com/OpenSCAP/scap-security-guide/issues/1549
Almost exactly the same situation as https://bugzilla.redhat.com/show_bug.cgi?id=1372058
SSG 0.1.30 only had the bash remediation for the "screen installed" rule. Since it was missing the Anaconda remediation it was not able to remediate this rule when provisioning using kickstart.
There has been a lot of refactoring in this part of SSG so it is fairly hard to pinpoint exactly when this was fixed. All of these 3 commits are required for this to work:
Lastest SSG built from git master has all 4 remediations for the package_screen_installed XCCDF rule.
Verified manually on version scap-security-guide-0.1.33-4.el7, that anaconda kickstart is successfully updated to contain aide package
# Packages selection (%packages section is required)
# Require @Base
Note: This test was performed on OSPP profile, but the relevant rule (screen) is the same.
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.
For information on the advisory, and where to find the updated
files, follow the link below.
If the solution does not work for you, open a new bug report.