Hide Forgot
RHEL 7.3 beta install with DoD STIG UPSTREAM profile leaves the following SSH items as non-compliant: - CCE-80220-7: xccdf_org.ssgproject.content_rule_sshd_disable_gssapi_auth - CCE-80221-5: xccdf_org.ssgproject.content_rule_sshd_disable_kerb_auth - CCE-80222-3: xccdf_org.ssgproject.content_rule_sshd_enable_strictmodes - CCE-80223-1: xccdf_org.ssgproject.content_rule_sshd_use_priv_separation - CCE-80224-9: xccdf_org.ssgproject.content_rule_sshd_disable_compression The above appear to need remediation scripts.
upstream bz https://github.com/OpenSCAP/scap-security-guide/issues/1546
Pending upstream PR: https://github.com/OpenSCAP/scap-security-guide/pull/1554
Upstream PR #1554 was closed as this was already fixed upstream on Sept 8th. - CCE-80220-7: https://github.com/OpenSCAP/scap-security-guide/blob/master/shared/templates/static/bash/sshd_disable_gssapi_auth.sh - CCE-80221-5: https://github.com/OpenSCAP/scap-security-guide/blob/master/shared/templates/static/bash/sshd_disable_kerb_auth.sh - CCE-80222-3: https://github.com/OpenSCAP/scap-security-guide/blob/master/shared/templates/static/bash/sshd_enable_strictmodes.sh - CCE-80223-1: https://github.com/OpenSCAP/scap-security-guide/blob/master/shared/templates/static/bash/sshd_use_priv_separation.sh - CCE-80224-9: https://github.com/OpenSCAP/scap-security-guide/blob/master/shared/templates/static/bash/sshd_disable_compression.sh This appears to be a downstream issue.
For posterity, https://github.com/OpenSCAP/scap-security-guide/pull/1471 is the PR fixing this issues.
*** Bug 1392672 has been marked as a duplicate of this bug. ***
*** Bug 1392674 has been marked as a duplicate of this bug. ***
*** Bug 1392676 has been marked as a duplicate of this bug. ***
*** Bug 1392679 has been marked as a duplicate of this bug. ***
OLD: scap-security-guide-0.1.30-3.el7.noarch --profile xccdf_org.ssgproject.content_profile_stig-rhel7-server-upstream xccdf_org.ssgproject.content_rule_sshd_disable_gssapi_auth:fail xccdf_org.ssgproject.content_rule_sshd_disable_kerb_auth:fail xccdf_org.ssgproject.content_rule_sshd_enable_strictmodes:fail xccdf_org.ssgproject.content_rule_sshd_use_priv_separation:fail xccdf_org.ssgproject.content_rule_sshd_disable_compression:fail ---- NO REMEDIATIONS NEW: scap-security-guide-0.1.33-5.el7.noarch --profile xccdf_org.ssgproject.content_profile_ospp-rhel7 xccdf_org.ssgproject.content_rule_sshd_disable_gssapi_auth:fail xccdf_org.ssgproject.content_rule_sshd_disable_kerb_auth:fail xccdf_org.ssgproject.content_rule_sshd_enable_strictmodes:fail xccdf_org.ssgproject.content_rule_sshd_use_priv_separation:fail xccdf_org.ssgproject.content_rule_sshd_disable_compression:fail ---- xccdf_org.ssgproject.content_rule_sshd_disable_gssapi_auth:fixed xccdf_org.ssgproject.content_rule_sshd_disable_kerb_auth:fixed xccdf_org.ssgproject.content_rule_sshd_enable_strictmodes:fixed xccdf_org.ssgproject.content_rule_sshd_use_priv_separation:fixed xccdf_org.ssgproject.content_rule_sshd_disable_compression:fixed
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2017:2064