Bug 1465675 - 14 audit related rules fail to remediate on fresh installed system
Summary: 14 audit related rules fail to remediate on fresh installed system
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Red Hat Enterprise Linux 7
Classification: Red Hat
Component: scap-security-guide
Version: 7.4
Hardware: Unspecified
OS: Unspecified
medium
medium
Target Milestone: rc
: ---
Assignee: Jan Černý
QA Contact: Watson Yuuma Sato
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2017-06-27 22:43 UTC by Marek Haicman
Modified: 2019-08-06 13:04 UTC (History)
4 users (show)

Fixed In Version: scap-security-guide-0.1.43-1.el7
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2019-08-06 13:04:08 UTC
Target Upstream Version:


Attachments (Terms of Use)


Links
System ID Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2019:2198 None None None 2019-08-06 13:04:20 UTC

Description Marek Haicman 2017-06-27 22:43:21 UTC
Description of problem:
When remediations of complex profiles shipped in scap-security-guide are applied to freshly installed system (note - not using anaconda, but after the installation is finished), 14 audit related rules stays incompliant, these rules are:

C2S and CJIS profiles:
xccdf_org.ssgproject.content_rule_audit_rules_kernel_module_loading

OSPP, STIG profiles:
xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_creat
xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_open
xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_openat
xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_open_by_handle_at
xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_truncate
xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_ftruncate
--
xccdf_org.ssgproject.content_rule_audit_rules_kernel_module_loading_init
xccdf_org.ssgproject.content_rule_audit_rules_kernel_module_loading_delete
--
xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_group
xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_gshadow
xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_shadow
xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_passwd
xccdf_org.ssgproject.content_rule_audit_rules_usergroup_modification_opasswd



Version-Release number of selected component (if applicable):
scap-security-guide-0.1.33-5.el7.noarch

How reproducible:
reliably

Steps to Reproduce:
1. install fresh RHEL7.4 machine
2. run remediation of one of the aforementioned profiles
3.

Actual results:
Rules still failing after the remediation

Expected results:
Rules passing after the remediation

Additional info:

Comment 1 Watson Yuuma Sato 2017-11-16 16:22:11 UTC
On RHEL7.4 with scap-security-guide-0.1.36, scan after remediation of following Rules report pass:
rule_audit_rules_unsuccessful_file_modification_*
rule_audit_rules_usergroup_modification_*

But Rule xccdf_org.ssgproject.content_rule_audit_rules_kernel_module_loading errors on remediation.

Comment 2 Watson Yuuma Sato 2018-11-26 13:38:54 UTC
This commit https://github.com/ComplianceAsCode/content/commit/8c6107f26a fixes Rule xccdf_org.ssgproject.content_rule_audit_rules_kernel_module_loading errors on RHEL7.6.

Comment 9 errata-xmlrpc 2019-08-06 13:04:08 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2019:2198


Note You need to log in before you can comment on or make changes to this bug.