Red Hat Bugzilla – Bug 1465681
rule_package_aide_installed is not enabled in profile_stig-rhel7-disa
Last modified: 2018-04-10 08:21:04 EDT
Description of problem: By missing this rule, profile remediation won't install aide package, even though it is required by other aide-related rules, which are failing if aide is not installed. Version-Release number of selected component (if applicable): scap-security-guide-0.1.33-5.el7.noarch How reproducible: reliably Steps to Reproduce: 1. Remediate freshly installed system with profile stig-rhel7-disa 2. 3. Actual results: aide rules are failing Expected results: aide rules are passing after remediation Additional info: Possible reason for Bug 1392683
Should be fixed by: https://github.com/OpenSCAP/scap-security-guide/pull/2132
Verified that scap-security-guide-0.1.36-7.el7.noarch contains fix for this issue: OLD (scap-security-guide-0.1.33-6.el7.noarch): [dahaic@machine]$ grep 'Profile\|package_aide_installed' 0.1.33-6/ssg-rhel7-ds.xml | grep "stig-rhel7-disa" -A2 <Profile id="xccdf_org.ssgproject.content_profile_stig-rhel7-disa"> </Profile> <Profile id="xccdf_org.ssgproject.content_profile_stig-rhevh-upstream"> NEW (scap-security-guide-0.1.36-7.el7.noarch): [dahaic@machine]$ grep 'Profile\|package_aide_installed' 0.1.33-6/ssg-rhel7-ds.xml | grep "stig-rhel7-disa" -A2 <Profile id="xccdf_org.ssgproject.content_profile_stig-rhel7-disa"> <select idref="xccdf_org.ssgproject.content_rule_package_aide_installed" selected="true"/> </Profile>
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2018:0761