Note: This bug is displayed in read-only format because
the product is no longer active in Red Hat Bugzilla.
RHEL Engineering is moving the tracking of its product development work on RHEL 6 through RHEL 9 to Red Hat Jira (issues.redhat.com). If you're a Red Hat customer, please continue to file support cases via the Red Hat customer portal. If you're not, please head to the "RHEL project" in Red Hat Jira and file new tickets here. Individual Bugzilla bugs in the statuses "NEW", "ASSIGNED", and "POST" are being migrated throughout September 2023. Bugs of Red Hat partners with an assigned Engineering Partner Manager (EPM) are migrated in late September as per pre-agreed dates. Bugs against components "kernel", "kernel-rt", and "kpatch" are only migrated if still in "NEW" or "ASSIGNED". If you cannot log in to RH Jira, please consult article #7032570. That failing, please send an e-mail to the RH Jira admins at rh-issues@redhat.com to troubleshoot your issue as a user management inquiry. The email creates a ServiceNow ticket with Red Hat. Individual Bugzilla bugs that are migrated will be moved to status "CLOSED", resolution "MIGRATED", and set with "MigratedToJIRA" in "Keywords". The link to the successor Jira issue will be found under "Links", have a little "two-footprint" icon next to it, and direct you to the "RHEL project" in Red Hat Jira (issue links are of type "https://issues.redhat.com/browse/RHEL-XXXX", where "X" is a digit). This same link will be available in a blue banner at the top of the page informing you that that bug has been migrated.
Description of problem:
The following three remediations show fail, even though the proper rules appear to be in place.
xccdf_org.ssgproject.content_rule_audit_rules_kernel_module_loading
xccdf_org.ssgproject.content_rule_audit_rules_kernel_module_loading_init
xccdf_org.ssgproject.content_rule_audit_rules_kernel_module_loading_delete
Version-Release number of selected component (if applicable):
openscap-1.2.17-2.el7.x86_64
scap-security-guide-0.1.40-12.el7.noarch
openscap-scanner-1.2.17-2.el7.x86_64
How reproducible:
Always
Steps to Reproduce:
1. Remediate/scan a system using oscap with DISA STIG
Actual results:
System shows fail on the following 3 in rules
- Ensure auditd Collects Information on Kernel Module Loading and Unloading
- Ensure auditd Collects Information on Kernel Module Loading and Unloading - init_module
- Ensure auditd Collects Information on Kernel Module Loading and Unloading - delete_module
Expected results:
System will properly recognize that the rules have been implemented
Additional info:
Attempted automatic remediation with --remediate, as well as taking the recommended remediation from the report.html generated and running that from a bash script, neither one results in the checks properly passing, though the proper remediations do appear to be in place
Comment 2Watson Yuuma Sato
2019-03-25 12:26:44 UTC
Hello Ryan,
I believe this is a duplicate of https://bugzilla.redhat.com/show_bug.cgi?id=1658136.
There were fixes to the recommended remediation in rule description and also to bash scripts.
Problem was that audit rules for two other syscalls are also expected to be in place: finit_module and create_module.
A work around for this is to add manually the audit rules as follows:
-a always,exit -F arch=32 -S init_module -S delete_module -S finit_module -S create_module -F key=modules
-a always,exit -F arch=64 -S init_module -S delete_module -S finit_module -S create_module -F key=modules
*** This bug has been marked as a duplicate of bug 1658136 ***
Comment 3Watson Yuuma Sato
2019-03-25 13:23:23 UTC
Also, please note that 64 bit systems need to have the audit rule for both, 32 bits,and 64 bits.