Bug 1760734
| Summary: | [RFE] Provide CIS profile for RHEL8 | ||
|---|---|---|---|
| Product: | Red Hat Enterprise Linux 8 | Reporter: | Steffen Froemer <sfroemer> |
| Component: | scap-security-guide | Assignee: | Watson Yuuma Sato <wsato> |
| Status: | CLOSED ERRATA | QA Contact: | Matus Marhefka <mmarhefk> |
| Severity: | high | Docs Contact: | Jan Fiala <jafiala> |
| Priority: | medium | ||
| Version: | 8.0 | CC: | coilew, ekasprzy, ggasparb, jafiala, janarula, kagarwal, lagordon, mhaicman, mjahoda, mmarhefk, musman, wsato |
| Target Milestone: | rc | Keywords: | FutureFeature |
| Target Release: | 8.0 | Flags: | pm-rhel:
mirror+
|
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | |||
| Fixed In Version: | scap-security-guide-0.1.50-4.el8 | Doc Type: | Enhancement |
| Doc Text: |
.SCAP Security Guide now provides a profile aligned with the CIS RHEL 8 Benchmark v1.0.0
With this update, the `scap-security-guide` packages provide a profile aligned with the CIS Red Hat Enterprise Linux 8 Benchmark v1.0.0. The profile enables you to harden the configuration of the system using the guidelines by the Center for Internet Security (CIS). As a result, you can configure and automate compliance of your RHEL 8 systems with CIS by using the CIS Ansible Playbook and the CIS SCAP profile.
Note that the `rpm_verify_permissions` rule in the CIS profile does not work correctly.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | 2020-11-04 02:29:53 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | |||
| Bug Blocks: | 1888915 | ||
|
Description
Steffen Froemer
2019-10-11 08:07:59 UTC
Hello Steffen, you are asking here for C2S profile, that is U.S. Government Commercial Cloud Services (C2S) baseline inspired by the Center for Internet Security baseline (CIS) (there are some deliberate differences). Is that really what you are asking for? Or it's the CIS you seek? After double checking with the requestors we have realized that what is needed here is CIS profile, not C2S. (C2S is profile inspired by CIS but is not identical. It is also currently the only CIS alternative shipped with RHEL7, until Bug 1821633 gets fixed - that was the cause of confusion). Changing topic of this BZ to CIS, to clear things up. Steffen, just to make very clear what will be sufficient for the customers - they are interested in the hardening during installation. We have been getting a lot of request for Ansible coverage lately. As the installation hardening and ansible hardening are two different pieces of code, so to say, can you check if customers have any expectations about Ansible? Thanks! For my customers the hardening happen during installation already. There is no need of ansible for them. The priority is on availability of CIS profile during installation. For some US federal government users, the lack of the CIS/C2S profile on installation is hindering adoption of RHEL8. It would be great to see some movement on addressing this bug. Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory (scap-security-guide bug fix and enhancement update), and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2020:4626 *** Bug 1888722 has been marked as a duplicate of this bug. *** |