Bug 1838622
| Summary: | Rule rpm_verify_permissions in CIS profile always fails | |||
|---|---|---|---|---|
| Product: | Red Hat Enterprise Linux 7 | Reporter: | Watson Yuuma Sato <wsato> | |
| Component: | scap-security-guide | Assignee: | Vojtech Polasek <vpolasek> | |
| Status: | CLOSED WONTFIX | QA Contact: | BaseOS QE Security Team <qe-baseos-security> | |
| Severity: | medium | Docs Contact: | Jan Fiala <jafiala> | |
| Priority: | medium | |||
| Version: | 7.9 | CC: | ggasparb, jafiala, mhaicman, mjahoda, qe-baseos-security, wsato | |
| Target Milestone: | rc | Keywords: | Triaged | |
| Target Release: | --- | |||
| Hardware: | Unspecified | |||
| OS: | Unspecified | |||
| Whiteboard: | ||||
| Fixed In Version: | Doc Type: | Known Issue | ||
| Doc Text: |
.`rpm_verify_permissions` fails in the CIS profile
The `rpm_verify_permissions` rule compares file permissions to package default permissions. However, the Center for Internet Security (CIS) profile, which is provided by the `scap-security-guide` packages, changes some file permissions to be more strict than default. As a consequence, verification of certain files using `rpm_verify_permissions` fails. To work around this problem, manually verify that these files have the following permissions:
* `/etc/cron.d` (0700)
* `/etc/cron.hourly` (0700)
* `/etc/cron.monthly` (0700)
* `/etc/crontab` (0600)
* `/etc/cron.weekly` (0700)
* `/etc/cron.daily` (0700)
For more information about the related feature, see xref:BZ-1821633[].
|
Story Points: | --- | |
| Clone Of: | ||||
| : | 1843913 (view as bug list) | Environment: | ||
| Last Closed: | 2020-06-18 15:56:55 UTC | Type: | Bug | |
| Regression: | --- | Mount Type: | --- | |
| Documentation: | --- | CRM: | ||
| Verified Versions: | Category: | --- | ||
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | ||
| Cloudforms Team: | --- | Target Upstream Version: | ||
| Embargoed: | ||||
| Bug Depends On: | ||||
| Bug Blocks: | 1843913 | |||
|
Description
Watson Yuuma Sato
2020-05-21 13:03:03 UTC
Closing this BZ. This expectation in CIS profile is not compatible with how RPM verification works, and implementation would be prohibitively expansive. For further details please read the Doc text. |