Description of problem: Current benchmark used by Insights is Red Hat Enterprise Linux 7 Benchmark™, v2.2.0, released 12-27-2017. We need it to use Level 2 of CIS Red Hat Enterprise Linux 7 Benchmark v3.0.1 released 09-21-2020. Version-Release number of selected component (if applicable): insights-client-3.1.1-1.el7_9.noarch scap-security-guide-0.1.52-2.el7_9.noarch How reproducible: Always Steps to Reproduce: 1. Install latest scap-security-guide package on RHEL 7 2. Create a CIS compliance policy with RHEL 7 Host Actual results: This profile defines a baseline that aligns to the Center for Internet Security® Red Hat Enterprise Linux 7 Benchmark™, v2.2.0, released 12-27-2017. This profile includes Center for Internet Security® Red Hat Enterprise Linux 7 CIS Benchmarks™ content. Expected results: The Benchmark should be updated to the latest version in the 'scap-security-guide' package. Security standards require using the latest benchmark. Additional info: # oscap info --profile xccdf_org.ssgproject.content_profile_cis /usr/share/xml/scap/ssg/content/ssg-rhel7-ds.xml Profile Title: CIS Red Hat Enterprise Linux 7 Benchmark Id: xccdf_org.ssgproject.content_profile_cis Description: This profile defines a baseline that aligns to the Center for Internet Security® Red Hat Enterprise Linux 7 Benchmark™, v2.2.0, released 12-27-2017. This profile includes Center for Internet Security® Red Hat Enterprise Linux 7 CIS Benchmarks™ content.
Linking JIRA issue for tracking
*** Bug 1953748 has been marked as a duplicate of this bug. ***
The profile is upstream: https://github.com/ComplianceAsCode/content/pull/7108 https://github.com/ComplianceAsCode/content/pull/7111 https://github.com/ComplianceAsCode/content/pull/7112 https://github.com/ComplianceAsCode/content/pull/7134 https://github.com/ComplianceAsCode/content/pull/7193 https://github.com/ComplianceAsCode/content/pull/7219 https://github.com/ComplianceAsCode/content/pull/7237 https://github.com/ComplianceAsCode/content/pull/7259 https://github.com/ComplianceAsCode/content/pull/7382 https://github.com/ComplianceAsCode/content/pull/7384
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory (scap-security-guide bug fix and enhancement update), and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2021:4781