RHEL Engineering is moving the tracking of its product development work on RHEL 6 through RHEL 9 to Red Hat Jira (issues.redhat.com). If you're a Red Hat customer, please continue to file support cases via the Red Hat customer portal. If you're not, please head to the "RHEL project" in Red Hat Jira and file new tickets here. Individual Bugzilla bugs in the statuses "NEW", "ASSIGNED", and "POST" are being migrated throughout September 2023. Bugs of Red Hat partners with an assigned Engineering Partner Manager (EPM) are migrated in late September as per pre-agreed dates. Bugs against components "kernel", "kernel-rt", and "kpatch" are only migrated if still in "NEW" or "ASSIGNED". If you cannot log in to RH Jira, please consult article #7032570. That failing, please send an e-mail to the RH Jira admins at rh-issues@redhat.com to troubleshoot your issue as a user management inquiry. The email creates a ServiceNow ticket with Red Hat. Individual Bugzilla bugs that are migrated will be moved to status "CLOSED", resolution "MIGRATED", and set with "MigratedToJIRA" in "Keywords". The link to the successor Jira issue will be found under "Links", have a little "two-footprint" icon next to it, and direct you to the "RHEL project" in Red Hat Jira (issue links are of type "https://issues.redhat.com/browse/RHEL-XXXX", where "X" is a digit). This same link will be available in a blue banner at the top of the page informing you that that bug has been migrated.
Bug 2000264 - oscap scans for xccdf_org.ssgproject.content_profile_ospp profile incorrectly flags 11-loginuid.rules and 30-ospp-v42.rules as altered if 10-base-config.rules is changed
Summary: oscap scans for xccdf_org.ssgproject.content_profile_ospp profile incorrectly...
Alias: None
Product: Red Hat Enterprise Linux 8
Classification: Red Hat
Component: scap-security-guide
Version: 8.4
Hardware: Unspecified
OS: Linux
Target Milestone: rc
: ---
Assignee: Vojtech Polasek
QA Contact: Milan Lysonek
Khushbu Borole
Depends On:
TreeView+ depends on / blocked
Reported: 2021-09-01 17:32 UTC by Lark Gordon
Modified: 2022-05-10 14:42 UTC (History)
8 users (show)

Fixed In Version: scap-security-guide-0.1.60-2.el8
Doc Type: Bug Fix
Doc Text:
.Files in `/usr/share/audit/sample-rules` are now accepted by SCAP rules Previously, according to the description of SCAP rules `xccdf_org.ssgproject.content_rule_audit_ospp_general` and `xccdf_org.ssgproject.content_rule_audit_immutable_login_uids`, users were able to make systems compliant by copying appropriate files from the `/usr/share/audit/sample-rules` directory. However, OVAL checks of these rules failed, and the system was consequently marked as non-compliant after the scan. With this update, the OVAL checks now accept the files from `/usr/share/audit/sample-rules`, and the SCAP rules pass successfully.
Clone Of:
Last Closed: 2022-05-10 14:14:34 UTC
Type: Bug
Target Upstream Version:

Attachments (Terms of Use)

System ID Private Priority Status Summary Last Updated
Red Hat Issue Tracker RHELPLAN-95916 0 None None None 2021-09-01 17:33:50 UTC
Red Hat Product Errata RHBA-2022:1900 0 None None None 2022-05-10 14:14:44 UTC

Description Lark Gordon 2021-09-01 17:32:03 UTC
Description of problem:

oscap scans reports that 30-ospp-v42.rules and 11-loginuid.rules do not match the sample rules in /usr/share/audit/sample-rules if 10-base-config.rules has been changed.

Version-Release number of selected component (if applicable):


How reproducible:
Easily reproducible if  10-base-config.rules. The customer needs to change the buffer size but sees other rules are also flagged whenever they change that file.

Steps to Reproduce:
1. Copy the files from /usr/share/audit/sample-rules to /etc/audit/rules.d/ and make some change to a file (in this case the customer is editing 10-base-config.rules).

2. Scan the system with oscap using the xccdf_org.ssgproject.content_profile_ospp profile from /usr/share/xml/scap/ssg/content/ssg-rhel8-ds.xml

3. The scan shows that 10-base-config.rules is changed (expected) as well as 30-ospp-v42.rules and 11-loginuid.rules (not expected).

Actual results:
The scan shows that 10-base-config.rules is changed (expected) as well as 30-ospp-v42.rules and 11-loginuid.rules (not expected) if 10-base-config.rules is changed.

Expected results:
The scan should only fail 10-base-config.rules since these files are all checked individually.

Comment 3 Vojtech Polasek 2022-01-12 08:05:26 UTC
Fixed upstream:

Comment 13 Watson Yuuma Sato 2022-02-11 16:17:12 UTC

Comment 27 errata-xmlrpc 2022-05-10 14:14:34 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (scap-security-guide bug fix and enhancement update), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.


Note You need to log in before you can comment on or make changes to this bug.