Hide Forgot
Description of problem: oscap scans reports that 30-ospp-v42.rules and 11-loginuid.rules do not match the sample rules in /usr/share/audit/sample-rules if 10-base-config.rules has been changed. Version-Release number of selected component (if applicable): scap-security-guide-0.1.54-5.el8.noarch How reproducible: Easily reproducible if 10-base-config.rules. The customer needs to change the buffer size but sees other rules are also flagged whenever they change that file. Steps to Reproduce: 1. Copy the files from /usr/share/audit/sample-rules to /etc/audit/rules.d/ and make some change to a file (in this case the customer is editing 10-base-config.rules). 2. Scan the system with oscap using the xccdf_org.ssgproject.content_profile_ospp profile from /usr/share/xml/scap/ssg/content/ssg-rhel8-ds.xml 3. The scan shows that 10-base-config.rules is changed (expected) as well as 30-ospp-v42.rules and 11-loginuid.rules (not expected). Actual results: The scan shows that 10-base-config.rules is changed (expected) as well as 30-ospp-v42.rules and 11-loginuid.rules (not expected) if 10-base-config.rules is changed. Expected results: The scan should only fail 10-base-config.rules since these files are all checked individually.
Fixed upstream: https://github.com/ComplianceAsCode/content/pull/8047
https://github.com/ComplianceAsCode/content/pull/8152
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory (scap-security-guide bug fix and enhancement update), and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2022:1900