Bug 2021258
| Summary: | Rule file_permissions_sshd_private_key fails after kickstart installation [rhel-7.9.z] | ||
|---|---|---|---|
| Product: | Red Hat Enterprise Linux 7 | Reporter: | Milan Lysonek <mlysonek> |
| Component: | scap-security-guide | Assignee: | Vojtech Polasek <vpolasek> |
| Status: | CLOSED ERRATA | QA Contact: | Matus Marhefka <mmarhefk> |
| Severity: | unspecified | Docs Contact: | |
| Priority: | unspecified | ||
| Version: | 7.9 | CC: | ggasparb, kpfleming, mhaicman, wsato |
| Target Milestone: | rc | Keywords: | Triaged, ZStream |
| Target Release: | --- | Flags: | pm-rhel:
mirror+
|
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | |||
| Fixed In Version: | scap-security-guide-0.1.63-1.el7_9 | Doc Type: | Known Issue |
| Doc Text: |
Cause: Selecting a security profile containing the rule `xccdf_org.ssgproject.content_rule_file_permissions_sshd_private_key` with identifier CCE-27485-2 during RHEL7 installation.
Consequence: The rule `xccdf_org.ssgproject.content_rule_file_permissions_sshd_private_key` with identifier CCE-27485-2 fails to comply with the policy.
Workaround (if any): Rerun remediation again for this rule to fix it.
Result: The rule `xccdf_org.ssgproject.content_rule_file_permissions_sshd_private_key` with identifier CCE-27485-2 reports passing when a new scan is performed using a security profile that selects it, e.g `xccdf_org.ssgproject.content_profile_stig`.
Moreover, this rule expects some files to exist with certain permissions. During installation phase of RHEL, these files don't exist and the compliance assessment reports pass for the rule. But after the first boot, these files are created and they don't comply with the policy, requiring a remediation fix to applied once more.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | 2022-09-20 09:07:04 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Comment 4
Watson Yuuma Sato
2022-08-01 08:36:19 UTC
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory (scap-security-guide bug fix and enhancement update), and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2022:6576 |