Bug 2053587 - Profile ANSSI Enhanced is missing the rule selinux_state
Summary: Profile ANSSI Enhanced is missing the rule selinux_state
Keywords:
Status: CLOSED ERRATA
Alias: None
Deadline: 2022-02-14
Product: Red Hat Enterprise Linux 8
Classification: Red Hat
Component: scap-security-guide
Version: 8.5
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: rc
: ---
Assignee: Watson Yuuma Sato
QA Contact: Milan Lysonek
Khushbu Borole
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2022-02-11 14:52 UTC by Watson Yuuma Sato
Modified: 2022-05-10 14:43 UTC (History)
5 users (show)

Fixed In Version: scap-security-guide-0.1.60-2.el8
Doc Type: Bug Fix
Doc Text:
.ANSSI Enhanced Profile correctly selects the "Ensure SELinux State is Enforcing" rule Previously, the ANSSI Enhanced profile (`anssi_bp28_enhanced`) did not select the "Ensure SELinux State is Enforcing" (`selinux_state`) rule. This update modified the rule selection and now the ANSSI Enhanced Profile selects the "Ensure SELinux State is Enforcing" rule.
Clone Of:
Environment:
Last Closed: 2022-05-10 14:15:29 UTC
Type: Bug
Target Upstream Version:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Issue Tracker RHELPLAN-112040 0 None None None 2022-02-11 14:55:28 UTC
Red Hat Product Errata RHBA-2022:1900 0 None None None 2022-05-10 14:15:52 UTC

Description Watson Yuuma Sato 2022-02-11 14:52:06 UTC
Description of problem:
Profile anssi_bp28_enhanced doesn't select rule 'selinux_state'.
But the lower (anssi_bp28_intermediary) and higher (anssi_bp28_high) level hardening profiles select the rule.


Version-Release number of selected component (if applicable):
scap-security-guide-0.1.57-5.el8


How reproducible:
Always


Steps to Reproduce:
1. oscap xccdf eval --profile anssi_bp28_enhanced /usr/share/xml/scap/ssg/content/ssg-rhel8-ds.xml

Actual results:
Rule selinux_state is not evaluated on a scan with 'anssi_bp28_enhanced'.

Expected results:
Rule selinux_state should be evaluated when profile 'anssi_bp28_enhanced' is scanned.

Additional info:

Comment 2 Watson Yuuma Sato 2022-02-11 16:16:12 UTC
https://github.com/ComplianceAsCode/content/pull/8182

Comment 9 errata-xmlrpc 2022-05-10 14:15:29 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (scap-security-guide bug fix and enhancement update), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2022:1900


Note You need to log in before you can comment on or make changes to this bug.