Hide Forgot
Description of problem: The xccdf_org.ssgproject.content_rule_chronyd_run_as_chrony_user rule enforces setting "-u chrony" in /etc/sysconfig/chrony, which is not necessary on RHEL8 since chronyd already executes as chrony user. Please modify the rule to enforce this setting only if chronyd doesn't run as chrony user already. Version-Release number of selected component (if applicable): scap-security-guide-0.1.57 (RHEL8.5.0) scap-security-guide-0.1.60 (RHEL8.6.0) How reproducible: Always Steps to Reproduce: 1. Execute "xccdf_org.ssgproject.content_rule_chronyd_run_as_chrony_user" rule Actual results: FAIL Expected results: PASS because "chronyd" executes as "chrony" user by default
https://github.com/ComplianceAsCode/content/pull/9156
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory (scap-security-guide bug fix and enhancement update), and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2022:7563