Bug 2152657
| Summary: | Update RHEL7 DISA STIG profile to V3R10 [rhel-7.9.z] | ||
|---|---|---|---|
| Product: | Red Hat Enterprise Linux 7 | Reporter: | Watson Yuuma Sato <wsato> |
| Component: | scap-security-guide | Assignee: | Vojtech Polasek <vpolasek> |
| Status: | CLOSED ERRATA | QA Contact: | Jiri Jaburek <jjaburek> |
| Severity: | unspecified | Docs Contact: | |
| Priority: | unspecified | ||
| Version: | 7.9 | CC: | ggasparb, jjaburek, kpfleming, mhaicman, mlysonek, wsato |
| Target Milestone: | rc | Keywords: | Triaged, ZStream |
| Target Release: | --- | Flags: | pm-rhel:
mirror+
|
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | |||
| Fixed In Version: | scap-security-guide-0.1.66-1.el7_9 | Doc Type: | Enhancement |
| Doc Text: |
.STIG security profile updated to version V3R10
The `DISA STIG for Red Hat Enterprise Linux 7` profile in the SCAP Security Guide has been updated to align with the latest version `V3R10`.
This release also includes changes published in `V3R9`.
You should use only the current version of this profile because older versions are no longer valid.
V3R10
* RHEL-07-010090 - Selected rule package_screen_installed
* RHEL-07-010375 - Selected rule sysctl_kernel_dmsg_restrict
* RHEL-07-020029 - Selected rule aide_build_database
* RHEL-07-030010 - Rule audit_rules_system_shutdown has been parametrized allow shut down, or only recording of the event, in case of audit failure. (default is still system shut down).
* RHEL-07-040470 - Rule sshd_disable_compression is not applicable on RHEL-7.4 and newer
V3R9
* RHEL-07-021040 - Check and remediations now ignore .bash_history
* RHEL-07-030201 - 4 new rules to configure autitd's audispd plugin (active, direction, path, type)
* RHEL-07-030840 - The rule now checks and configures auditing of /usr/bin/kmod via path filters
* RHEL-07-040160 - Handle duplicate and conflicting values of TMOUT.
WARNING: Automatic remediation might render the system non-functional. Run the remediation in a test environment first.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | 2023-03-07 09:54:58 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
Watson Yuuma Sato
2022-12-12 15:58:42 UTC
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory (scap-security-guide bug fix and enhancement update), and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2023:1099 |