Description of problem: The following checks in the xccdf_org.ssgproject.content_profile_stig profile for ssg-rhel8-xccdf.xml do not have clear guidelines for meeting the check requirements. xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_interval xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_deny The following values lead to all 3 checks Success: deny = 3 fail_interval = 900 unlock_time = 900 A deny of 2 fails, a deny of 4 fails Setting fail_interval to 300 fails Setting fail_interval to 1200 Success Setting unlock_time to 1200 is Success Setting unlock_time to 300 is still Success, which is strange as it weaker than the 900 seconds. Version-Release number of selected component (if applicable): scap-security-guide-0.1.66-2.el8_7.noarch How reproducible: Every time Steps to Reproduce: 1. Run scap scan for xccdf_org.ssgproject.content_profile_stig profile 2. Scan results do not state the exact requirement for the fallock interval or faillock deny settings. Actual results: Scan results do not state the exact requirement for the fallock interval or faillock deny settings. If the system fails the check, there is no clear recommendation for what the settings must be. Expected results: The scap results should be clear about what settings are required for compliance. Additional info:
Fix is already merged in Upstream: https://github.com/ComplianceAsCode/content/pull/10824