Bug 2228458 - AIDE compliancy [rhel-8.8.0.z]
Summary: AIDE compliancy [rhel-8.8.0.z]
Keywords:
Status: MODIFIED
Alias: None
Product: Red Hat Enterprise Linux 8
Classification: Red Hat
Component: scap-security-guide
Version: 8.7
Hardware: All
OS: Linux
medium
medium
Target Milestone: rc
: ---
Assignee: Jan Černý
QA Contact: BaseOS QE Security Team
URL:
Whiteboard:
Depends On: 2175684
Blocks:
TreeView+ depends on / blocked
 
Reported: 2023-08-02 12:18 UTC by RHEL Program Management Team
Modified: 2023-08-11 17:05 UTC (History)
7 users (show)

Fixed In Version: scap-security-guide-0.1.69-1.el8_8
Doc Type: Bug Fix
Doc Text:
Fixed rules related to AIDE configuration Rule `aide_build_database` no longer requires the existence of the `/var/lib/aide/aide.db.new.gz` file which contains the freshly generated AIDE database. The reason is that this database isn't needed for AIDE to work, only the installed database at `/var/lib/aide/aide.db.gz` is needed by AIDE. Users can install the freshly generated database by moving the file from `/var/lib/aide/aide.db.new.gz` to `/var/lib/aide/aide.db.gz`. Previously, the rule required the existence of both `/var/lib/aide/aide.db.new.gz` and `/var/lib/aide/aide.db.gz` in order to pass. Now, it requires only the existence of `/var/lib/aide/aide.db.gz` in order to pass. Rule `aide_periodic_cron_checking` hass been changed to be less strict on entries in `/etc/cron.daily` and `/etc/cron.weekly`. That allows administrators to schedule the `aide --check` command with additional wrappers while staying compliant with the rule.
Clone Of: 2175684
Environment:
Last Closed:
Type: ---
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Issue Tracker RHELPLAN-164135 0 None None None 2023-08-02 12:21:47 UTC


Note You need to log in before you can comment on or make changes to this bug.