Login
Log in using an SSO provider:
Fedora Account System
Red Hat Associate
Red Hat Customer
Login using a Red Hat Bugzilla account
Forgot Password
Create an Account
Red Hat Bugzilla – Bug 2228462
Home
New
Search
Simple Search
Advanced Search
My Links
Browse
Requests
Reports
Current State
Search
Tabular reports
Graphical reports
Duplicates
Other Reports
User Changes
Plotly Reports
Bug Status
Bug Severity
Non-Defaults
Product Dashboard
Help
Page Help!
Bug Writing Guidelines
What's new
Browser Support Policy
5.0.4.rh89 Release notes
FAQ
Guides index
User guide
Web Services
Contact
Legal
[?]
This site requires JavaScript to be enabled to function correctly, please enable it.
Bug 2228462
-
Rule "All Interactive Users Home Directories Must Exist" (`xccdf_org.ssgproject.content_rule_accounts_user_interactive_home_directory_exists`) applies to non-local users as well [rhel-9.2.0.z]
Summary:
Rule "All Interactive Users Home Directories Must Exist" (`xccdf_org.ssgproje...
Keywords
:
Triaged
ZStream
Status
:
ON_QA
Alias:
None
Product:
Red Hat Enterprise Linux 9
Classification:
Red Hat
Component:
scap-security-guide
Sub Component:
---
Version:
9.2
Hardware:
All
OS:
Linux
Priority:
medium
Severity:
medium
Target Milestone:
rc
Target Release
:
---
Assignee:
Jan Černý
QA Contact:
BaseOS QE Security Team
Docs Contact:
URL:
Whiteboard:
Depends On:
2203791
Blocks:
TreeView+
depends on
/
blocked
Reported:
2023-08-02 12:21 UTC by
RHEL Program Management Team
Modified:
2023-08-17 00:49 UTC (
History
)
CC List:
10 users
(
show
)
ggasparb
jcerny
jjaburek
juschind
matyc
mhaicman
mlysonek
myllynen
openscap-maint
vpolasek
Fixed In Version:
scap-security-guide-0.1.69-1.el9_2
Doc Type:
Bug Fix
Doc Text:
.Rules checking home directories apply only to local users Multiple compliance profiles provided by the `scap-security-guide` package contain rules checking the correct configuration of user home directories. Specifically, we are talking about these rules: - accounts_user_interactive_home_directory_exists - accounts_users_home_files_groupownership - accounts_user_dot_group_ownership - accounts_users_home_files_permissions - accounts_umask_interactive_users - accounts_user_dot_user_ownership - file_permissions_home_directories - file_groupownership_home_directories - file_ownership_home_directories - accounts_users_home_files_ownership Previously, these rules checked not only configuration of local users but they also evaluated configuration of remote users provided by network sources such as NSS. This behavior was caused by using the `getpwent()` system call in the OpenSCAP scanner. This behavior wasn't desired, behavior the remediation scripts weren't able to change the configuration of the remote users. Therefore, the internal implementation of the aforementioned rules has been changed to depend only on data present in the "/etc/passwd" file. That means no other sources of user metadata are read by the rules. As a result, the rules now consider only local users configuration.
Clone Of:
2203791
Environment:
Last Closed:
Type:
---
Target Upstream Version:
Embargoed:
Dependent Products:
Container Native Virtualization (CNV)
OpenShift Container Platform
Red Hat Certificate System
Red Hat Directory Server
Red Hat Enterprise Virtualization Manager
Red Hat OpenStack
Attachments
(Terms of Use)
Links
System
ID
Private
Priority
Status
Summary
Last Updated
Red Hat Issue Tracker
RHELPLAN-164212
0
None
None
None
2023-08-02 14:23:14 UTC
Note
You need to
log in
before you can comment on or make changes to this bug.