diff --git a/checklist/sunayu_rhel7_v2_r1.ckl b/checklist/sunayu_rhel7_v2_r1.ckl index 9b7cec5..b405a24 100644 --- a/checklist/sunayu_rhel7_v2_r1.ckl +++ b/checklist/sunayu_rhel7_v2_r1.ckl @@ -6718,7 +6718,7 @@ clean_requirements_on_remove=1 CCI_REF CCI-002617 - NotAFinding + Not_Reviewed @@ -7735,7 +7735,7 @@ If GIDs referenced in "/etc/passwd" file are returned as not defined in "/etc/gr CCI_REF CCI-000764 - Not_Applicable + Not_Reviewed @@ -11168,7 +11168,7 @@ If a separate entry for the file system/partition that contains the non-privileg CCI_REF CCI-000366 - Not_Applicable + Not_Reviewed @@ -11282,7 +11282,7 @@ If a separate entry for "/var" is not in use, this is a finding.CCI_REF CCI-000366 - Not_Applicable + Not_Reviewed @@ -11399,7 +11399,7 @@ If no result is returned, or "/var/log/audit" is not on a separate file system, CCI_REF CCI-000366 - Not_Applicable + Not_Reviewed @@ -11515,7 +11515,7 @@ If the "tmp.mount" service is not enabled, this is a finding. CCI_REF CCI-000366 - NotAFinding + Not_Reviewed @@ -11836,7 +11836,7 @@ If AIDE is installed, ensure the "acl" rule is present on all uncommented file a CCI_REF CCI-000366 - NotAFinding + Not_Reviewed @@ -11969,7 +11969,7 @@ If AIDE is installed, ensure the "xattrs" rule is present on all uncommented fil CCI_REF CCI-000366 - NotAFinding + Not_Reviewed @@ -20887,7 +20887,7 @@ Add the following line to the top of the /etc/security/limits.conf: CCI_REF CCI-000054 - NotAFinding + Not_Reviewed @@ -24567,7 +24567,7 @@ Start the firewall via "systemctl" with the following command: CCI_REF CCI-000366 - Open + NotAFinding @@ -24685,7 +24685,7 @@ session required pam_lastlog.so showfailed CCI_REF CCI-000366 - NotAFinding + Not_Reviewed @@ -25054,7 +25054,7 @@ If the "/etc/resolv.conf" file must be mutable, the required configuration must CCI_REF CCI-000366 - Not_Applicable + Not_Reviewed @@ -26903,7 +26903,7 @@ Ensure the "sec" option is defined as "krb5:krb5i:krb5p". CCI_REF CCI-000366 - Open + Not_Applicable @@ -27172,7 +27172,7 @@ If "firewalld" is not "active", enable "tcpwrappers" by configuring "/etc/hosts. CCI_REF CCI-000366 - Open + NotAFinding @@ -27299,7 +27299,7 @@ If "libreswan" is installed, "IPsec" is active, and an undocumented tunnel is ac CCI_REF CCI-000366 - Open + NotAFinding @@ -27845,7 +27845,7 @@ Modify all of the "cert_policy" lines in "/etc/pam_pkcs11/pam_pkcs11.conf" to in CCI_REF CCI-001954 - Open + NotAFinding @@ -28117,7 +28117,7 @@ Add the setting to lock the session idle delay: CCI_REF CCI-000057 - Open + NotAFinding @@ -28360,7 +28360,7 @@ If no results are returned and use of NFS imported binaries is not documented wi CCI_REF CCI-000366 - Open + Not_Applicable @@ -28478,7 +28478,7 @@ network_failure_action = syslog CCI_REF CCI-001851 - Not_Applicable + NotAFinding @@ -28613,7 +28613,7 @@ The audit daemon must be restarted for the changes to take effect.CCI_REF CCI-002130 - Open + NotAFinding @@ -28748,7 +28748,7 @@ The audit daemon must be restarted for the changes to take effect.CCI_REF CCI-002130 - Open + NotAFinding @@ -28883,7 +28883,7 @@ The audit daemon must be restarted for the changes to take effect.CCI_REF CCI-002130 - Open + NotAFinding @@ -29019,7 +29019,7 @@ The audit daemon must be restarted for the changes to take effect: CCI_REF CCI-002130 - Open + NotAFinding @@ -29273,7 +29273,7 @@ If a wireless interface is configured and its use on the system is not documente CCI_REF CCI-002418 - Open + Not_Applicable @@ -29422,7 +29422,7 @@ Update the system databases: CCI_REF CCI-001954 - Open + Not_Applicable @@ -29551,7 +29551,7 @@ blacklist dccp CCI_REF CCI-001958 - Open + NotAFinding @@ -29670,7 +29670,7 @@ ExecStart=-/bin/sh -c "/usr/sbin/sulogin; /usr/bin/systemctl --fail --no-block d CCI_REF CCI-000213 - Open + NotAFinding @@ -29799,7 +29799,7 @@ Issue the following command to make the changes take effect: CCI_REF CCI-000366 - Open + NotAFinding @@ -30070,7 +30070,7 @@ The audit daemon must be restarted for the changes to take effect.CCI_REF CCI-000172 - Open + NotAFinding @@ -30202,7 +30202,7 @@ The audit daemon must be restarted for the changes to take effect.CCI_REF CCI-000172 - Open + NotAFinding @@ -30318,7 +30318,7 @@ password substack system-auth CCI_REF CCI-000192 - Open + NotAFinding @@ -30713,7 +30713,7 @@ If no results are returned, this is a finding. CCI_REF CCI-001764 - Open + Not_Reviewed @@ -30834,7 +30834,7 @@ If no results are returned, this is a finding. CCI_REF CCI-001764 - Open + Not_Reviewed @@ -30955,7 +30955,7 @@ If no results are returned, this is a finding. CCI_REF CCI-001764 - Open + Not_Reviewed @@ -31078,7 +31078,7 @@ The audit daemon must be restarted for changes to take effect: CCI_REF CCI-001851 - Open + NotAFinding @@ -31213,7 +31213,7 @@ The audit daemon must be restarted for changes to take effect: CCI_REF CCI-001851 - Open + NotAFinding diff --git a/ci_testing_dummy_file b/ci_testing_dummy_file new file mode 100644 index 0000000..e69de29 diff --git a/disa_stig7/README.md b/disa_stig7/README.md index 4d9961c..e630f5c 100644 --- a/disa_stig7/README.md +++ b/disa_stig7/README.md @@ -2,8 +2,8 @@ This formula is created to enfofce the rhel/centos disa 7 stigs Has been tested on -* RHEL 7.4 -* CentOS 7.4 +* RHEL 7.6 +* CentOS 7.6 Required: diff --git a/disa_stig7/VERSION b/disa_stig7/VERSION index 890a1c1..5f8e42b 100644 --- a/disa_stig7/VERSION +++ b/disa_stig7/VERSION @@ -1 +1 @@ -Red Hat 7 STIG - Ver 1, Rel 4 +Red Hat 7 STIG - Ver 2, Rel 1 diff --git a/disa_stig7/cat2/aide.sls b/disa_stig7/cat2/aide.sls index ba13172..ec7e123 100644 --- a/disa_stig7/cat2/aide.sls +++ b/disa_stig7/cat2/aide.sls @@ -42,6 +42,13 @@ aide config settings DATAONLY: ^DATAONLY\s*=.+$ - repl: "DATAONLY = p+n+u+g+s+acl+selinux+xattrs+sha512\n" +aide config settings NORMAL: + file.replace: + - name: /etc/aide.conf + - pattern: | + ^NORMAL\s*=.+$ + - repl: "NORMAL = FIPSR+sha512\n" + # CAT2 # RHEL-07-020130 # RHEL-07-020140