Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

RHEL9 ISM O - Rules missing ism reference #12427

Open
mildas opened this issue Sep 25, 2024 · 0 comments
Open

RHEL9 ISM O - Rules missing ism reference #12427

mildas opened this issue Sep 25, 2024 · 0 comments
Labels
RHEL9 Red Hat Enterprise Linux 9 product related.

Comments

@mildas
Copy link
Contributor

mildas commented Sep 25, 2024

Description of problem:

A lot of ISM O rules doesn't have ism reference. The list of affected rules:

  • rpm_verify_hashes
  • dir_perms_world_writable_sticky_bits
  • sysctl_kernel_kptr_restrict
  • service_telnet_disabled
  • network_sniffer_disabled
  • package_firewalld_installed
  • audit_rules_execution_setfiles
  • file_ownership_binary_dirs
  • audit_rules_execution_setsebool
  • configure_ssh_crypto_policy
  • sshd_enable_warning_banner
  • package_telnet-server_removed
  • ensure_gpgcheck_globally_activated
  • package_quagga_removed
  • sysctl_kernel_kexec_load_disabled
  • file_permissions_sshd_private_key
  • auditd_log_format
  • package_talk-server_removed
  • sshd_disable_root_login
  • package_fapolicyd_installed
  • package_rsh_removed
  • audit_rules_time_adjtimex
  • audit_rules_login_events
  • sysctl_kernel_dmesg_restrict
  • usbguard_allow_hid_and_hub
  • file_ownership_library_dirs
  • mount_option_dev_shm_nosuid
  • package_rear_installed
  • auditd_data_retention_flush
  • audit_rules_dac_modification_chmod
  • sshd_disable_rhosts
  • file_permissions_library_dirs
  • sshd_print_last_log
  • auditd_freq
  • audit_rules_time_clock_settime
  • audit_rules_execution_semanage
  • package_rsyslog_installed
  • audit_rules_execution_seunshare
  • rpm_verify_ownership
  • rpm_verify_permissions
  • sysctl_kernel_exec_shield
  • sshd_set_loglevel_info
  • package_talk_removed
  • accounts_no_uid_except_zero
  • sshd_use_directory_configuration
  • auditd_local_events
  • package_squid_removed
  • ensure_gpgcheck_local_packages
  • audit_rules_kernel_module_loading
  • audit_rules_login_events_faillock
  • auditd_write_logs
  • sysctl_kernel_yama_ptrace_scope
  • file_permissions_unauthorized_suid
  • service_avahi-daemon_disabled
  • service_fapolicyd_enabled
  • ensure_redhat_gpgkey_installed
  • sudo_remove_nopasswd
  • sshd_disable_empty_passwords
  • audit_rules_execution_chcon
  • audit_rules_login_events_tallylog
  • audit_rules_usergroup_modification
  • sshd_disable_x11_forwarding
  • sshd_enable_strictmodes
  • audit_rules_execution_restorecon
  • auditd_name_format
  • file_permissions_unauthorized_world_writable
  • audit_rules_time_stime
  • package_ypbind_removed
  • sysctl_net_core_bpf_jit_harden
  • sysctl_kernel_unprivileged_bpf_disabled
  • package_rsh-server_removed
  • file_permissions_unauthorized_sgid
  • selinux_policytype
  • security_patches_up_to_date
  • audit_rules_dac_modification_chown
  • audit_rules_time_settimeofday
  • enable_authselect
  • sshd_disable_user_known_hosts
  • selinux_state
  • service_auditd_enabled
  • file_permissions_binary_dirs
  • service_rsyslog_enabled
  • ensure_gpgcheck_never_disabled
  • sudo_require_authentication
  • audit_rules_login_events_lastlog
  • audit_rules_sysadmin_actions
  • mount_option_dev_shm_noexec
  • service_squid_disabled
  • service_firewalld_enabled
  • sshd_do_not_permit_user_env
  • dnf-automatic_security_updates_only
  • package_telnet_removed
  • no_empty_passwords
  • mount_option_dev_shm_nodev
  • audit_rules_time_watch_localtime
  • sysctl_kernel_randomize_va_space
  • sudo_remove_no_authenticate
  • audit_rules_networkconfig_modification

SCAP Security Guide Version:

master

Operating System Version:

RHEL9

@mildas mildas added the RHEL9 Red Hat Enterprise Linux 9 product related. label Sep 25, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
RHEL9 Red Hat Enterprise Linux 9 product related.
Projects
None yet
Development

No branches or pull requests

1 participant