-
Notifications
You must be signed in to change notification settings - Fork 686
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Align RHEL 7 CIS control file with CIS v4.0.0 - Section 6 #11452
Align RHEL 7 CIS control file with CIS v4.0.0 - Section 6 #11452
Conversation
Skipping CI for Draft Pull Request. |
/packit retest-failed |
1 similar comment
/packit retest-failed |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Hello and thank you for the update. Looks quite good, but please see my comments.
controls/cis_rhel7.yml
Outdated
- file_groupowner_backup_etc_group | ||
- file_owner_backup_etc_group | ||
- file_permissions_backup_etc_group | ||
status: partial |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Why partial status when we don't have the rule at all?
591d05d
to
d2a0bb5
Compare
The CI fail on Rawhide is caused by aio-libs/multidict#926 and isn't related to the pull request. |
I have rebased this PR on the top of the latest upstream master branch. |
/packit retest-failed |
Use accounts_users_netrc_file_permissions instead of no_netrc_files to better align with the CIS Benchmark.
The rule accounts_user_dot_no_world_writable_programs is not aligned with the policy requirement, it checks permissions of files executed by the dot files. Also, we should clarify the situation about remediation of .forward and .rhost files.
52b2313
to
a2c8a2c
Compare
I have rebased this PR on the top of the latest upstream master branch. I have add rules related to |
Code Climate has analyzed commit a2c8a2c and detected 0 issues on this pull request. The test coverage on the diff in this pull request is 100.0% (50% is the threshold). This pull request will bring the total coverage in the repository to 58.5% (0.0% change). View more on Code Climate. |
/packit retest-failed |
Hello @jan-cerny and thank you for updates to this PR. I think the PR is ready to be merged, let's just wait for CI. |
/packit retest-failed |
The failing build on RAwhide is not caused by this PR, it caused by problem in Rawhide. This PR does not touch rules related to k8s so I am merging it. |
Description:
In this PR, we change the control file, change references, add existing rules. But, we don't add new rules, and we don't modify other content.
Rationale:
Align RHEL 7 CIS control file with CIS v4.0.0