Uploaded image for project: 'OpenShift Bugs'
  1. OpenShift Bugs
  2. OCPBUGS-77901

Validation of Compliance Operator DISA-STIG profiles on P Fails

    • None
    • False
    • Hide

      None

      Show
      None
    • None
    • Moderate
    • None
    • ppc64le
    • None
    • None
    • Proposed
    • None
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      Description of problem:

      Hi Team,
      I’m seeing a failure in the DISA STIG compliance automation (ocp4-playbooks-extras).After running the playbook, the scan rhcos4-disa-stig-stig-worker finishes as NON-COMPLIANT.Failed rule: service-usbguard-enabledManual verification on worker nodes shows usbguard is disabled/inactive.I created a MachineConfig to enable usbguard and rescanned, but the scan is still NON-COMPLIANT.

      Version-Release number of selected component (if applicable):

          4.22

      How reproducible:

         this automation worked well and fine previously

      Steps to Reproduce:

      1. clone ocp4-playbooks-extras and change to directory ocp4-playbooks-extras 
      2. Copy ocp4-playbooks-extras/examples/inventory file and ocp4-playbooks-extras/examples/ocp_disa_stig_vars.yaml to current directory    
      3. run this command ansible-playbook -i inventory -e @ocp_disa_stig_vars.yaml ~/ocp4-playbooks-extras/playbooks/ocp-disa-stig-compliance.yml     

      Actual results:

           Execution of the playbook without failure marks successful validation.

      Expected results:

          automation is failing when rhcos4-disa-stig validation at last step where it is checking scan result task

      Additional info:

          tried manually still its failing 

              ocp-docs-bot OCP DocsBot
              psadhana Pavan Sadhana
              Xiaojie Yuan Xiaojie Yuan
              None
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

                Created:
                Updated:
                Resolved: