-
Bug
-
Resolution: Done-Errata
-
Undefined
-
rhel-9.6
-
None
-
scap-security-guide-0.1.78-1.el9
-
No
-
Low
-
rhel-security-compliance
-
1
-
False
-
False
-
-
No
-
Red Hat Enterprise Linux
-
None
-
Unspecified Release Note Type - Unknown
-
Unspecified
-
Unspecified
-
Unspecified
-
None
As per CIS_Red_Hat_Enterprise_Linux_9_Benchmark_v2.0.0 specification, "Ensure events that modify user/group information are collected" is supposed to check /etc/nsswitch.conf, /etc/pam.conf and /etc/pam.d.
What is the reason for not having this yet?
Is it due to needing to use -w ... audit rules which is deprecated and may lead to performance issues or just lack of time to do so?