Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-102332

Rule "Ensure events that modify user/group information are collected" is partially implemented

Linking RHIVOS CVEs to...Migration: Automation ...SWIFT: POC ConversionSync from "Extern...XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Done-Errata
    • Icon: Undefined Undefined
    • rhel-9.6.z
    • rhel-9.6
    • scap-security-guide
    • None
    • scap-security-guide-0.1.78-1.el9
    • No
    • Low
    • rhel-security-compliance
    • 1
    • False
    • False
    • Hide

      None

      Show
      None
    • No
    • Red Hat Enterprise Linux
    • None
    • Unspecified Release Note Type - Unknown
    • Unspecified
    • Unspecified
    • Unspecified
    • None

      As per CIS_Red_Hat_Enterprise_Linux_9_Benchmark_v2.0.0 specification, "Ensure events that modify user/group information are collected" is supposed to check /etc/nsswitch.conf, /etc/pam.conf and /etc/pam.d.

      What is the reason for not having this yet?
      Is it due to needing to use -w ... audit rules which is deprecated and may lead to performance issues or just lack of time to do so?

              vpolasek@redhat.com Vojtech Polasek
              rhn-support-rmetrich Renaud Métrich
              Vojtech Polasek Vojtech Polasek
              Matus Marhefka Matus Marhefka
              Votes:
              0 Vote for this issue
              Watchers:
              7 Start watching this issue

                Created:
                Updated:
                Resolved: