Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-11938

Rule audit_rules_privileged_commands results in "fixed" -> "fail"

    • sst_security_compliance
    • ssg_security
    • None
    • False
    • Hide

      None

      Show
      None
    • No
    • None
    • None

      Description of problem:
      On ppc64le architecture, audit_rules_privileged_commands rule fails after ANSSI NT28 High profile remediation.
      The rule is "fixed" during remediation run, but during final scan (oscap scan after "oscap xccdf eval --remediate") the rule fails.

      Version-Release number of selected component (if applicable):
      scap-security-guide-0.1.69-1.el7_9

      How reproducible:
      100%

      Steps to Reproduce:
      1. oscap xccdf eval --profile xccdf_org.ssgproject.content_profile_anssi_nt28_high --progress --remediate --report remediation.html /usr/share/xml/scap/ssg/content/ssg-rhel7-ds.xml
      2. Reboot
      3. oscap xccdf eval --rule xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands --progress --report report.html --results results.xml --oval-results

      Actual results:
      xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands:fail

      Expected results:
      xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands:pass

      Additional info:
      Might be ordering problem connected to package_sendmail_removed rule:
      1. audit_rules_privileged_commands is remediated (fixed)
      2. package_sendmail_removed is remediated and that affects audit_rules_privileged_commands
      3. audit_rules_privileged_commands fails

      Only ppc64le is affected. Other archs are ok.

            maburgha@redhat.com Marcus Burghardt
            mlysonek@redhat.com Milan Lysonek
            Marcus Burghardt Marcus Burghardt
            Milan Lysonek Milan Lysonek
            Votes:
            0 Vote for this issue
            Watchers:
            11 Start watching this issue

              Created:
              Updated:
              Resolved: