-
Bug
-
Resolution: Done-Errata
-
Undefined
-
rhel-7.9.z
-
None
-
None
-
rhel-sst-security-compliance
-
ssg_security
-
None
-
False
-
-
No
-
None
-
Pass
-
None
-
-
Unspecified
-
None
Description of problem:
On ppc64le architecture, audit_rules_privileged_commands rule fails after ANSSI NT28 High profile remediation.
The rule is "fixed" during remediation run, but during final scan (oscap scan after "oscap xccdf eval --remediate") the rule fails.
Version-Release number of selected component (if applicable):
scap-security-guide-0.1.69-1.el7_9
How reproducible:
100%
Steps to Reproduce:
1. oscap xccdf eval --profile xccdf_org.ssgproject.content_profile_anssi_nt28_high --progress --remediate --report remediation.html /usr/share/xml/scap/ssg/content/ssg-rhel7-ds.xml
2. Reboot
3. oscap xccdf eval --rule xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands --progress --report report.html --results results.xml --oval-results
Actual results:
xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands:fail
Expected results:
xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands:pass
Additional info:
Might be ordering problem connected to package_sendmail_removed rule:
1. audit_rules_privileged_commands is remediated (fixed)
2. package_sendmail_removed is remediated and that affects audit_rules_privileged_commands
3. audit_rules_privileged_commands fails
Only ppc64le is affected. Other archs are ok.
- external trackers
- links to
-
RHBA-2024:128049 scap-security-guide bug fix and enhancement update