Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-130498

Missing CIS Rule “5.1.2.6 Ensure journald log rotation is configured per site policy" (CIS Server Level 1 v3.0.0 profile)

Linking RHIVOS CVEs to...Migration: Automation ...SWIFT: POC ConversionSync from "Extern...XMLWordPrintable

    • None
    • Low
    • rhel-security-compliance
    • None
    • False
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • None
    • None
    • Unspecified
    • Unspecified
    • Unspecified
    • None

      What were you trying to do that didn't work?

      Performing a CIS Level 1 compliance scan on RHEL 8 servers using the CIS profile xccdf_org.ssgproject.content_profile_cis_server_l1
      The scan did not include or evaluate below CIS Benchmark rule.

      5.1.2.6 – Ensure journald log rotation is configured per site policy{}{}

       

      Even though this rule exists in the official CIS RHEL 8 Benchmark v3.0.0.

      The rule appears to be missing from the ssg-rhel8-ds.xml content.

      Please provide the package NVR for which the bug is seen:

       

      latest version of scap-security-guide on RHEL 8.10 

      How reproducible is this bug?:

      Always

      Steps to reproduce

      1. Install the latest scap-security-guide on RHEL 8:
      2. Verify it's content.
      3. Run a scan against CIS Level 1
      4. Review the generated report — there is no entry corresponding to CIS rule 5.1.2.6

      Expected results

      The SCAP content should include the rule “ 5.1.2.6 – Ensure journald log rotation is configured per site policy”  so that oscap can evaluate it per the CIS v3.0.0 benchmark.

              vpolasek@redhat.com Vojtech Polasek
              rhn-support-vshastri Vaishnavi Shastri
              Vojtech Polasek Vojtech Polasek
              SSG Security QE SSG Security QE
              Votes:
              1 Vote for this issue
              Watchers:
              7 Start watching this issue

                Created:
                Updated:
                Resolved: