-
Bug
-
Resolution: Won't Do
-
Undefined
-
None
-
rhel-8.6.0
-
None
-
Moderate
-
rhel-sst-security-compliance
-
ssg_security
-
None
-
False
-
-
Yes
-
None
-
None
-
None
-
Known Issue
-
-
Done
-
-
Unspecified
-
None
Description of problem:
There are two SCAP rules in the datastream shipped in RHEL 8.6 which can configure the system to terminate idle sessions after certain time has passed.
Rules are logind_session_timeout and sshd_set_idle_timeout.
None of those rules unfortunately work properly in RHEL 8.6 and therefore they are restricted by CPE platforms. Both rules will result in "not applicable". The reason is that the SSH feature used by sshd_set_idle_timeout was never meaned to be used in this way and it is not producing desired behavior in 8.6. The patch which enables usage of Logind to terinate idle sessions is not backported into 8.6 as of the time of this comment.
Version-Release number of selected component (if applicable):
scap-security-guide-0.1.66 in RHEL 8.6 (the package has not been built yet)
How reproducible:
always
Steps to Reproduce:
1. oscap xccdf eval --profile '(all)' --rule xccdf_org.ssgproject.content_rule_logind_session_timeout /usr/share/xml/scap/ssg/content/ssg-rhel8-ds.xml
2. oscap xccdf eval --profile '(all)' --rule xccdf_org.ssgproject.content_rule_sshd_set_idle_timeout /usr/share/xml/scap/ssg/content/ssg-rhel8-ds.xml
Actual results:
Both rules report "not applicable"
Expected results:
Ideally the rule logind_session_timeout should be applicable as soon as the correct functionality gets backported into 8.6.
Additional info:
- external trackers