Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-1814

When applying DISA STIG Profile it either automatically change the pool or recommend the person implementing the stig policy to use it.

    • scap-security-guide-0.1.73-1.el8_10
    • sst_security_compliance
    • ssg_security
    • 2
    • False
    • Hide

      None

      Show
      None
    • No
    • None
    • Hide

      PTP: Manually check on a system hardened to STIG profile that the default server pool for /etc/chrony.conf contains only "0.us.pool.ntp.mil". For example by looking at generated HTML report from /hardening/anaconda/stig test, rule chronyd_specify_remote_server should contain the value for NTP server found in /etc/chrony.conf. Alternatively, reserve a system and harden it to STIG manually, then check that /etc/chrony.conf only contains "server 0.us.pool.ntp.mil":

      grep -i server /etc/chrony.conf
      server 0.us.pool.ntp.mil
      
      Show
      PTP: Manually check on a system hardened to STIG profile that the default server pool for /etc/chrony.conf contains only "0.us.pool.ntp.mil". For example by looking at generated HTML report from /hardening/anaconda/stig test, rule chronyd_specify_remote_server should contain the value for NTP server found in /etc/chrony.conf. Alternatively, reserve a system and harden it to STIG manually, then check that /etc/chrony.conf only contains "server 0.us.pool.ntp.mil": grep -i server /etc/chrony.conf server 0.us.pool.ntp.mil
    • Pass
    • None
    • None

      Description of problem:

      When applying DISA STIG Profile it either automatically change the pool or recommend the person implementing the stig policy to use it.

      Version-Release number of selected component (if applicable):

      RHEL 8.0

      How reproducible:

      Very.

      Steps to Reproduce:
      1. Stop Chrony Service

      2. Apply DISA STIG profile.

      3. Chrony configuration still contains NTP pools host names, which casuses synchronizing to server outside of the US.

      Actual results:

      This causes problems because our systems may (and have) randomly select time sources from Russia, Iran, China and other nations.

      Expected results:

      Only use the us.pool.ntp.org

      Additional info:

            maburgha@redhat.com Marcus Burghardt
            rhn-support-jfaison Joshua Faison (Inactive)
            Marcus Burghardt Marcus Burghardt
            Milan Lysonek Milan Lysonek
            Votes:
            0 Vote for this issue
            Watchers:
            11 Start watching this issue

              Created:
              Updated:
              Resolved: