Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-79123

Remediatin script for xccdf_org.ssgproject.content_rule_ensure_logrotate_activated does not take effect

Linking RHIVOS CVEs to...Migration: Automation ...SWIFT: POC ConversionSync from "Extern...XMLWordPrintable

    • scap-security-guide-0.1.79-1.el9
    • No
    • Low
    • rhel-security-compliance
    • ssg_security
    • 1
    • False
    • False
    • Hide

      None

      Show
      None
    • No
    • None
    • Unspecified Release Note Type - Unknown
    • Unspecified
    • Unspecified
    • Unspecified
    • x86_64
    • None

      What were you trying to do that didn't work?

      The remediation script is mean to set logrotation frequency to `daily` instead of the default `weekly`, but because of the location `daily` directive is inserted, it takes no effect.

      Also, it will create `/etc/cron.daily/logrotate` file, which is not necessary for RHEL 9+.

      What is the impact of this issue to you?

      The customer has to fix this for their 400+ systems.

      Please provide the package NVR for which the bug is seen:

      scap-security-guide-0.1.74-3.el8_10.noarch

      scap-security-guide-0.1.74-1.el9_4.noarch

      scap-security-guide-0.1.74-1.el10.noarch

      How reproducible is this bug?:

      Always

      Steps to reproduce

      1.  With the profile `xccdf_org.ssgproject.content_profile_pci-dss`, enable    `xccdf_org.ssgproject.content_rule_ensure_logrotate_activated` rule, and create a tailoring file.
      2. Using the tailoring file, evaluate a server.
      3. The result of the rule is returne `fail` with remediation scripts.
      4. Apply the remediation script

      Expected results

      daily
      rotate 4
      create
      dateext
      include /etc/logrotate.d

      Actual results

      rotate 4
      create
      dateext
      include /etc/logrotate.d
      daily

              vpolasek@redhat.com Vojtech Polasek
              rhn-engineering-kmoriguc Kenzo Moriguchi
              Vojtech Polasek Vojtech Polasek
              Matus Marhefka Matus Marhefka
              Votes:
              0 Vote for this issue
              Watchers:
              10 Start watching this issue

                Created:
                Updated:
                Resolved: