Skip to content

Commit 042b66a

Browse files
committed
Add rules to RHEL 10 CIS 7.1.10
To better cover the control
1 parent 7ebdd60 commit 042b66a

File tree

12 files changed

+36
-11
lines changed

12 files changed

+36
-11
lines changed

controls/cis_rhel10.yml

Lines changed: 6 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3166,7 +3166,12 @@ controls:
31663166
- l1_workstation
31673167
status: automated
31683168
rules:
3169-
- file_etc_security_opasswd
3169+
- file_groupowner_etc_security_opasswd
3170+
- file_owner_etc_security_opasswd
3171+
- file_permissions_etc_security_opasswd
3172+
- file_groupowner_etc_security_opasswd_old
3173+
- file_owner_etc_security_opasswd_old
3174+
- file_permissions_etc_security_opasswd_old
31703175

31713176
- id: 7.1.11
31723177
title: Ensure world writable files and directories are secured (Automated)

linux_os/guide/system/permissions/files/permissions_important_account_files/file_groupowner_etc_security_opasswd/rule.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -11,6 +11,7 @@ rationale: |-
1111
severity: medium
1212

1313
identifiers:
14+
cce@rhel10: CCE-90453-2
1415
cce@sle15: CCE-92539-6
1516

1617
ocil_clause: '{{{ ocil_clause_file_group_owner(file="/etc/security/opasswd", group="root") }}}'

linux_os/guide/system/permissions/files/permissions_important_account_files/file_groupowner_etc_security_opasswd_old/rule.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -11,6 +11,7 @@ rationale: |-
1111
severity: medium
1212

1313
identifiers:
14+
cce@rhel10: CCE-89419-6
1415
cce@sle15: CCE-92540-4
1516

1617
ocil_clause: '{{{ ocil_clause_file_group_owner(file="/etc/security/opasswd.old", group="root") }}}'

linux_os/guide/system/permissions/files/permissions_important_account_files/file_owner_etc_security_opasswd/rule.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -11,6 +11,7 @@ rationale: |-
1111
severity: medium
1212

1313
identifiers:
14+
cce@rhel10: CCE-86791-1
1415
cce@sle15: CCE-92545-3
1516

1617
ocil_clause: '{{{ ocil_clause_file_owner(file="/etc/security/opasswd", owner="root") }}}'

linux_os/guide/system/permissions/files/permissions_important_account_files/file_owner_etc_security_opasswd_old/rule.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -11,6 +11,7 @@ rationale: |-
1111
severity: medium
1212

1313
identifiers:
14+
cce@rhel10: CCE-88528-5
1415
cce@sle15: CCE-92546-1
1516

1617
ocil_clause: '{{{ ocil_clause_file_owner(file="/etc/security/opasswd.old", owner="root") }}}'

linux_os/guide/system/permissions/files/permissions_important_account_files/file_permissions_etc_security_opasswd/rule.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -12,6 +12,7 @@ rationale: |-
1212
severity: medium
1313

1414
identifiers:
15+
cce@rhel10: CCE-89580-5
1516
cce@sle15: CCE-92558-6
1617

1718
ocil_clause: '{{{ ocil_clause_file_permissions(file="/etc/security/opasswd", perms="0600") }}}'

linux_os/guide/system/permissions/files/permissions_important_account_files/file_permissions_etc_security_opasswd_old/rule.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -12,6 +12,7 @@ rationale: |-
1212
severity: medium
1313

1414
identifiers:
15+
cce@rhel10: CCE-87434-7
1516
cce@sle15: CCE-92559-4
1617

1718
ocil_clause: '{{{ ocil_clause_file_permissions(file="/etc/security/opasswd.old", perms="0600") }}}'

shared/references/cce-redhat-avail.txt

Lines changed: 0 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -101,7 +101,6 @@ CCE-86785-3
101101
CCE-86788-7
102102
CCE-86789-5
103103
CCE-86790-3
104-
CCE-86791-1
105104
CCE-86793-7
106105
CCE-86795-2
107106
CCE-86796-0
@@ -442,7 +441,6 @@ CCE-87426-3
442441
CCE-87427-1
443442
CCE-87431-3
444443
CCE-87432-1
445-
CCE-87434-7
446444
CCE-87435-4
447445
CCE-87436-2
448446
CCE-87437-0
@@ -1108,7 +1106,6 @@ CCE-88522-8
11081106
CCE-88525-1
11091107
CCE-88526-9
11101108
CCE-88527-7
1111-
CCE-88528-5
11121109
CCE-88530-1
11131110
CCE-88531-9
11141111
CCE-88532-7
@@ -1628,7 +1625,6 @@ CCE-89413-9
16281625
CCE-89415-4
16291626
CCE-89416-2
16301627
CCE-89417-0
1631-
CCE-89419-6
16321628
CCE-89420-4
16331629
CCE-89421-2
16341630
CCE-89422-0
@@ -1722,7 +1718,6 @@ CCE-89576-3
17221718
CCE-89577-1
17231719
CCE-89578-9
17241720
CCE-89579-7
1725-
CCE-89580-5
17261721
CCE-89582-1
17271722
CCE-89583-9
17281723
CCE-89584-7
@@ -2305,7 +2300,6 @@ CCE-90446-6
23052300
CCE-90447-4
23062301
CCE-90448-2
23072302
CCE-90452-4
2308-
CCE-90453-2
23092303
CCE-90454-0
23102304
CCE-90455-7
23112305
CCE-90457-3

tests/data/profile_stability/rhel10/cis.profile

Lines changed: 6 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -133,7 +133,6 @@ ensure_root_password_configured
133133
file_at_deny_not_exist
134134
file_cron_allow_exists
135135
file_cron_deny_not_exist
136-
file_etc_security_opasswd
137136
file_group_ownership_var_log_audit
138137
file_groupowner_at_allow
139138
file_groupowner_backup_etc_group
@@ -153,6 +152,8 @@ file_groupowner_etc_issue
153152
file_groupowner_etc_issue_net
154153
file_groupowner_etc_motd
155154
file_groupowner_etc_passwd
155+
file_groupowner_etc_security_opasswd
156+
file_groupowner_etc_security_opasswd_old
156157
file_groupowner_etc_shadow
157158
file_groupowner_etc_shells
158159
file_groupowner_grub2_cfg
@@ -180,6 +181,8 @@ file_owner_etc_issue
180181
file_owner_etc_issue_net
181182
file_owner_etc_motd
182183
file_owner_etc_passwd
184+
file_owner_etc_security_opasswd
185+
file_owner_etc_security_opasswd_old
183186
file_owner_etc_shadow
184187
file_owner_etc_shells
185188
file_owner_grub2_cfg
@@ -212,6 +215,8 @@ file_permissions_etc_issue
212215
file_permissions_etc_issue_net
213216
file_permissions_etc_motd
214217
file_permissions_etc_passwd
218+
file_permissions_etc_security_opasswd
219+
file_permissions_etc_security_opasswd_old
215220
file_permissions_etc_shadow
216221
file_permissions_etc_shells
217222
file_permissions_grub2_cfg

tests/data/profile_stability/rhel10/cis_server_l1.profile

Lines changed: 6 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -64,7 +64,6 @@ ensure_root_password_configured
6464
file_at_deny_not_exist
6565
file_cron_allow_exists
6666
file_cron_deny_not_exist
67-
file_etc_security_opasswd
6867
file_groupowner_at_allow
6968
file_groupowner_backup_etc_group
7069
file_groupowner_backup_etc_gshadow
@@ -83,6 +82,8 @@ file_groupowner_etc_issue
8382
file_groupowner_etc_issue_net
8483
file_groupowner_etc_motd
8584
file_groupowner_etc_passwd
85+
file_groupowner_etc_security_opasswd
86+
file_groupowner_etc_security_opasswd_old
8687
file_groupowner_etc_shadow
8788
file_groupowner_etc_shells
8889
file_groupowner_grub2_cfg
@@ -108,6 +109,8 @@ file_owner_etc_issue
108109
file_owner_etc_issue_net
109110
file_owner_etc_motd
110111
file_owner_etc_passwd
112+
file_owner_etc_security_opasswd
113+
file_owner_etc_security_opasswd_old
111114
file_owner_etc_shadow
112115
file_owner_etc_shells
113116
file_owner_grub2_cfg
@@ -135,6 +138,8 @@ file_permissions_etc_issue
135138
file_permissions_etc_issue_net
136139
file_permissions_etc_motd
137140
file_permissions_etc_passwd
141+
file_permissions_etc_security_opasswd
142+
file_permissions_etc_security_opasswd_old
138143
file_permissions_etc_shadow
139144
file_permissions_etc_shells
140145
file_permissions_grub2_cfg

0 commit comments

Comments
 (0)