Skip to content

Commit 12fdee1

Browse files
committed
Add rules to check sshd drop in permissions and ownership to 5.1.1
1 parent 7ebdd60 commit 12fdee1

File tree

5 files changed

+30
-0
lines changed

5 files changed

+30
-0
lines changed

controls/cis_rhel10.yml

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1583,6 +1583,12 @@ controls:
15831583
- file_groupowner_sshd_config
15841584
- file_owner_sshd_config
15851585
- file_permissions_sshd_config
1586+
- directory_permissions_sshd_config_d
1587+
- file_permissions_sshd_drop_in_config
1588+
- directory_groupowner_sshd_config_d
1589+
- directory_owner_sshd_config_d
1590+
- file_groupowner_sshd_drop_in_config
1591+
- file_owner_sshd_drop_in_config
15861592

15871593
- id: 5.1.2
15881594
title: Ensure access to SSH private host key files is configured (Automated)

tests/data/profile_stability/rhel10/cis.profile

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -124,6 +124,9 @@ dconf_gnome_screensaver_lock_delay
124124
dconf_gnome_screensaver_user_locks
125125
dconf_gnome_session_idle_user_locks
126126
dir_perms_world_writable_sticky_bits
127+
directory_groupowner_sshd_config_d
128+
directory_owner_sshd_config_d
129+
directory_permissions_sshd_config_d
127130
directory_permissions_var_log_audit
128131
disable_host_auth
129132
disable_users_coredumps
@@ -157,6 +160,7 @@ file_groupowner_etc_shadow
157160
file_groupowner_etc_shells
158161
file_groupowner_grub2_cfg
159162
file_groupowner_sshd_config
163+
file_groupowner_sshd_drop_in_config
160164
file_groupowner_user_cfg
161165
file_groupownership_audit_binaries
162166
file_groupownership_audit_configuration
@@ -184,6 +188,7 @@ file_owner_etc_shadow
184188
file_owner_etc_shells
185189
file_owner_grub2_cfg
186190
file_owner_sshd_config
191+
file_owner_sshd_drop_in_config
187192
file_owner_user_cfg
188193
file_ownership_audit_binaries
189194
file_ownership_audit_configuration
@@ -217,6 +222,7 @@ file_permissions_etc_shells
217222
file_permissions_grub2_cfg
218223
file_permissions_home_directories
219224
file_permissions_sshd_config
225+
file_permissions_sshd_drop_in_config
220226
file_permissions_sshd_private_key
221227
file_permissions_sshd_pub_key
222228
file_permissions_unauthorized_world_writable

tests/data/profile_stability/rhel10/cis_server_l1.profile

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -56,6 +56,9 @@ dconf_gnome_screensaver_lock_delay
5656
dconf_gnome_screensaver_user_locks
5757
dconf_gnome_session_idle_user_locks
5858
dir_perms_world_writable_sticky_bits
59+
directory_groupowner_sshd_config_d
60+
directory_owner_sshd_config_d
61+
directory_permissions_sshd_config_d
5962
disable_host_auth
6063
disable_users_coredumps
6164
ensure_gpgcheck_globally_activated
@@ -87,6 +90,7 @@ file_groupowner_etc_shadow
8790
file_groupowner_etc_shells
8891
file_groupowner_grub2_cfg
8992
file_groupowner_sshd_config
93+
file_groupowner_sshd_drop_in_config
9094
file_groupowner_user_cfg
9195
file_groupownership_sshd_private_key
9296
file_groupownership_sshd_pub_key
@@ -112,6 +116,7 @@ file_owner_etc_shadow
112116
file_owner_etc_shells
113117
file_owner_grub2_cfg
114118
file_owner_sshd_config
119+
file_owner_sshd_drop_in_config
115120
file_owner_user_cfg
116121
file_ownership_home_directories
117122
file_ownership_sshd_private_key
@@ -140,6 +145,7 @@ file_permissions_etc_shells
140145
file_permissions_grub2_cfg
141146
file_permissions_home_directories
142147
file_permissions_sshd_config
148+
file_permissions_sshd_drop_in_config
143149
file_permissions_sshd_private_key
144150
file_permissions_sshd_pub_key
145151
file_permissions_unauthorized_world_writable

tests/data/profile_stability/rhel10/cis_workstation_l1.profile

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -54,6 +54,9 @@ dconf_gnome_screensaver_lock_delay
5454
dconf_gnome_screensaver_user_locks
5555
dconf_gnome_session_idle_user_locks
5656
dir_perms_world_writable_sticky_bits
57+
directory_groupowner_sshd_config_d
58+
directory_owner_sshd_config_d
59+
directory_permissions_sshd_config_d
5760
disable_host_auth
5861
disable_users_coredumps
5962
ensure_gpgcheck_globally_activated
@@ -85,6 +88,7 @@ file_groupowner_etc_shadow
8588
file_groupowner_etc_shells
8689
file_groupowner_grub2_cfg
8790
file_groupowner_sshd_config
91+
file_groupowner_sshd_drop_in_config
8892
file_groupowner_user_cfg
8993
file_groupownership_sshd_private_key
9094
file_groupownership_sshd_pub_key
@@ -110,6 +114,7 @@ file_owner_etc_shadow
110114
file_owner_etc_shells
111115
file_owner_grub2_cfg
112116
file_owner_sshd_config
117+
file_owner_sshd_drop_in_config
113118
file_owner_user_cfg
114119
file_ownership_home_directories
115120
file_ownership_sshd_private_key
@@ -138,6 +143,7 @@ file_permissions_etc_shells
138143
file_permissions_grub2_cfg
139144
file_permissions_home_directories
140145
file_permissions_sshd_config
146+
file_permissions_sshd_drop_in_config
141147
file_permissions_sshd_private_key
142148
file_permissions_sshd_pub_key
143149
file_permissions_unauthorized_world_writable

tests/data/profile_stability/rhel10/cis_workstation_l2.profile

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -124,6 +124,9 @@ dconf_gnome_screensaver_lock_delay
124124
dconf_gnome_screensaver_user_locks
125125
dconf_gnome_session_idle_user_locks
126126
dir_perms_world_writable_sticky_bits
127+
directory_groupowner_sshd_config_d
128+
directory_owner_sshd_config_d
129+
directory_permissions_sshd_config_d
127130
directory_permissions_var_log_audit
128131
disable_host_auth
129132
disable_users_coredumps
@@ -157,6 +160,7 @@ file_groupowner_etc_shadow
157160
file_groupowner_etc_shells
158161
file_groupowner_grub2_cfg
159162
file_groupowner_sshd_config
163+
file_groupowner_sshd_drop_in_config
160164
file_groupowner_user_cfg
161165
file_groupownership_audit_binaries
162166
file_groupownership_audit_configuration
@@ -184,6 +188,7 @@ file_owner_etc_shadow
184188
file_owner_etc_shells
185189
file_owner_grub2_cfg
186190
file_owner_sshd_config
191+
file_owner_sshd_drop_in_config
187192
file_owner_user_cfg
188193
file_ownership_audit_binaries
189194
file_ownership_audit_configuration
@@ -217,6 +222,7 @@ file_permissions_etc_shells
217222
file_permissions_grub2_cfg
218223
file_permissions_home_directories
219224
file_permissions_sshd_config
225+
file_permissions_sshd_drop_in_config
220226
file_permissions_sshd_private_key
221227
file_permissions_sshd_pub_key
222228
file_permissions_unauthorized_world_writable

0 commit comments

Comments
 (0)