Skip to content

Commit f0c0f93

Browse files
committed
Add rules to check sshd drop in permissions to 5.1.1
1 parent 7ebdd60 commit f0c0f93

File tree

5 files changed

+10
-0
lines changed

5 files changed

+10
-0
lines changed

controls/cis_rhel10.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1583,6 +1583,8 @@ controls:
15831583
- file_groupowner_sshd_config
15841584
- file_owner_sshd_config
15851585
- file_permissions_sshd_config
1586+
- directory_permissions_sshd_config_d
1587+
- file_permissions_sshd_drop_in_config
15861588

15871589
- id: 5.1.2
15881590
title: Ensure access to SSH private host key files is configured (Automated)

tests/data/profile_stability/rhel10/cis.profile

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -124,6 +124,7 @@ dconf_gnome_screensaver_lock_delay
124124
dconf_gnome_screensaver_user_locks
125125
dconf_gnome_session_idle_user_locks
126126
dir_perms_world_writable_sticky_bits
127+
directory_permissions_sshd_config_d
127128
directory_permissions_var_log_audit
128129
disable_host_auth
129130
disable_users_coredumps
@@ -217,6 +218,7 @@ file_permissions_etc_shells
217218
file_permissions_grub2_cfg
218219
file_permissions_home_directories
219220
file_permissions_sshd_config
221+
file_permissions_sshd_drop_in_config
220222
file_permissions_sshd_private_key
221223
file_permissions_sshd_pub_key
222224
file_permissions_unauthorized_world_writable

tests/data/profile_stability/rhel10/cis_server_l1.profile

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -56,6 +56,7 @@ dconf_gnome_screensaver_lock_delay
5656
dconf_gnome_screensaver_user_locks
5757
dconf_gnome_session_idle_user_locks
5858
dir_perms_world_writable_sticky_bits
59+
directory_permissions_sshd_config_d
5960
disable_host_auth
6061
disable_users_coredumps
6162
ensure_gpgcheck_globally_activated
@@ -140,6 +141,7 @@ file_permissions_etc_shells
140141
file_permissions_grub2_cfg
141142
file_permissions_home_directories
142143
file_permissions_sshd_config
144+
file_permissions_sshd_drop_in_config
143145
file_permissions_sshd_private_key
144146
file_permissions_sshd_pub_key
145147
file_permissions_unauthorized_world_writable

tests/data/profile_stability/rhel10/cis_workstation_l1.profile

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -54,6 +54,7 @@ dconf_gnome_screensaver_lock_delay
5454
dconf_gnome_screensaver_user_locks
5555
dconf_gnome_session_idle_user_locks
5656
dir_perms_world_writable_sticky_bits
57+
directory_permissions_sshd_config_d
5758
disable_host_auth
5859
disable_users_coredumps
5960
ensure_gpgcheck_globally_activated
@@ -138,6 +139,7 @@ file_permissions_etc_shells
138139
file_permissions_grub2_cfg
139140
file_permissions_home_directories
140141
file_permissions_sshd_config
142+
file_permissions_sshd_drop_in_config
141143
file_permissions_sshd_private_key
142144
file_permissions_sshd_pub_key
143145
file_permissions_unauthorized_world_writable

tests/data/profile_stability/rhel10/cis_workstation_l2.profile

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -124,6 +124,7 @@ dconf_gnome_screensaver_lock_delay
124124
dconf_gnome_screensaver_user_locks
125125
dconf_gnome_session_idle_user_locks
126126
dir_perms_world_writable_sticky_bits
127+
directory_permissions_sshd_config_d
127128
directory_permissions_var_log_audit
128129
disable_host_auth
129130
disable_users_coredumps
@@ -217,6 +218,7 @@ file_permissions_etc_shells
217218
file_permissions_grub2_cfg
218219
file_permissions_home_directories
219220
file_permissions_sshd_config
221+
file_permissions_sshd_drop_in_config
220222
file_permissions_sshd_private_key
221223
file_permissions_sshd_pub_key
222224
file_permissions_unauthorized_world_writable

0 commit comments

Comments
 (0)