-
Notifications
You must be signed in to change notification settings - Fork 764
Update RHEL 8 CIS profile #14269
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: master
Are you sure you want to change the base?
Update RHEL 8 CIS profile #14269
Conversation
ATEX Test ResultsTest artifacts have been submitted to Testing Farm. Results: View Test Results This comment was automatically generated by the ATEX workflow. |
7857e49 to
14b394a
Compare
|
@jan-cerny: The following test failed, say
Full PR test history. Your PR dashboard. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here. |
| dir_perms_world_writable_sticky_bits | ||
| disable_host_auth | ||
| disable_users_coredumps | ||
| enable_authselect |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Seems the workstation profiles are missing enable_authselect is that intentional?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The authselect situation is complicated for me. Currently I'm trying to learn about authselect and understand how it should work in CIS profiles. So far I found that in RHEL 8 we had enable_authselect but in RHEL 10 we don't. Moreover, authselect is somehow related to the fails in testing farm jobs that are reported by CI. The remediation in rule accounts_password_pam_pwhistory_use_authtok seems to be wrong and conflicts with authselect. I will try to fix it. The addition of enable_authselect to server profiles is an experiment and once it will be more clear I plan to consistently either add or remove it from all 4 profiles.
Update RHEL 8 CIS control file and profiles according to the version 4.0.0 of the RHEL 8 CIS Benchmark.
The remediations shouldn't update the /etc/pam.d/system-auth and /etc/pam.d/password-auth directly, it would conflict with authselect. The remediations need to update the authselect profile instead, and then let authselect to modify the files in /etc/pam.d/.
|
This PR is blocked by #14275 and will be rebased after that one is merged. |
Update RHEL 8 CIS control file and profiles according to the version 4.0.0 of the RHEL 8 CIS Benchmark.