Marcus Burghardt
Marcus Burghardt
Already covered by `rsyslog_files_permissions` rule.
This requirement is outdated. In addition, there is already rules for `firewalld` and `nftables` packages.
https://github.com/ComplianceAsCode/content/pull/9789 and https://github.com/ComplianceAsCode/content/pull/10139 recently improved the rsyslog rules. They are aligned to the benchmark requirements.
I didn't receive any answer from @maage for some time. However, I liked the changes he proposed here. If there is no objection until tomorrow, I will merge his PR...
/packit retest-failed
This PR was closed in favor of #10026 . The #10026 is a rebase of this PR plus some additional improvements.
For registry, I liked this suggested approach. Based on this draft, it is already clear the improvements in readability. Also, in long-term this would be much easier to be maintained....
Although this idea is interesting, the PR is quite outdated and seems that a considerable work is still necessary. Unfortunately, there is no more interaction from the author for months....
The relevant rule is `sshd_disable_compression`. I will take a look on it.
I researched about this and didn't find any ordering restriction for the `Compression` line. We can simply remove the `insertbefore: ^[#\s]*Match` line. @ggbecker , do you know why this `insertbefore:...