content icon indicating copy to clipboard operation
content copied to clipboard

file_permission_user_init_files_root is misaligned with DISA

Open jan-cerny opened this issue 11 months ago • 0 comments

Description of problem:

On 2025-02-12, the daily productization run shows the following fails on RHEL 8.10:

  • /scanning/disa-alignment/ansible/file_permission_user_init_files_root
  • /scanning/disa-alignment/oscap/file_permission_user_init_files_root

The content is misaligned with an external (third party) content that targets the same policy - typically, this means that a system hardened by our content doesn't pass the scan by the external content.

Details:

Our rule file_permission_user_init_files_root passed Their rule SV-230325r1017136_rule failed because it didn't file any file in / matching ^\.[^\s\.]+.

There was a ticket about this rule but for RHEL 9, but the ticket is now closed: https://github.com/ComplianceAsCode/content/issues/11778

Outcome:

  • [ ] This project's content can be improved:
    • [ ] Check needs to be improved.
    • [ ] Remediation needs to be improved.
  • [ ] The external content's check is faulty - the other party needs to be notified, they have work to do.

SCAP Security Guide Version:

current upstream master as of 2025-02-12 as of HEAD 0f151a1b78273764df0d0e86a5088d089b386231

External Content's Version:

V2R2

jan-cerny avatar Feb 12 '25 09:02 jan-cerny