content icon indicating copy to clipboard operation
content copied to clipboard

Rule pam_faillock wrongly used for standard scan profile in SLE15

Open phibid opened this issue 3 years ago • 3 comments

Description of problem:

Rule xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_deny is used when scanning a SLE15 server with standard profile, which is not correct as pam_faillock module does not exist on SLE 15, pam_tally2 does. As an example, Set Deny For Failed Password Attempts use pam_faillock.

Don't have this issue with CIS scan, in which xccdf_org.ssgproject.content_rule_accounts_passwords_pam_tally2 is correctly used.

SCAP Security Guide Version:

0.1.57

Operating System Version:

Suse Linux Enterprise server 15

Steps to Reproduce:

  1. Scan a SLE15 server with or without remediation with standard profile
  2. Check the result and see that pam_faillock is mentionned/used

Actual Results:

xccdf_org.ssgproject.content_rule_accounts_passwords_pam_faillock_deny is mentioned/used to remediate for example Set Deny For Failed Password Attempts

Expected Results:

xccdf_org.ssgproject.content_rule_accounts_passwords_pam_tally2 should be used

phibid avatar Sep 16 '21 08:09 phibid

In fact, the static guide is wrong too: http://static.open-scap.org/ssg-guides/ssg-sle15-guide-standard.html

phibid avatar Sep 21 '21 13:09 phibid

@anivan-suse @teacup-on-rockingchair FYI

marcusburghardt avatar Jul 07 '22 07:07 marcusburghardt

@anivan-suse @teacup-on-rockingchair FYI

Thanks @marcusburghardt. I opened an issue #9115 that will try to handle ASAP

teacup-on-rockingchair avatar Jul 08 '22 07:07 teacup-on-rockingchair

Hi @teacup-on-rockingchair , do you have plans to work on it soon? The #9104 is blocked by this issue.

marcusburghardt avatar Aug 16 '22 14:08 marcusburghardt

Hi @teacup-on-rockingchair , do you have plans to work on it soon? The #9104 is blocked by this issue.

Hi, my plans are to close this by the end of the month, hopefully next week.

teacup-on-rockingchair avatar Aug 17 '22 03:08 teacup-on-rockingchair

This would be great. : ) Thanks

marcusburghardt avatar Aug 17 '22 06:08 marcusburghardt

Based on the @teacup-on-rockingchair comment on #9115 , the pam_faillock.so PAM module is now supported out of box on SLE15.

Based on that, I am closing this issue.

marcusburghardt avatar Aug 29 '22 09:08 marcusburghardt