Gabriel Becker

Results 50 issues of Gabriel Becker

#### Description: - Improve ansible remediation of accounts_umask_etc_login_defs. - Correctly replace wrong values - Do not attempt to change a file that already has a valid configuration #### Rationale: -...

Ansible

#### Description: - Remove jinja condition to make rule applicability to all products in Kerberos rules. #### Rationale: - The applicability should be there for all products, not only part...

OVAL

https://github.com/ComplianceAsCode/content/blob/9fcf8560cf16987306bd8179050ef6660c67bb73/linux_os/guide/system/software/integrity/crypto/configure_gnutls_tls_crypto_policy/rule.yml#L15 This is possibly changing in a upcoming release of RHEL8 and the rule should be adapted accordingly. New string: `+VERS-ALL:-VERS-DTLS0.9:-VERS-TLS1.1:-VERS-TLS1.0:-VERS-SSL3.0:-VERS-DTLS1.0`

RHEL
triaged

#### Description of problem: `\s` covers all whitespace characters including newlines and in somecases newlines are not expected, for example: https://github.com/ComplianceAsCode/content/blob/1880981b573f38f334d74765c54676af24f15a25/shared/templates/sysctl/oval.template#L20 would match something like: ``` {{{ SYSCTLVAR }}} =1...

OVAL

#### Description of problem: Start shipping RHEL9 ansible content on galaxy. https://galaxy.ansible.com/RedHatOfficial https://github.com/ComplianceAsCode/content/blob/87768ea76b8ff21fdcc546fc9cce231bef1c85e7/utils/ansible_playbook_to_role.py#L57-L60

#### Description of problem: The test only assess OVAL files that belong to rule directories (`.../rule_id/oval/*`) and does not consider OVAL from templates. Now that we store intermediate built OVAL...

OVAL

I hard coded a few parts because the old code was not working so this definitely needs some improvements, but it's a proof of concept that the build actually works...

As a follow up from #4648, the meaning of authorized needs to be defined and well documented. Second option would be creating a new rule to check for the authorization...

unclear

Generated using: https://app.termly.io