Marco Fortina
Marco Fortina
I confirm. Also SLES15 uses `/bin/false`: data:image/s3,"s3://crabby-images/b505c/b505cbd6f319b03d75eb6dc2b440551ed6ae84f2" alt="image"
> > > for firewall rules you will need to use a tailoring file to select the firewall you want. By default the profile is enabled for nftables only. >...
> > I confirm. Also SLES15 uses `/bin/false`: > > data:image/s3,"s3://crabby-images/6e0e7/6e0e70864d70642bf0cf6124aeed9831dff18975" alt="image" > > Could you include `sle15` in the condition, please? FYI @teacup-on-rockingchair done, but I included SLE because also...
> @marcofortina there is still one test failing on sles Yes :( I'm installing a SLES15 vm right now to check the patched rule.
Checked manually on SLES15 vm. With this PR: ``` localhost:~/scap-security-guide/build # oscap xccdf eval --profile xccdf_org.ssgproject.content_profile_cis --rule xccdf_org.ssgproject.content_rule_no_shelllogin_for_systemaccounts ssg-sle15-ds.xml WARNING: Datastream component 'scap_org.open-scap_cref_pub-projects-security-oval-suse.linux.enterprise.15-patch.xml.bz2' points out to the remote 'https://ftp.suse.com/pub/projects/security/oval/suse.linux.enterprise.15-patch.xml.bz2'. Use...
``` ERROR - Rule 'no_shelllogin_for_systemaccounts' test setup script 'system_user_with_shell.fail.sh' failed with exit code 6 ERROR - Environment failed to prepare, skipping test INFO - Script last_uid_min.pass.sh using profile (all) OK...
> The `database` message is just a warning and we are not yet planning to move to `database_in` now as this is not backwards compatible and the warning doesn't prevent...
Version 0.1.72 does not report this error: ``` Title Ensure that System Accounts Do Not Run a Shell Upon Login Rule xccdf_org.ssgproject.content_rule_no_shelllogin_for_systemaccounts Result pass ``` master branch (commit 59013f66872e02613ba822587d7c5d57ba92cd9e): ```...
Last good commit c35978fb981d6938c1a40230e6a419cc128ed633: ``` Title Ensure that System Accounts Do Not Run a Shell Upon Login Rule xccdf_org.ssgproject.content_rule_no_shelllogin_for_systemaccounts Result pass ``` From commit a936357f1f2226ce25ba478ee82217584ecd980f: ``` Title Ensure that System...
PR #11896 broke pass result on Ubuntu 22.04 I agree on the usage of `/usr/sbin/nologin` instead of `/bin/false`, but only after all packages change their own users in `/etc/passwd` and...