Milan Lysonek
Milan Lysonek
#### Description of problem: During hardened kickstart installation, `set_password_hashing_algorithm_passwordauth`, `set_password_hashing_algorithm_systemauth`, and `accounts_password_pam_retry` PAM rules pass. After installation when scanning, the rules fail because expected object has not been found. For...
#### Description of problem: A lot of rules from rhel7 and rhel8 cui profile miss a reference. List of rhel7 rules: ``` *** rules of 'cui' profile missing CUI Refs:...
#### Description of problem: A lot of rules from rhel7 and rhel8 ospp profile miss a reference. List of rhel7 ospp rules: ``` *** rules of 'ospp' profile missing OSPP...
RHEL 8/9 - `configure_usbguard_auditbackend` results in `notapplicable` and in final scan in `fail`
#### Description of problem: The `configure_usbguard_auditbackend` rule results in `notapplicable`, because `platform: usbguard` is not met. Then during remediations, usbguard is installed which causes `configure_usbguard_auditbackend` `fail` results in final scan....
#### Description of Problem: When XCCDF results from `oscap xccdf eval` are being validated, a lot of warnings is printed out. #### OpenSCAP Version: openscap-1.3.5-2.el8 #### Operating System & Version:...
#### Description: Switch Fedora project tests to Contest. #### Rationale: Current Fedora project beakerlib tests fail very often and we do not maintain those tests anymore because of newer and...
During installation of RHEL8, when a security policy is selected, and then the policy is changes to a different one, it seems that list of excluded packages is not reset....
#### Description of problem: The content is misaligned with an external (third party) content that targets the same policy - typically, this means that a system hardened by our content...
#### Description: TF test commit
#### Description of problem: harden_sshd_ciphers_openssh_conf_crypto_policy is misaligned with DISA #### Outcome: SSG result: fail DISA result: pass The issue is present in these test variants: - oscap - ansible -...