Skip to content

Commit 64be48d

Browse files
authored
Merge pull request #106 from ansible-lockdown/devel
2.5.0 Release
2 parents b5440af + b6bef33 commit 64be48d

7 files changed

Lines changed: 47 additions & 34 deletions

File tree

README.md

Lines changed: 7 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@
66

77
Configure a RHEL/Rocky 8 system to be DISA STIG compliant. All findings will be audited by default. Non-disruptive CAT I, CAT II, and CAT III findings will be corrected by default. Disruptive finding remediation can be enabled by setting `rhel8stig_disruption_high` to `yes`.
88

9-
This role is based on RHEL 8 DISA STIG: [Version 1, Rel 5 released on Jan 27, 2022](https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_RHEL_8_V1R5_STIG.zip).
9+
This role is based on RHEL 8 DISA STIG: [Version 1, Rel 6 released on April 27, 2022](https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_RHEL_8_V1R6_STIG.zip).
1010

1111
## Join us
1212

@@ -145,6 +145,12 @@ uses:
145145
- runs the audit using the devel branch
146146
- This is an automated test that occurs on pull requests into devel
147147

148+
## Known Issues
149+
150+
If adopting stig rule RHEL-08-040134
151+
152+
This will affect cloud init as per https://bugs.launchpad.net/cloud-init/+bug/1839899
153+
148154
## Support
149155

150156
This is a community project at its core and will be managed as such.

defaults/main.yml

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -885,6 +885,11 @@ rhel8stig_tmux_lock_after_time: 900
885885
rhel8stig_sudo_timestamp_timeout: 1
886886

887887
#### Goss Configuration Settings ####
888+
# Set correct env for the run_audit.sh script from https://github.com/ansible-lockdown/{{ benchmark }}-Audit.git"
889+
audit_run_script_environment:
890+
AUDIT_BIN: "{{ audit_bin }}"
891+
AUDIT_FILE: 'goss.yml'
892+
AUDIT_CONTENT_LOCATION: "{{ audit_out_dir }}"
888893

889894
### Goss binary settings ###
890895
goss_version:

tasks/fix-cat2.yml

Lines changed: 29 additions & 29 deletions
Original file line numberDiff line numberDiff line change
@@ -1166,7 +1166,7 @@
11661166
- CAT2
11671167
- CCI-001749
11681168
- SRG-OS-000366-GPOS-00153
1169-
- SV-230266r792870_rule
1169+
- SV-230266r818816_rule
11701170
- V-230266
11711171
- sysctl
11721172

@@ -1182,7 +1182,7 @@
11821182
- CAT2
11831183
- CCI-002165
11841184
- SRG-OS-000312-GPOS-00122
1185-
- SV-230267r792873_rule
1185+
- SV-230267r818819_rule
11861186
- V-230267
11871187
- sysctl
11881188

@@ -1198,7 +1198,7 @@
11981198
- CAT2
11991199
- CCI-002165
12001200
- SRG-OS-000312-GPOS-00122
1201-
- SV-230268r792876_rule
1201+
- SV-230268r818822_rule
12021202
- V-230268
12031203
- sysctl
12041204

@@ -1475,7 +1475,7 @@
14751475
- CAT2
14761476
- CCI-002824
14771477
- SRG-OS-000433-GPOS-00193
1478-
- SV-230280r792891_rule
1478+
- SV-230280r818831_rule
14791479
- V-230280
14801480
- sysctl
14811481

@@ -2141,7 +2141,7 @@
21412141
- CAT2
21422142
- CCI-000366
21432143
- SRG-OS-000480-GPOS-00227
2144-
- SV-230311r792894_rule
2144+
- SV-230311r818834_rule
21452145
- V-230311
21462146
- sysctl
21472147

@@ -3442,7 +3442,7 @@
34423442
- CAT2
34433443
- CCI-000187
34443444
- SRG-OS-000068-GPOS-00036
3445-
- SV-230355r627750_rule
3445+
- SV-230355r818836_rule
34463446
- V-230355
34473447
- authentication
34483448

@@ -4762,7 +4762,7 @@
47624762
- CAT2
47634763
- CCI-000169
47644764
- SRG-OS-000062-GPOS-00031
4765-
- SV-244542r743875_rule
4765+
- SV-244542r818838_rule
47664766
- V-244542
47674767
- auditd
47684768

@@ -5581,7 +5581,7 @@
55815581
- CAT2
55825582
- CCI-001851
55835583
- SRG-OS-000342-GPOS-00133
5584-
- SV-230481r627750_rule
5584+
- SV-230481r818840_rule
55855585
- V-230481
55865586
- auditd
55875587
- rsyslog
@@ -6468,7 +6468,7 @@
64686468
- CAT2
64696469
- CI-000366
64706470
- SRG-OS-000480-GPOS-00227
6471-
- SV-244550r792987_rule
6471+
- SV-244550r818845_rule
64726472
- V-244550
64736473
- ipv4
64746474

@@ -6485,7 +6485,7 @@
64856485
- CAT2
64866486
- CCI-000366
64876487
- SRG-OS-000480-GPOS-00227
6488-
- SV-230535r792936_rule
6488+
- SV-230535r818848_rule
64896489
- V-230535
64906490
- icmp
64916491

@@ -6501,7 +6501,7 @@
65016501
- CAT2
65026502
- CCI-00036
65036503
- SRG-OS-000480-GPOS-00227
6504-
- SV-230536r792939_rule
6504+
- SV-230536r818851_rule
65056505
- V-230536
65066506
- icmp
65076507

@@ -6517,7 +6517,7 @@
65176517
- CAT2
65186518
- CCI-000366
65196519
- SRG-OS-000480-GPOS-00227
6520-
- SV-230537r792942_rule
6520+
- SV-230537r818854_rule
65216521
- V-230537
65226522
- icmp
65236523

@@ -6533,7 +6533,7 @@
65336533
- CAT2
65346534
- CCI-000366
65356535
- SRG-OS-000480-GPOS-00227
6536-
- SV-244551r792990_rule
6536+
- SV-244551r818857_rule
65376537
- V-244551
65386538
- ip4
65396539

@@ -6550,7 +6550,7 @@
65506550
- CAT2
65516551
- CCI-000366
65526552
- SRG-OS-000480-GPOS-00227
6553-
- SV-230538r792945_rule
6553+
- SV-230538r818860_rule
65546554
- V-230538
65556555
- icmp
65566556

@@ -6566,7 +6566,7 @@
65666566
- CAT2
65676567
- CCI-000366
65686568
- SRG-OS-000480-GPOS-00227
6569-
- SV-244552r792993_rule
6569+
- SV-244552r818863_rule
65706570
- V-244552
65716571
- ipv4
65726572

@@ -6583,7 +6583,7 @@
65836583
- CAT2
65846584
- CCI-000366
65856585
- SRG-OS-000480-GPOS-00227
6586-
- SV-230539r792948_rule
6586+
- SV-230539r818866_rule
65876587
- V-230539
65886588
- icmp
65896589

@@ -6600,7 +6600,7 @@
66006600
- CAT2
66016601
- CCI-000366
66026602
- SRG-OS-000480-GPOS-00227
6603-
- SV-250317r793008_rule
6603+
- SV-250317r818869_rule
66046604
- V-250317
66056605
- icmp
66066606

@@ -6617,7 +6617,7 @@
66176617
- CAT2
66186618
- CCI-000366
66196619
- SRG-OS-000480-GPOS-00227
6620-
- SV-230540r792951_rule
6620+
- SV-230540r818872_rule
66216621
- V-230540
66226622
- icmp
66236623

@@ -6635,7 +6635,7 @@
66356635
- CAT2
66366636
- CCI-000366
66376637
- SRG-OS-000480-GPOS-00227
6638-
- SV-230541r792954_rule
6638+
- SV-230541r818875_rule
66396639
- V-230541
66406640
- icmp
66416641

@@ -6653,7 +6653,7 @@
66536653
- CAT2
66546654
- CCI-000366
66556655
- SRG-OS-000480-GPOS-00227
6656-
- SV-230542r792957_rule
6656+
- SV-230542r818878_rule
66576657
- V-230542
66586658
- icmp
66596659

@@ -6669,7 +6669,7 @@
66696669
- CAT2
66706670
- CCI-000366
66716671
- SRG-OS-000480-GPOS-00227
6672-
- SV-230543r792960_rule
6672+
- SV-230543r818881_rule
66736673
- V-230543
66746674
- icmp
66756675

@@ -6685,7 +6685,7 @@
66856685
- CAT2
66866686
- CCI-000366
66876687
- SRG-OS-000480-GPOS-00227
6688-
- SV-244553r792996_rule
6688+
- SV-244553r818884_rule
66896689
- V-244553
66906690
- ipv4
66916691

@@ -6702,7 +6702,7 @@
67026702
- CAT2
67036703
- CCI-000366
67046704
- SRG-OS-000480-GPOS-00227
6705-
- SV-230544r792963_rule
6705+
- SV-230544r818887_rule
67066706
- V-230544
67076707
- icmp
67086708

@@ -6718,7 +6718,7 @@
67186718
- CAT2
67196719
- CCI-000366
67206720
- SRG-OS-000480-GPOS-00227
6721-
- SV-230545r792966_rule
6721+
- SV-230545r818890_rule
67226722
- V-230545
67236723
- sysctl
67246724

@@ -6734,7 +6734,7 @@
67346734
- CAT2
67356735
- CCI-000366
67366736
- SRG-OS-000480-GPOS-00227
6737-
- SV-230546r792969_rule
6737+
- SV-230546r818893_rule
67386738
- V-230546
67396739
- sysctl
67406740

@@ -6750,7 +6750,7 @@
67506750
- CAT2
67516751
- CCI-000366
67526752
- SRG-OS-000480-GPOS-00227
6753-
- SV-230547r792972_rule
6753+
- SV-230547r818896_rule
67546754
- V-230547
67556755
- sysctl
67566756

@@ -6766,7 +6766,7 @@
67666766
- CAT2
67676767
- CCI-000366
67686768
- SRG-OS-000480-GPOS-00227
6769-
- SV-230548r792975_rule
6769+
- SV-230548r818899_rule
67706770
- V-230548
67716771
- sysctl
67726772

@@ -6782,7 +6782,7 @@
67826782
- CAT2
67836783
- CCI-000366
67846784
- SRG-OS-000480-GPOS-00227
6785-
- SV-230549r792978_rule
6785+
- SV-230549r818902_rule
67866786
- V-230549
67876787
- sysctl
67886788

@@ -6798,7 +6798,7 @@
67986798
- CAT2
67996799
- CCI-000366
68006800
- SRG-OS-000480-GPOS-00227
6801-
- V-244554r792999_rule
6801+
- SV-244554r818905_rule
68026802
- V-244554
68036803

68046804
- name: "MEDIUM | RHEL-08-040290 | PATCH | The RHEL 8 must be configured to prevent unrestricted mail relaying. | Set restriction"

tasks/fix-cat3.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -43,7 +43,7 @@
4343
- CAT3
4444
- CCI-001090
4545
- SRG-OS-000138-GPOS-00069
46-
- SV-230269r792879_rule
46+
- SV-230269r818825_rule
4747
- V-230269
4848
- sysctl
4949

@@ -58,7 +58,7 @@
5858
- CAT3
5959
- CCI-001090
6060
- SRG-OS-000138-GPOS-00069
61-
- SV-230270r792882_rule
61+
- SV-230270r818828_rule
6262
- V-230270
6363
- sysctl
6464

@@ -428,7 +428,7 @@
428428
- CAT3
429429
- CCI-000381
430430
- SRG-OS-000095-GPOS-00049
431-
- SV-230491r792908_rule
431+
- SV-230491r818842_rule
432432
- V-230491
433433
- grub
434434

tasks/post_remediation_audit.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2,6 +2,7 @@
22

33
- name: "Post Audit | Run post_remediation {{ benchmark }} audit"
44
shell: "{{ audit_conf_dir }}/run_audit.sh -v {{ audit_vars_path }} -o {{ post_audit_outfile }} -g {{ group_names }}"
5+
environment: "{{ audit_run_script_environment|default({}) }}"
56
changed_when: rhel8stig_run_post_remediation.rc == 0
67
register: rhel8stig_run_post_remediation
78
vars:

tasks/pre_remediation_audit.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -90,6 +90,7 @@
9090

9191
- name: "Pre Audit | Run pre_remediation {{ benchmark }} audit"
9292
shell: "{{ audit_conf_dir }}/run_audit.sh -v {{ audit_vars_path }} -o {{ pre_audit_outfile }} -g {{ group_names }}"
93+
environment: "{{ audit_run_script_environment|default({}) }}"
9394
changed_when: rhel8stig_run_pre_remediation.rc == 0
9495
register: rhel8stig_run_pre_remediation
9596
vars:

templates/99-sysctl.conf.j2

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -78,7 +78,7 @@ net.ipv6.conf.all.accept_source_route = 0
7878
{% endif %}
7979

8080
{% if rhel_08_040249 %}
81-
# RHEL-08-040240
81+
# RHEL-08-040249
8282
net.ipv4.conf.default.accept_source_route = 0
8383
{% endif %}
8484

0 commit comments

Comments
 (0)