Skip to content

Releases: ansible-lockdown/RHEL8-STIG

Stig V1r9 release

20 Mar 08:27
7d5b654

Choose a tag to compare

Overall Review of Changes:
Release of stig v1r9 to main along with many improvements

Issue Fixes:
#157
#158
#159
#168
#169
#170
#171
#172
#173
#178
#179
#180
#181
#183
#185
#185

Enhancements:
Workflow updates
linting
audit alignment with correct stig benchmark release
Warning layout and updates

Benchmark 1.8 Updates

06 Jan 15:47
2c784de

Choose a tag to compare

STIG Benchmark Release: Version 1 Release 8
STIG Benchmark Release Date: Oct 27, 2022

Issues Fixed:

  • #139 - RHEL-08-010330 & RHEL-08-010350 | SETroubleshootD Breaks
  • #140 - RHEL-08-020027/020028 | SELinux Permission Discrepancies / Faillock SELinux Denials
  • #142 - RHEL-08-010141 /etc/grub.d/01_users need 755 permission
  • #147 - Install git
  • #148 - RHEL-08-020025 and RHEL-08-020026 - The "preauth" line is NOT listed before pam_unix.so
  • #151 - fstype in fix-cat2.yml set to static value "xfs" on mount tasks (Thanks to @whitehat237 for the PR with the fix idea)

Enhancements:

  • Updates for new benchmark 1.8
  • Updates for banner usage
  • Linting updates

Benchmark 1.7 and Issue Fixes

02 Nov 17:09
f98b63a

Choose a tag to compare

STIG Benchmark Release: Version 1 Release 7
STIG Benchmark Release Date: Jul 27, 2022

Issues Fixed:

  • #93 - Error with RHEL-08-040137 - Failed
  • #104 - README update - cloudint bug when /var noexec
  • #107 - RHEL-08-020040/41 needs additional configuration.
  • #109 - Broken link for the wiki for Main Variables
  • #115 - List dependencies in requirements.txt
  • #116 - Inconsistent YAML
  • #118 - ansible-lint: 648 failure(s), 0 warning(s) on 18 files
  • #124 - RHEL-08-040090 : Firewall must employ deny-all | Missing Configuration
  • #125 - RHEL-08-040259: Shall not enable IPv4 Forwarding | Update configuration to latest baseline
  • #126 - RHEL-08-010141: Unique Superuser Name for Maintenance | Non-Standard Configuration Method
  • #127 - RHEL-08-010690 / RHEL-08-010770 | Failure in Multiple Steps
  • #128 - RHEL-08-010050 Banner on Login Screen | Missing Configuration
  • #130 - Question regarding RHEL-08-010290 / RHEL-08-010291: Enabling FIPS mode even if not required by STIG?
  • #131 - RHEL-08-020040: TMUX Lock-Command Config | Incomplete Regex
  • #133 - RHEL-08-010295: GnuTLS Encryption | Line Bug
  • #134 - RHEL-08-010740: Group Ownership by Home Dir Owner | Incorrect Ownership by "Nobody" in RHEL 8.6

Enhancements:

  • Benchmarks 1.7 updates
  • Updates for new linting checks

Benchmark Version 1 Release 6

19 May 15:25
64be48d

Choose a tag to compare

STIG Benchmark Version: Version 1 Release 6
STIG Benchmark Release Date: Apr 27, 2022

Issues Fixed:

  • #104 - README Update - Cloudint bug when/var noexec

Enhancements:

  • Benchmark 1.6 updates

2.4.0

26 Apr 18:52
b5440af

Choose a tag to compare

STIG Benchmark Version: Version 1 Release 5
STIG Benchmark Release Date: Jan 27, 2022

Issues Fixed:

  • #72 - Prelim SSSD Bug
  • #75 - Typo in RHEL-08-040259 and RHEL-08-040260 notify
  • #87 - RHEL-08-020027 failed
  • #88 - RHEL-08-04017 not applying on RHEL8 Workstation
  • #93 - Error with RHEL-08-040137 - Failed
  • #99 - RHEL-08-010292 failing

Enhancements:

  • Workflows and testing improvements
  • #79 - Permit the use of service name or protocol port.
  • #81 - Version number inconsistencies causing Galaxy issue
  • #90 - Added additional conditionals to template to align with conditionals
  • #97 - ability to skip supported os check
  • #101 - Container updates

2.3.1

07 Jan 16:51
35c9d2b

Choose a tag to compare

STIG Benchmark Version: 1.3
STIG Benchmark Release Date: July 23, 2021

Issues Fixed:

  • #62 - Blacklisted module names should be lowercase
  • #64 - RHEL-08-020024 is not using the rhel8stig_maxlogins variable
  • #65 - RHEL-08-010201 task is replacing ClientAliveInterval value with ClientaliveCountMax.

Enhancements:

  • Misc. Rule updates
  • Added fapolicy white list
  • Added attributes file
  • fapolicy handler updates
  • tag name and backwards compatibility for notify

2.3.0

08 Nov 20:43
a2ce7bb

Choose a tag to compare

STIG Version: 1.3

Issues Addressed:
#57 - RHEL-08-030650 missing rule for rsyslogd
#58 - RHEL-08-010421 Same grubby behavior than on other tasks
#59 - RHEL-08-010400 - lineinfile task with state:present fails due to missing line: entry
PR #51 - Fix superuser for EFI boo
PR #56 - Fix Masked nftables Service

Enhancements:

  • Updated to Version 1 Release 3 of benchmarks

Added Issue/PR Templates and Issue Fix

30 Aug 20:35
f4c7157

Choose a tag to compare

STIG Version: 1.2.0

Issues Addressed:
#46 - RNG packages not installed causes control to fail

Enhancements:

  • Added issue templates
  • Added PR template

Benchmark update, issue fixes, and enhancements

19 Aug 19:24
3e411d4

Choose a tag to compare

STIG version: 1.2.0

Issues Addressed:
#26 - Errors on IPv6 disabled systems
#30 - Script overwriting new mount options
#40 - ssd.conf issues

Enhancements:

  • Updates for benchmark version 1 release 2
  • Improvements to controls requiring reboots
  • Improved FIPS logic
  • Rocky and Alma support
  • Updates to support Audit feature
  • Improved postfix logic
  • Updated to use package module instead of dnf module

Final Benchmark 1.0.0 Release

12 Jul 15:58
fe50d2a

Choose a tag to compare

STIG Version: 1.0.0

Issues Addressed:

  • #14 - Typo in resolv.conf configuration
  • #26 - Errors on ipv6 disabled systems.
  • #29 - Error applying playbooks referencing changes in sssd.conf
  • #31 - Script creating a new line in

Enhancements:

  • Linting for galaxy