Releases: ansible-lockdown/RHEL8-STIG
Stig V1r9 release
Benchmark 1.8 Updates
STIG Benchmark Release: Version 1 Release 8
STIG Benchmark Release Date: Oct 27, 2022
Issues Fixed:
- #139 - RHEL-08-010330 & RHEL-08-010350 | SETroubleshootD Breaks
- #140 - RHEL-08-020027/020028 | SELinux Permission Discrepancies / Faillock SELinux Denials
- #142 - RHEL-08-010141 /etc/grub.d/01_users need 755 permission
- #147 - Install git
- #148 - RHEL-08-020025 and RHEL-08-020026 - The "preauth" line is NOT listed before pam_unix.so
- #151 - fstype in fix-cat2.yml set to static value "xfs" on mount tasks (Thanks to @whitehat237 for the PR with the fix idea)
Enhancements:
- Updates for new benchmark 1.8
- Updates for banner usage
- Linting updates
Benchmark 1.7 and Issue Fixes
STIG Benchmark Release: Version 1 Release 7
STIG Benchmark Release Date: Jul 27, 2022
Issues Fixed:
- #93 - Error with RHEL-08-040137 - Failed
- #104 - README update - cloudint bug when /var noexec
- #107 - RHEL-08-020040/41 needs additional configuration.
- #109 - Broken link for the wiki for Main Variables
- #115 - List dependencies in requirements.txt
- #116 - Inconsistent YAML
- #118 - ansible-lint: 648 failure(s), 0 warning(s) on 18 files
- #124 - RHEL-08-040090 : Firewall must employ deny-all | Missing Configuration
- #125 - RHEL-08-040259: Shall not enable IPv4 Forwarding | Update configuration to latest baseline
- #126 - RHEL-08-010141: Unique Superuser Name for Maintenance | Non-Standard Configuration Method
- #127 - RHEL-08-010690 / RHEL-08-010770 | Failure in Multiple Steps
- #128 - RHEL-08-010050 Banner on Login Screen | Missing Configuration
- #130 - Question regarding RHEL-08-010290 / RHEL-08-010291: Enabling FIPS mode even if not required by STIG?
- #131 - RHEL-08-020040: TMUX Lock-Command Config | Incomplete Regex
- #133 - RHEL-08-010295: GnuTLS Encryption | Line Bug
- #134 - RHEL-08-010740: Group Ownership by Home Dir Owner | Incorrect Ownership by "Nobody" in RHEL 8.6
Enhancements:
- Benchmarks 1.7 updates
- Updates for new linting checks
Benchmark Version 1 Release 6
STIG Benchmark Version: Version 1 Release 6
STIG Benchmark Release Date: Apr 27, 2022
Issues Fixed:
- #104 - README Update - Cloudint bug when/var noexec
Enhancements:
- Benchmark 1.6 updates
2.4.0
STIG Benchmark Version: Version 1 Release 5
STIG Benchmark Release Date: Jan 27, 2022
Issues Fixed:
- #72 - Prelim SSSD Bug
- #75 - Typo in RHEL-08-040259 and RHEL-08-040260 notify
- #87 - RHEL-08-020027 failed
- #88 - RHEL-08-04017 not applying on RHEL8 Workstation
- #93 - Error with RHEL-08-040137 - Failed
- #99 - RHEL-08-010292 failing
Enhancements:
2.3.1
STIG Benchmark Version: 1.3
STIG Benchmark Release Date: July 23, 2021
Issues Fixed:
- #62 - Blacklisted module names should be lowercase
- #64 - RHEL-08-020024 is not using the rhel8stig_maxlogins variable
- #65 - RHEL-08-010201 task is replacing ClientAliveInterval value with ClientaliveCountMax.
Enhancements:
- Misc. Rule updates
- Added fapolicy white list
- Added attributes file
- fapolicy handler updates
- tag name and backwards compatibility for notify
2.3.0
STIG Version: 1.3
Issues Addressed:
#57 - RHEL-08-030650 missing rule for rsyslogd
#58 - RHEL-08-010421 Same grubby behavior than on other tasks
#59 - RHEL-08-010400 - lineinfile task with state:present fails due to missing line: entry
PR #51 - Fix superuser for EFI boo
PR #56 - Fix Masked nftables Service
Enhancements:
- Updated to Version 1 Release 3 of benchmarks
Added Issue/PR Templates and Issue Fix
STIG Version: 1.2.0
Issues Addressed:
#46 - RNG packages not installed causes control to fail
Enhancements:
- Added issue templates
- Added PR template
Benchmark update, issue fixes, and enhancements
STIG version: 1.2.0
Issues Addressed:
#26 - Errors on IPv6 disabled systems
#30 - Script overwriting new mount options
#40 - ssd.conf issues
Enhancements:
- Updates for benchmark version 1 release 2
- Improvements to controls requiring reboots
- Improved FIPS logic
- Rocky and Alma support
- Updates to support Audit feature
- Improved postfix logic
- Updated to use package module instead of dnf module