Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

RHEL-09-232260 causes long running scan #44

Open
layluke opened this issue Sep 28, 2024 · 0 comments
Open

RHEL-09-232260 causes long running scan #44

layluke opened this issue Sep 28, 2024 · 0 comments
Assignees
Labels
question Further information is requested

Comments

@layluke
Copy link
Contributor

layluke commented Sep 28, 2024

Question
RHEL-09-232260 causes long running scan as it will scan all filesystems attached to /, even remote ones.

While this is probably the most complete way of handling this, it causes very long scan times that may be unnecessary when NFS is being used. Since other portions of the STIG locks down using device files, I'm not sure if the checks there are necessary outside of /dev.

in https://www.stigviewer.com/stig/red_hat_enterprise_linux_9/2023-09-13/finding/V-257932, it notes that there could be device files outside of /dev, but the scan text provided only searches through dev.

Not sure if appending /dev to the find command in the task would just be a lazy way of getting this to perform better, and satisfying scans. Or if adding some code to ignore nfs mounts would be a "better" way to ensure this check.

I'm not even sure if this needs to be addressed, as it can be likely turned off in most cases. Just want to bring it up at least since it was in my notes during my initial testing of this role.

@layluke layluke added the question Further information is requested label Sep 28, 2024
@uk-bolly uk-bolly self-assigned this Sep 30, 2024
@uk-bolly uk-bolly mentioned this issue Sep 30, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
question Further information is requested
Projects
None yet
Development

No branches or pull requests

2 participants