-
Notifications
You must be signed in to change notification settings - Fork 718
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
RHEL9 STIG profile difference from SRG mapping controls #8580
Comments
@Mab879 FYI |
How to reproduce
|
I tried to reproduce using this command but it returned this error:
The |
I have updated the list of rules that were in the original RHEL9 draft profile but are not in the profile that is generated from the control file srg_pos.
Some of these rules don't necessarily need to be present in the RHEL9 profile as they can be notapplicable for example. The easiest way to check if the rules are not there is to build the RHEL9 content and inspect the build/rhel9/profiles/stig.profile file and see if the built profile contains these rules. I guess at this point in time we are mostly waiting for the official RHEL9 STIG to be released and if they for some reason include any of these missing rules, we should readd them to the profile. But there is no need to keep this issue open, since when we get the official release we will compare with what we have and detect any inconsistencies. I propose to close this one. The only concern I have is that we submitted the STIG profile with the following:
If I'm not mistaken, and they were then later removed from the profile because they were not working properly. But if DISA has already accepted this, it might mean we will need to readd them back. @Mab879 Feel free to close this one. |
To include these rules, first the #10978 should be fixed. |
I will close this issue for now based on the discussion. In short, once DISA releases the STIG for RHEL9 we check if any change is necessary. Ok for you @Mab879 ? |
Works for me. |
These are the list of rules/variables that are in the RHEL9
stig.profile
but are not selected by the SRG mapping.as of 95dbc54
updated: Jun 21 2022
The text was updated successfully, but these errors were encountered: