Skip to content

Commit

Permalink
accounts_user_dot_group_ownership: Improve OVAL to avoid nobody group
Browse files Browse the repository at this point in the history
  • Loading branch information
dodys committed Dec 12, 2022
1 parent b4b4afb commit b3397d7
Showing 1 changed file with 6 additions and 0 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -10,12 +10,18 @@
<unix:password_object id="object_accounts_user_dot_group_ownership_objects" version="1">
<unix:username datatype="string" operation="not equal">nobody</unix:username>
<filter action="include">state_accounts_user_dot_group_ownership_interactive_gids</filter>
<filter action="exclude">state_accounts_user_dot_group_ownership_nobody</filter>
</unix:password_object>

<unix:password_state id="state_accounts_user_dot_group_ownership_interactive_gids" version="1">
<unix:group_id datatype="int" operation="greater than or equal">{{{ gid_min }}}</unix:group_id>
</unix:password_state>

<unix:password_state id="state_accounts_user_dot_group_ownership_nobody" version="1">
<unix:group_id datatype="int" operation="equals">{{{ nobody_gid }}}</unix:group_id>
</unix:password_state>


<local_variable id="var_accounts_user_dot_group_ownership_dirs" datatype="string" version="1"
comment="Variable including all home dirs from interactive users">
<object_component item_field="home_dir"
Expand Down

0 comments on commit b3397d7

Please sign in to comment.