From c7e7073dbf9af3aae86aaa37a33b614f83062c3f Mon Sep 17 00:00:00 2001 From: Matthew Burket Date: Tue, 13 Feb 2024 18:30:46 -0600 Subject: [PATCH] Update sudo_dedicated_group 1. Fix broken test 2. Move to only forbidding root from owning the sudo binary --- .../software/sudo/sudo_dedicated_group/oval/shared.xml | 10 ++++------ .../sudo/sudo_dedicated_group/tests/no_group.fail.sh | 2 +- .../tests/{other_group.fail.sh => other_group.pass.sh} | 0 .../{root_default.pass.sh => root_default.fail.sh} | 0 4 files changed, 5 insertions(+), 7 deletions(-) rename linux_os/guide/system/software/sudo/sudo_dedicated_group/tests/{other_group.fail.sh => other_group.pass.sh} (100%) rename linux_os/guide/system/software/sudo/sudo_dedicated_group/tests/{root_default.pass.sh => root_default.fail.sh} (100%) diff --git a/linux_os/guide/system/software/sudo/sudo_dedicated_group/oval/shared.xml b/linux_os/guide/system/software/sudo/sudo_dedicated_group/oval/shared.xml index 2ecb1008b94..541de4a3bdf 100644 --- a/linux_os/guide/system/software/sudo/sudo_dedicated_group/oval/shared.xml +++ b/linux_os/guide/system/software/sudo/sudo_dedicated_group/oval/shared.xml @@ -1,7 +1,7 @@ {{{- oval_metadata("This test makes sure that /usr/bin/sudo is owned by the group set in var_sudo_dedicated_group") }}} - + @@ -14,19 +14,17 @@ /usr/bin/sudo + - + 0 - - - - + /etc/group diff --git a/linux_os/guide/system/software/sudo/sudo_dedicated_group/tests/no_group.fail.sh b/linux_os/guide/system/software/sudo/sudo_dedicated_group/tests/no_group.fail.sh index 971e8ac271e..897e5ac3587 100644 --- a/linux_os/guide/system/software/sudo/sudo_dedicated_group/tests/no_group.fail.sh +++ b/linux_os/guide/system/software/sudo/sudo_dedicated_group/tests/no_group.fail.sh @@ -1,6 +1,6 @@ # platform = multi_platform_all # remediation = none -# value = var_sudo_dedicated_group=othergroup +# variables = var_sudo_dedicated_group=othergroup groupadd othergroup chown :othergroup /usr/bin/sudo diff --git a/linux_os/guide/system/software/sudo/sudo_dedicated_group/tests/other_group.fail.sh b/linux_os/guide/system/software/sudo/sudo_dedicated_group/tests/other_group.pass.sh similarity index 100% rename from linux_os/guide/system/software/sudo/sudo_dedicated_group/tests/other_group.fail.sh rename to linux_os/guide/system/software/sudo/sudo_dedicated_group/tests/other_group.pass.sh diff --git a/linux_os/guide/system/software/sudo/sudo_dedicated_group/tests/root_default.pass.sh b/linux_os/guide/system/software/sudo/sudo_dedicated_group/tests/root_default.fail.sh similarity index 100% rename from linux_os/guide/system/software/sudo/sudo_dedicated_group/tests/root_default.pass.sh rename to linux_os/guide/system/software/sudo/sudo_dedicated_group/tests/root_default.fail.sh