Skip to content

Commit

Permalink
update requirement R69 in ANSSI control file
Browse files Browse the repository at this point in the history
  • Loading branch information
vojtapolasek committed Mar 11, 2024
1 parent c8e8e4a commit cc7638a
Showing 1 changed file with 22 additions and 2 deletions.
24 changes: 22 additions & 2 deletions controls/anssi.yml
Original file line number Diff line number Diff line change
Expand Up @@ -1378,8 +1378,28 @@ controls:
title: Securing access to remote user databases
levels:
- intermediary
notes: We cannot automate securing access to remote databases in a general way.
status: manual
description: |-
When the user databases are stored on a remote network service, NSS must
be configured to establish a secure link that allows, at minimum, to
authenticate the server and protect the communication channel.
{{% if "rhel" in product %}}
notes: |-
A nsswitch service connecting to remote database is provided by sssd. This is checked in requirement R67.
Another such service is winbind which is by default configured to connect
securely to Samba domains.
Other relevant services are NIS and Hesiod. These should not be used.
status: automated
{{% if product in ["rhel7", "rhel8"] %}}
rules:
- no_nis_in_nsswitch
{{% if product == "rhel7" %}}
- no_hesiod_in_nsswitch
{{% endif %}}
{{% endif %}}
{{% else %}}
status: pending
{{% endif %}}


- id: R70
title: Separation of System Accounts and Directory Administrator
Expand Down

0 comments on commit cc7638a

Please sign in to comment.