Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

OCPBUGS-26193: Fix missing OCP4 STIG selections #11423

Merged
merged 8 commits into from
Feb 13, 2024

Conversation

yuumasato
Copy link
Member

Description:

  • Select missing OCP4 and RHCOS4 rules in SRG CTR controls.

Rationale:

  • There are unaddressed findings after OCP4 and RHCOS4 STIG profiles are applied.
    • These findings can be addressed by selecting already existing rules.

@yuumasato yuumasato added the OpenShift OpenShift product related. label Jan 5, 2024
@yuumasato yuumasato requested a review from rhmdnd January 5, 2024 15:18
Copy link

github-actions bot commented Jan 5, 2024

Start a new ephemeral environment with changes proposed in this pull request:

rhel8 (from CTF) Environment (using Fedora as testing environment)
Open in Gitpod

Fedora Testing Environment
Open in Gitpod

Oracle Linux 8 Environment
Open in Gitpod

@yuumasato yuumasato added the STIG STIG Benchmark related. label Jan 5, 2024
@yuumasato yuumasato changed the title OCPBUGS-26193: Fix missing OCP4 STIG CTR selections OCPBUGS-26193: Fix missing OCP4 STIG selections Jan 5, 2024
@@ -3,11 +3,12 @@ controls:
levels:
- medium
title: {{{ full_name }}} must be configured with only essential configurations.
related_rules:
rules:
Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One aspect of the usbgard rules is that at least two rounds of scan and remediations are needed for the rules to pass.
Because in the first round, the rule to install usbguard will be applied, but rules configuring it will result in not applicable.
In the second round, the rules configuring usbguard will fail, and their remediations will be applied.

@rhmdnd
Copy link
Collaborator

rhmdnd commented Jan 18, 2024

/test

Copy link

openshift-ci bot commented Jan 18, 2024

@rhmdnd: The /test command needs one or more targets.
The following commands are available to trigger required jobs:

  • /test e2e-aws-ocp4-cis
  • /test e2e-aws-ocp4-cis-node
  • /test e2e-aws-ocp4-e8
  • /test e2e-aws-ocp4-high
  • /test e2e-aws-ocp4-high-node
  • /test e2e-aws-ocp4-moderate
  • /test e2e-aws-ocp4-moderate-node
  • /test e2e-aws-ocp4-pci-dss
  • /test e2e-aws-ocp4-pci-dss-node
  • /test e2e-aws-ocp4-stig
  • /test e2e-aws-ocp4-stig-node
  • /test e2e-aws-rhcos4-e8
  • /test e2e-aws-rhcos4-high
  • /test e2e-aws-rhcos4-moderate
  • /test e2e-aws-rhcos4-stig
  • /test images

Use /test all to run the following jobs that were automatically triggered:

  • pull-ci-ComplianceAsCode-content-master-images

In response to this:

/test

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

@rhmdnd
Copy link
Collaborator

rhmdnd commented Jan 18, 2024

/test e2e-aws-ocp4-stig
/test e2e-aws-ocp4-stig-node
/test e2e-aws-rhcos4-stig

@rhmdnd
Copy link
Collaborator

rhmdnd commented Jan 18, 2024

Looks good to me - just one question inline.

@BhargaviGudi
Copy link
Collaborator

/hold for test

@openshift-ci openshift-ci bot added the do-not-merge/hold Used by openshift-ci-robot bot. label Jan 19, 2024
@BhargaviGudi
Copy link
Collaborator

Verification failed with 4.15.0-0.nightly-2024-01-18-050837 + compliance-operator with compliance-operator code

Please find the testing details below
Scenario 1: ocp4-stig and ocp4-stig-node profile -> PASS

$ oc compliance bind -N test-ocp4 -S default-auto-apply profile/upstream-ocp4-stig profile/upstream-ocp4-stig-node
Creating ScanSettingBinding test-ocp4
$ oc get suite -w
NAME        PHASE       RESULT
test-ocp4   LAUNCHING   NOT-AVAILABLE
test-ocp4   LAUNCHING   NOT-AVAILABLE
test-ocp4   LAUNCHING   NOT-AVAILABLE
test-ocp4   RUNNING     NOT-AVAILABLE
test-ocp4   RUNNING     NOT-AVAILABLE
test-ocp4   RUNNING     NOT-AVAILABLE
test-ocp4   AGGREGATING   NOT-AVAILABLE
test-ocp4   AGGREGATING   NOT-AVAILABLE
test-ocp4   AGGREGATING   NOT-AVAILABLE
test-ocp4   DONE          NON-COMPLIANT
test-ocp4   DONE          NON-COMPLIANT
$ oc get suite
NAME        PHASE   RESULT
test-ocp4   DONE    NON-COMPLIANT
$ oc get scan
NAME                             PHASE   RESULT
upstream-ocp4-stig               DONE    NON-COMPLIANT
upstream-ocp4-stig-node-master   DONE    NON-COMPLIANT
upstream-ocp4-stig-node-worker   DONE    NON-COMPLIANT
$ oc get cr
NAME                                                              STATE
upstream-ocp4-stig-api-server-encryption-provider-cipher          Applied
upstream-ocp4-stig-audit-profile-set                              Applied
upstream-ocp4-stig-oauth-or-oauthclient-token-maxage              Applied
upstream-ocp4-stig-project-config-and-template-network-policy     Applied
upstream-ocp4-stig-project-config-and-template-network-policy-1   Applied
upstream-ocp4-stig-project-config-and-template-resource-quota     Applied
upstream-ocp4-stig-project-config-and-template-resource-quota-1   Applied
$ oc get ccr -l compliance.openshift.io/automated-remediation=,compliance.openshift.io/check-status=FAIL
NAME                                                            STATUS   SEVERITY
upstream-ocp4-stig-api-server-encryption-provider-cipher        FAIL     medium
upstream-ocp4-stig-audit-profile-set                            FAIL     medium
upstream-ocp4-stig-oauth-or-oauthclient-token-maxage            FAIL     medium
upstream-ocp4-stig-project-config-and-template-network-policy   FAIL     medium
upstream-ocp4-stig-project-config-and-template-resource-quota   FAIL     medium
[bgudi@bgudi content]$ oc-compliance rerun-now scansettingbinding test-ocp4
Rerunning scans from 'test-ocp4': upstream-ocp4-stig, upstream-ocp4-stig-node-master, upstream-ocp4-stig-node-worker
Re-running scan 'openshift-compliance/upstream-ocp4-stig'
Re-running scan 'openshift-compliance/upstream-ocp4-stig-node-master'
Re-running scan 'openshift-compliance/upstream-ocp4-stig-node-worker'
$ oc get suite -w
NAME        PHASE       RESULT
test-ocp4   LAUNCHING   NOT-AVAILABLE
test-ocp4   LAUNCHING   NOT-AVAILABLE
test-ocp4   RUNNING     NOT-AVAILABLE
test-ocp4   RUNNING     NOT-AVAILABLE
test-ocp4   RUNNING     NOT-AVAILABLE
test-ocp4   RUNNING     NOT-AVAILABLE
test-ocp4   AGGREGATING   NOT-AVAILABLE
test-ocp4   AGGREGATING   NOT-AVAILABLE
test-ocp4   DONE          NON-COMPLIANT
test-ocp4   DONE          NON-COMPLIANT
$ oc get ccr -l compliance.openshift.io/automated-remediation=
NAME                                                                                    STATUS   SEVERITY
upstream-ocp4-stig-api-server-encryption-provider-cipher                                PASS     medium
upstream-ocp4-stig-audit-error-alert-exists                                             PASS     high
upstream-ocp4-stig-audit-profile-set                                                    PASS     medium
upstream-ocp4-stig-node-master-kubelet-configure-event-creation                         PASS     medium
upstream-ocp4-stig-node-master-kubelet-configure-tls-cipher-suites                      PASS     medium
upstream-ocp4-stig-node-master-kubelet-configure-tls-min-version                        PASS     medium
upstream-ocp4-stig-node-master-kubelet-enable-iptables-util-chains                      PASS     medium
upstream-ocp4-stig-node-master-kubelet-enable-protect-kernel-defaults                   PASS     medium
upstream-ocp4-stig-node-master-kubelet-enable-protect-kernel-sysctl                     PASS     medium
upstream-ocp4-stig-node-master-kubelet-enable-streaming-connections                     PASS     medium
upstream-ocp4-stig-node-master-kubelet-eviction-thresholds-set-hard-imagefs-available   PASS     medium
upstream-ocp4-stig-node-master-kubelet-eviction-thresholds-set-hard-memory-available    PASS     medium
upstream-ocp4-stig-node-master-kubelet-eviction-thresholds-set-hard-nodefs-available    PASS     medium
upstream-ocp4-stig-node-master-kubelet-eviction-thresholds-set-hard-nodefs-inodesfree   PASS     medium
upstream-ocp4-stig-node-worker-kubelet-configure-event-creation                         PASS     medium
upstream-ocp4-stig-node-worker-kubelet-configure-tls-cipher-suites                      PASS     medium
upstream-ocp4-stig-node-worker-kubelet-configure-tls-min-version                        PASS     medium
upstream-ocp4-stig-node-worker-kubelet-enable-iptables-util-chains                      PASS     medium
upstream-ocp4-stig-node-worker-kubelet-enable-protect-kernel-defaults                   PASS     medium
upstream-ocp4-stig-node-worker-kubelet-enable-protect-kernel-sysctl                     PASS     medium
upstream-ocp4-stig-node-worker-kubelet-enable-streaming-connections                     PASS     medium
upstream-ocp4-stig-node-worker-kubelet-eviction-thresholds-set-hard-imagefs-available   PASS     medium
upstream-ocp4-stig-node-worker-kubelet-eviction-thresholds-set-hard-memory-available    PASS     medium
upstream-ocp4-stig-node-worker-kubelet-eviction-thresholds-set-hard-nodefs-available    PASS     medium
upstream-ocp4-stig-node-worker-kubelet-eviction-thresholds-set-hard-nodefs-inodesfree   PASS     medium
upstream-ocp4-stig-oauth-or-oauthclient-token-maxage                                    PASS     medium
upstream-ocp4-stig-project-config-and-template-network-policy                           PASS     medium
upstream-ocp4-stig-project-config-and-template-resource-quota                           PASS     medium
$ oc get ccr -l compliance.openshift.io/automated-remediation=,compliance.openshift.io/check-status=FAIL
No resources found in openshift-compliance namespace.
$ oc get cr
NAME                                                              STATE
upstream-ocp4-stig-api-server-encryption-provider-cipher          Applied
upstream-ocp4-stig-audit-profile-set                              Applied
upstream-ocp4-stig-oauth-or-oauthclient-token-maxage              Applied
upstream-ocp4-stig-project-config-and-template-network-policy     Applied
upstream-ocp4-stig-project-config-and-template-network-policy-1   Applied
upstream-ocp4-stig-project-config-and-template-resource-quota     Applied
upstream-ocp4-stig-project-config-and-template-resource-quota-1   Applied
$ oc delete ssb test-ocp4 
scansettingbinding.compliance.openshift.io "test-ocp4" deleted

Scenario 2: rhcos4-stig profile -> FAIL

$ oc compliance bind -N test-rhcos4 -S default-auto-apply profile/upstream-rhcos4-stig
Creating ScanSettingBinding test-rhcos4
$ oc get suite -w
NAME          PHASE       RESULT
test-rhcos4   LAUNCHING   NOT-AVAILABLE
test-rhcos4   LAUNCHING   NOT-AVAILABLE
test-rhcos4   RUNNING     NOT-AVAILABLE
test-rhcos4   RUNNING     NOT-AVAILABLE
test-rhcos4   AGGREGATING   NOT-AVAILABLE
test-rhcos4   AGGREGATING   NOT-AVAILABLE
test-rhcos4   DONE          NON-COMPLIANT
test-rhcos4   DONE          NON-COMPLIANT
$ oc get scan
NAME                          PHASE   RESULT
upstream-rhcos4-stig-master   DONE    NON-COMPLIANT
upstream-rhcos4-stig-worker   DONE    NON-COMPLIANT
$ oc get cr | grep MissingDependencies
upstream-rhcos4-stig-master-service-usbguard-enabled                                       MissingDependencies
upstream-rhcos4-stig-master-usbguard-allow-hid-and-hub                                     MissingDependencies
upstream-rhcos4-stig-worker-service-usbguard-enabled                                       MissingDependencies
upstream-rhcos4-stig-worker-usbguard-allow-hid-and-hub                                     MissingDependencies
$ oc get ccr -l compliance.openshift.io/automated-remediation=,compliance.openshift.io/check-status=FAIL
NAME                                                                                       STATUS   SEVERITY
upstream-rhcos4-stig-master-audit-access-failed                                            FAIL     medium
upstream-rhcos4-stig-master-audit-create-failed                                            FAIL     medium
upstream-rhcos4-stig-master-audit-delete-failed                                            FAIL     medium
upstream-rhcos4-stig-master-audit-immutable-login-uids                                     FAIL     medium
upstream-rhcos4-stig-master-audit-modify-failed                                            FAIL     medium
upstream-rhcos4-stig-master-audit-rules-dac-modification-chmod                             FAIL     medium
upstream-rhcos4-stig-master-audit-rules-dac-modification-chown                             FAIL     medium
upstream-rhcos4-stig-master-audit-rules-dac-modification-fchmod                            FAIL     medium
upstream-rhcos4-stig-master-audit-rules-dac-modification-fchmodat                          FAIL     medium
upstream-rhcos4-stig-master-audit-rules-dac-modification-fchown                            FAIL     medium
upstream-rhcos4-stig-master-audit-rules-dac-modification-fchownat                          FAIL     medium
upstream-rhcos4-stig-master-audit-rules-dac-modification-fremovexattr                      FAIL     medium
upstream-rhcos4-stig-master-audit-rules-dac-modification-fsetxattr                         FAIL     medium
upstream-rhcos4-stig-master-audit-rules-dac-modification-lchown                            FAIL     medium
upstream-rhcos4-stig-master-audit-rules-dac-modification-lremovexattr                      FAIL     medium
upstream-rhcos4-stig-master-audit-rules-dac-modification-lsetxattr                         FAIL     medium
upstream-rhcos4-stig-master-audit-rules-dac-modification-removexattr                       FAIL     medium
upstream-rhcos4-stig-master-audit-rules-dac-modification-setxattr                          FAIL     medium
upstream-rhcos4-stig-master-audit-rules-dac-modification-umount                            FAIL     medium
upstream-rhcos4-stig-master-audit-rules-dac-modification-umount2                           FAIL     medium
upstream-rhcos4-stig-master-audit-rules-execution-chcon                                    FAIL     medium
upstream-rhcos4-stig-master-audit-rules-execution-semanage                                 FAIL     medium
upstream-rhcos4-stig-master-audit-rules-execution-setfiles                                 FAIL     medium
upstream-rhcos4-stig-master-audit-rules-execution-setsebool                                FAIL     medium
upstream-rhcos4-stig-master-audit-rules-file-deletion-events-rename                        FAIL     medium
upstream-rhcos4-stig-master-audit-rules-file-deletion-events-renameat                      FAIL     medium
upstream-rhcos4-stig-master-audit-rules-file-deletion-events-rmdir                         FAIL     medium
upstream-rhcos4-stig-master-audit-rules-file-deletion-events-unlink                        FAIL     medium
upstream-rhcos4-stig-master-audit-rules-file-deletion-events-unlinkat                      FAIL     medium
upstream-rhcos4-stig-master-audit-rules-immutable                                          FAIL     medium
upstream-rhcos4-stig-master-audit-rules-kernel-module-loading-delete                       FAIL     medium
upstream-rhcos4-stig-master-audit-rules-kernel-module-loading-finit                        FAIL     medium
upstream-rhcos4-stig-master-audit-rules-kernel-module-loading-init                         FAIL     medium
upstream-rhcos4-stig-master-audit-rules-login-events-faillock                              FAIL     medium
upstream-rhcos4-stig-master-audit-rules-login-events-lastlog                               FAIL     medium
upstream-rhcos4-stig-master-audit-rules-login-events-tallylog                              FAIL     medium
upstream-rhcos4-stig-master-audit-rules-media-export                                       FAIL     medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-chage                          FAIL     medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-chsh                           FAIL     medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-crontab                        FAIL     medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-dbus-daemon-launch-helper      FAIL     medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-fusermount                     FAIL     medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-fusermount3                    FAIL     medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-gpasswd                        FAIL     medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-grub2-set-bootflag             FAIL     medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-mount                          FAIL     medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-mount-nfs                      FAIL     medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-newgrp                         FAIL     medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-pam-timestamp-check            FAIL     medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-passwd                         FAIL     medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-pkexec                         FAIL     medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-polkit-helper                  FAIL     medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-postdrop                       FAIL     medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-postqueue                      FAIL     medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-pt-chown                       FAIL     medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-ssh-keysign                    FAIL     medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-sssd-krb5-child                FAIL     medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-sssd-ldap-child                FAIL     medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-sssd-proxy-child               FAIL     medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-sssd-selinux-child             FAIL     medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-su                             FAIL     medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-sudo                           FAIL     medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-sudoedit                       FAIL     medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-umount                         FAIL     medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-unix-chkpwd                    FAIL     medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-userhelper                     FAIL     medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-utempter                       FAIL     medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-write                          FAIL     medium
upstream-rhcos4-stig-master-audit-rules-session-events                                     FAIL     medium
upstream-rhcos4-stig-master-audit-rules-sysadmin-actions                                   FAIL     medium
upstream-rhcos4-stig-master-audit-rules-unsuccessful-file-modification-creat               FAIL     medium
upstream-rhcos4-stig-master-audit-rules-unsuccessful-file-modification-ftruncate           FAIL     medium
upstream-rhcos4-stig-master-audit-rules-unsuccessful-file-modification-open                FAIL     medium
upstream-rhcos4-stig-master-audit-rules-unsuccessful-file-modification-open-by-handle-at   FAIL     medium
upstream-rhcos4-stig-master-audit-rules-unsuccessful-file-modification-openat              FAIL     medium
upstream-rhcos4-stig-master-audit-rules-unsuccessful-file-modification-rename              FAIL     medium
upstream-rhcos4-stig-master-audit-rules-unsuccessful-file-modification-renameat            FAIL     medium
upstream-rhcos4-stig-master-audit-rules-unsuccessful-file-modification-truncate            FAIL     medium
upstream-rhcos4-stig-master-audit-rules-unsuccessful-file-modification-unlink              FAIL     medium
upstream-rhcos4-stig-master-audit-rules-unsuccessful-file-modification-unlinkat            FAIL     medium
upstream-rhcos4-stig-master-audit-rules-usergroup-modification                             FAIL     medium
upstream-rhcos4-stig-master-audit-rules-usergroup-modification-group                       FAIL     medium
upstream-rhcos4-stig-master-audit-rules-usergroup-modification-gshadow                     FAIL     medium
upstream-rhcos4-stig-master-audit-rules-usergroup-modification-opasswd                     FAIL     medium
upstream-rhcos4-stig-master-audit-rules-usergroup-modification-passwd                      FAIL     medium
upstream-rhcos4-stig-master-audit-rules-usergroup-modification-shadow                      FAIL     medium
upstream-rhcos4-stig-master-auditd-data-disk-error-action                                  FAIL     medium
upstream-rhcos4-stig-master-coreos-audit-backlog-limit-kernel-argument                     FAIL     medium
upstream-rhcos4-stig-master-coreos-audit-option                                            FAIL     medium
upstream-rhcos4-stig-master-coreos-page-poison-kernel-argument                             FAIL     medium
upstream-rhcos4-stig-master-coreos-slub-debug-kernel-argument                              FAIL     medium
upstream-rhcos4-stig-master-kernel-module-usb-storage-disabled                             FAIL     medium
upstream-rhcos4-stig-master-package-usbguard-installed                                     FAIL     medium
upstream-rhcos4-stig-master-service-sshd-disabled                                          FAIL     high
upstream-rhcos4-stig-master-service-usbguard-enabled                                       FAIL     medium
upstream-rhcos4-stig-master-sshd-disable-root-login                                        FAIL     medium
upstream-rhcos4-stig-master-sysctl-kernel-dmesg-restrict                                   FAIL     low
upstream-rhcos4-stig-master-sysctl-kernel-perf-event-paranoid                              FAIL     low
upstream-rhcos4-stig-master-sysctl-kernel-randomize-va-space                               FAIL     medium
upstream-rhcos4-stig-master-usbguard-allow-hid-and-hub                                     FAIL     medium
upstream-rhcos4-stig-worker-audit-access-failed                                            FAIL     medium
upstream-rhcos4-stig-worker-audit-create-failed                                            FAIL     medium
upstream-rhcos4-stig-worker-audit-delete-failed                                            FAIL     medium
upstream-rhcos4-stig-worker-audit-immutable-login-uids                                     FAIL     medium
upstream-rhcos4-stig-worker-audit-modify-failed                                            FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-dac-modification-chmod                             FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-dac-modification-chown                             FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-dac-modification-fchmod                            FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-dac-modification-fchmodat                          FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-dac-modification-fchown                            FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-dac-modification-fchownat                          FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-dac-modification-fremovexattr                      FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-dac-modification-fsetxattr                         FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-dac-modification-lchown                            FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-dac-modification-lremovexattr                      FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-dac-modification-lsetxattr                         FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-dac-modification-removexattr                       FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-dac-modification-setxattr                          FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-dac-modification-umount                            FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-dac-modification-umount2                           FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-execution-chcon                                    FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-execution-semanage                                 FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-execution-setfiles                                 FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-execution-setsebool                                FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-file-deletion-events-rename                        FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-file-deletion-events-renameat                      FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-file-deletion-events-rmdir                         FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-file-deletion-events-unlink                        FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-file-deletion-events-unlinkat                      FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-immutable                                          FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-kernel-module-loading-delete                       FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-kernel-module-loading-finit                        FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-kernel-module-loading-init                         FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-login-events-faillock                              FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-login-events-lastlog                               FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-login-events-tallylog                              FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-media-export                                       FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-chage                          FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-chsh                           FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-crontab                        FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-dbus-daemon-launch-helper      FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-fusermount                     FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-fusermount3                    FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-gpasswd                        FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-grub2-set-bootflag             FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-mount                          FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-mount-nfs                      FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-newgrp                         FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-pam-timestamp-check            FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-passwd                         FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-pkexec                         FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-polkit-helper                  FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-postdrop                       FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-postqueue                      FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-pt-chown                       FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-ssh-keysign                    FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-sssd-krb5-child                FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-sssd-ldap-child                FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-sssd-proxy-child               FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-sssd-selinux-child             FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-su                             FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-sudo                           FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-sudoedit                       FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-umount                         FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-unix-chkpwd                    FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-userhelper                     FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-utempter                       FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-write                          FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-session-events                                     FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-sysadmin-actions                                   FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-unsuccessful-file-modification-creat               FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-unsuccessful-file-modification-ftruncate           FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-unsuccessful-file-modification-open                FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-unsuccessful-file-modification-open-by-handle-at   FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-unsuccessful-file-modification-openat              FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-unsuccessful-file-modification-rename              FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-unsuccessful-file-modification-renameat            FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-unsuccessful-file-modification-truncate            FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-unsuccessful-file-modification-unlink              FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-unsuccessful-file-modification-unlinkat            FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-usergroup-modification                             FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-usergroup-modification-group                       FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-usergroup-modification-gshadow                     FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-usergroup-modification-opasswd                     FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-usergroup-modification-passwd                      FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-usergroup-modification-shadow                      FAIL     medium
upstream-rhcos4-stig-worker-auditd-data-disk-error-action                                  FAIL     medium
upstream-rhcos4-stig-worker-coreos-audit-backlog-limit-kernel-argument                     FAIL     medium
upstream-rhcos4-stig-worker-coreos-audit-option                                            FAIL     medium
upstream-rhcos4-stig-worker-coreos-page-poison-kernel-argument                             FAIL     medium
upstream-rhcos4-stig-worker-coreos-slub-debug-kernel-argument                              FAIL     medium
upstream-rhcos4-stig-worker-kernel-module-usb-storage-disabled                             FAIL     medium
upstream-rhcos4-stig-worker-package-usbguard-installed                                     FAIL     medium
upstream-rhcos4-stig-worker-service-sshd-disabled                                          FAIL     high
upstream-rhcos4-stig-worker-service-usbguard-enabled                                       FAIL     medium
upstream-rhcos4-stig-worker-sshd-disable-root-login                                        FAIL     medium
upstream-rhcos4-stig-worker-sysctl-kernel-dmesg-restrict                                   FAIL     low
upstream-rhcos4-stig-worker-sysctl-kernel-perf-event-paranoid                              FAIL     low
upstream-rhcos4-stig-worker-sysctl-kernel-randomize-va-space                               FAIL     medium
upstream-rhcos4-stig-worker-usbguard-allow-hid-and-hub                                     FAIL     medium
$ oc-compliance rerun-now scansettingbinding test-rhcos4
Rerunning scans from 'test-rhcos4': upstream-rhcos4-stig-master, upstream-rhcos4-stig-worker
Re-running scan 'openshift-compliance/upstream-rhcos4-stig-master'
Re-running scan 'openshift-compliance/upstream-rhcos4-stig-worker'
$ oc get mcp
NAME     CONFIG                                             UPDATED   UPDATING   DEGRADED   MACHINECOUNT   READYMACHINECOUNT   UPDATEDMACHINECOUNT   DEGRADEDMACHINECOUNT   AGE
master   rendered-master-5c2f388f55a1e963789ce3f85f6dd5f1   True      False      False      3              3                   3                     0                      5h44m
worker   rendered-worker-9fafad7ce7363e3e8994da447789593c   True      False      False      3              3                   3                     0                      5h44m
$ oc get suite
NAME          PHASE   RESULT
test-rhcos4   DONE    NON-COMPLIANT
$ oc get scan
NAME                          PHASE   RESULT
upstream-rhcos4-stig-master   DONE    NON-COMPLIANT
upstream-rhcos4-stig-worker   DONE    NON-COMPLIANT
$ oc get ^C
$ oc get cr | grep MissingDependencies
$ oc get ccr -l compliance.openshift.io/automated-remediation=,compliance.openshift.io/check-status=FAIL
NAME                                                          STATUS   SEVERITY
upstream-rhcos4-stig-master-audit-delete-failed               FAIL     medium
upstream-rhcos4-stig-master-configure-usbguard-auditbackend   FAIL     low
upstream-rhcos4-stig-master-service-usbguard-enabled          FAIL     medium
upstream-rhcos4-stig-master-usbguard-allow-hid-and-hub        FAIL     medium
upstream-rhcos4-stig-worker-audit-delete-failed               FAIL     medium
upstream-rhcos4-stig-worker-configure-usbguard-auditbackend   FAIL     low
upstream-rhcos4-stig-worker-service-usbguard-enabled          FAIL     medium
upstream-rhcos4-stig-worker-usbguard-allow-hid-and-hub        FAIL     medium

After multiple rescan, upstream-rhcos4-stig-worker-service-usbguard-enabled goes into INCONSISTENT state.
I have checked the status of usbguard.service in all the worker node and started usbguard.service service on the node where it was inactive. Still facing issue.
@yuumasato Could you please help me check the issue. Thanks

$ oc-compliance rerun-now scansettingbinding test-rhcos4
Rerunning scans from 'test-rhcos4': upstream-rhcos4-stig-master, upstream-rhcos4-stig-worker
Re-running scan 'openshift-compliance/upstream-rhcos4-stig-master'
Re-running scan 'openshift-compliance/upstream-rhcos4-stig-worker'
$ oc get suite -w
NAME          PHASE       RESULT
test-rhcos4   LAUNCHING   NOT-AVAILABLE
test-rhcos4   RUNNING     NOT-AVAILABLE
test-rhcos4   RUNNING     NOT-AVAILABLE
test-rhcos4   AGGREGATING   NOT-AVAILABLE
test-rhcos4   AGGREGATING   NOT-AVAILABLE
test-rhcos4   DONE          INCONSISTENT
test-rhcos4   DONE          INCONSISTENT
$ oc get ccr -l compliance.openshift.io/automated-remediation=,compliance.openshift.io/check-status=FAIL
NAME                                              STATUS   SEVERITY
upstream-rhcos4-stig-master-audit-delete-failed   FAIL     medium
upstream-rhcos4-stig-worker-audit-delete-failed   FAIL     medium
$ oc get ccr | grep INCONSISTENT
upstream-rhcos4-stig-worker-service-usbguard-enabled                                       INCONSISTENT   medium
$ oc describe ccr upstream-rhcos4-stig-worker-service-usbguard-enabled | tail
Rationale:                 The usbguard service must be running in order to enforce the USB device authorization policy for all USB devices.
Severity:                  medium
Status:                    INCONSISTENT
Events:                    

@yuumasato
Copy link
Member Author

yuumasato commented Jan 23, 2024

@BhargaviGudi I was not able to get the INCONSISTENT results. I tried with 4.14 and 4.15.
I waited for oc get mcp to have the pools updated, and rerun the profiles.
I had to wait and rerun twice to get the results below:

$ oc get scan
NAME                          PHASE   RESULT
upstream-ocp4-stig            DONE    NON-COMPLIANT
upstream-rhcos4-stig-master   DONE    COMPLIANT
upstream-rhcos4-stig-worker   DONE    COMPLIANT

$oc get ccr -l compliance.openshift.io/automated-remediation=,compliance.openshift.io/check-status=FAIL
No resources found in openshift-compliance namespace.

Copy link

github-actions bot commented Jan 23, 2024

This datastream diff is auto generated by the check Compare DS/Generate Diff

Click here to see the full diff
New content has different text for rule 'xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_rename'.
--- xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_rename
+++ xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_rename
@@ -394,6 +394,12 @@
 [reference]:
 SRG-OS-000468-GPOS-00212
 
+[reference]:
+SRG-APP-000501-CTR-001265
+
+[reference]:
+SRG-APP-000502-CTR-001270
+
 [rationale]:
 Unsuccessful attempts to delete files could be an indicator of malicious activity on a system. Auditing
 these events could serve as evidence of potential system compromise.

New content has different text for rule 'xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_renameat'.
--- xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_renameat
+++ xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_renameat
@@ -395,6 +395,12 @@
 [reference]:
 SRG-OS-000468-GPOS-00212
 
+[reference]:
+SRG-APP-000501-CTR-001265
+
+[reference]:
+SRG-APP-000502-CTR-001270
+
 [rationale]:
 Unsuccessful attempts to delete files could be an indicator of malicious activity on a system. Auditing
 these events could serve as evidence of potential system compromise.

New content has different text for rule 'xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_unlink'.
--- xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_unlink
+++ xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_unlink
@@ -397,6 +397,12 @@
 [reference]:
 SRG-OS-000468-GPOS-00212
 
+[reference]:
+SRG-APP-000501-CTR-001265
+
+[reference]:
+SRG-APP-000502-CTR-001270
+
 [rationale]:
 Unsuccessful attempts to delete files could be an indicator of malicious activity on a system. Auditing
 these events could serve as evidence of potential system compromise.

New content has different text for rule 'xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_unlinkat'.
--- xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_unlinkat
+++ xccdf_org.ssgproject.content_rule_audit_rules_unsuccessful_file_modification_unlinkat
@@ -397,6 +397,12 @@
 [reference]:
 SRG-OS-000468-GPOS-00212
 
+[reference]:
+SRG-APP-000501-CTR-001265
+
+[reference]:
+SRG-APP-000502-CTR-001270
+
 [rationale]:
 Unsuccessful attempts to delete files could be an indicator of malicious activity on a system. Auditing
 these events could serve as evidence of potential system compromise.

New content has different text for rule 'xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_pt_chown'.
--- xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_pt_chown
+++ xccdf_org.ssgproject.content_rule_audit_rules_privileged_commands_pt_chown
@@ -221,6 +221,15 @@
 [reference]:
 SRG-OS-000471-GPOS-00215
 
+[reference]:
+SRG-APP-000499-CTR-001255
+
+[reference]:
+SRG-APP-000501-CTR-001265
+
+[reference]:
+SRG-APP-000502-CTR-001270
+
 [rationale]:
 Misuse of privileged functions, either intentionally or unintentionally by
 authorized users, or by unauthorized external entities that have compromised system accounts,

New content has different text for rule 'xccdf_org.ssgproject.content_rule_audit_delete_failed'.
--- xccdf_org.ssgproject.content_rule_audit_delete_failed
+++ xccdf_org.ssgproject.content_rule_audit_delete_failed
@@ -44,6 +44,12 @@
 [reference]:
 SRG-OS-000468-GPOS-00212
 
+[reference]:
+SRG-APP-000501-CTR-001265
+
+[reference]:
+SRG-APP-000502-CTR-001270
+
 [rationale]:
 Unsuccessful attempts to delete a file might be signs of malicious activities. Auditing of such events help in monitoring and investigating of such activities.
 

kubernetes remediation for rule 'xccdf_org.ssgproject.content_rule_audit_delete_failed' differs.
--- xccdf_org.ssgproject.content_rule_audit_delete_failed
+++ xccdf_org.ssgproject.content_rule_audit_delete_failed
@@ -8,7 +8,7 @@
     storage:
       files:
       - contents:
-          source: data:,%23%23%20Unsuccessful%20file%20delete%0A-a%20always%2Cexit%20-F%20arch%3Db32%20-S%20unlink%2Cunlinkat%2Crename%2Crenameat%20-F%20exit%3D-EACCES%20-F%20auid%26gt%3B%3D1000%20-F%20auid%21%3Dunset%20-F%20key%3Dunsuccessful-delete%0A-a%20always%2Cexit%20-F%20arch%3Db64%20-S%20unlink%2Cunlinkat%2Crename%2Crenameat%20-F%20exit%3D-EACCES%20-F%20auid%26gt%3B%3D1000%20-F%20auid%21%3Dunset%20-F%20key%3Dunsuccessful-delete%0A-a%20always%2Cexit%20-F%20arch%3Db32%20-S%20unlink%2Cunlinkat%2Crename%2Crenameat%20-F%20exit%3D-EPERM%20-F%20auid%26gt%3B%3D1000%20-F%20auid%21%3Dunset%20-F%20key%3Dunsuccessful-delete%0A-a%20always%2Cexit%20-F%20arch%3Db64%20-S%20unlink%2Cunlinkat%2Crename%2Crenameat%20-F%20exit%3D-EPERM%20-F%20auid%26gt%3B%3D1000%20-F%20auid%21%3Dunset%20-F%20key%3Dunsuccessful-delete
+          source: data:,%23%23%20Unsuccessful%20file%20delete%0A-a%20always%2Cexit%20-F%20arch%3Db32%20-S%20unlink%2Cunlinkat%2Crename%2Crenameat%20-F%20exit%3D-EACCES%20-F%20auid%3E%3D1000%20-F%20auid%21%3Dunset%20-F%20key%3Dunsuccessful-delete%0A-a%20always%2Cexit%20-F%20arch%3Db64%20-S%20unlink%2Cunlinkat%2Crename%2Crenameat%20-F%20exit%3D-EACCES%20-F%20auid%3E%3D1000%20-F%20auid%21%3Dunset%20-F%20key%3Dunsuccessful-delete%0A-a%20always%2Cexit%20-F%20arch%3Db32%20-S%20unlink%2Cunlinkat%2Crename%2Crenameat%20-F%20exit%3D-EPERM%20-F%20auid%3E%3D1000%20-F%20auid%21%3Dunset%20-F%20key%3Dunsuccessful-delete%0A-a%20always%2Cexit%20-F%20arch%3Db64%20-S%20unlink%2Cunlinkat%2Crename%2Crenameat%20-F%20exit%3D-EPERM%20-F%20auid%3E%3D1000%20-F%20auid%21%3Dunset%20-F%20key%3Dunsuccessful-delete%0A
         mode: 0600
         path: /etc/audit/rules.d/30-ospp-v42-4-delete-failed.rules
         overwrite: true

New content has different text for rule 'xccdf_org.ssgproject.content_rule_kernel_module_usb-storage_disabled'.
--- xccdf_org.ssgproject.content_rule_kernel_module_usb-storage_disabled
+++ xccdf_org.ssgproject.content_rule_kernel_module_usb-storage_disabled
@@ -253,6 +253,9 @@
 SRG-OS-000480-GPOS-00227
 
 [reference]:
+SRG-APP-000141-CTR-000315
+
+[reference]:
 RHEL-08-040080
 
 [reference]:

New content has different text for rule 'xccdf_org.ssgproject.content_rule_package_usbguard_installed'.
--- xccdf_org.ssgproject.content_rule_package_usbguard_installed
+++ xccdf_org.ssgproject.content_rule_package_usbguard_installed
@@ -23,6 +23,9 @@
 SRG-OS-000378-GPOS-00163
 
 [reference]:
+SRG-APP-000141-CTR-000315
+
+[reference]:
 RHEL-08-040139
 
 [reference]:

New content has different text for rule 'xccdf_org.ssgproject.content_rule_service_usbguard_enabled'.
--- xccdf_org.ssgproject.content_rule_service_usbguard_enabled
+++ xccdf_org.ssgproject.content_rule_service_usbguard_enabled
@@ -30,6 +30,9 @@
 SRG-OS-000378-GPOS-00163
 
 [reference]:
+SRG-APP-000141-CTR-000315
+
+[reference]:
 RHEL-08-040141
 
 [reference]:

New content has different text for rule 'xccdf_org.ssgproject.content_rule_usbguard_allow_hid_and_hub'.
--- xccdf_org.ssgproject.content_rule_usbguard_allow_hid_and_hub
+++ xccdf_org.ssgproject.content_rule_usbguard_allow_hid_and_hub
@@ -24,6 +24,9 @@
 [reference]:
 SRG-OS-000114-GPOS-00059
 
+[reference]:
+SRG-APP-000092-CTR-000165
+
 [rationale]:
 Without allowing Human Interface Devices, it might not be possible
 to interact with the system. Without allowing hubs, it might not be possible to use any

Select rule oauth_or_oauthclient_token_maxage to satisfy
SRG-APP-000400-CTR-000960.
The default value is 24h (86400 seconds), but the STIG requires 8h
(28800 seconds).
Select rules for to generate audit records for unsuccessful attempts to
delete objects and catergories of information.
Select rule to generate audit records for the use of pt_chown binary.
The rules for control SRG-APP-000141-CTR-000315 were defined as related,
instead of being atually selected.
SRG-APP-000092-CTR-000165 is about setting 'audit' and
'audit_backlog_limit' options. Only one of them was being set.
Select rule USBGuard that authorizes hid and hub devices.
Fix kubernetes remediation for audit_delete_failed.
Make rules `oauth_token_maxage` and `oauthclient_token_maxage` check
the token expiry timeout based on a variable.

Default timeout is 24h, but STIG requires it to be 8h.
@yuumasato
Copy link
Member Author

/test e2e-aws-ocp4-stig
/test e2e-aws-ocp4-stig-node
/test e2e-aws-rhcos4-stig

Copy link

codeclimate bot commented Feb 1, 2024

Code Climate has analyzed commit b05da3d and detected 0 issues on this pull request.

The test coverage on the diff in this pull request is 100.0% (50% is the threshold).

This pull request will bring the total coverage in the repository to 58.3% (0.0% change).

View more on Code Climate.

@yuumasato
Copy link
Member Author

/retest

@rhmdnd
Copy link
Collaborator

rhmdnd commented Feb 3, 2024

Looks like the most recent CI failure was due to an unrelated change that we're already tracking to clean up CI.

@BhargaviGudi
Copy link
Collaborator

/hold for test

@BhargaviGudi
Copy link
Collaborator

BhargaviGudi commented Feb 13, 2024

Verification passed with 4.16.0-0.nightly-2024-02-08-073857 + compliance-operator with compliance-operator code

Please find the testing details below
Scenario 1: ocp4-stig and ocp4-stig-node profile -> PASS

$ oc compliance bind -N test-ocp4 -S default-auto-apply profile/upstream-ocp4-stig profile/upstream-ocp4-stig-node
Creating ScanSettingBinding test-ocp4
$ oc get ssb
NAME        STATUS
test-ocp4   READY
$ oc get suite
NAME        PHASE       RESULT
test-ocp4   LAUNCHING   NOT-AVAILABLE
$ oc get suite -w
NAME        PHASE     RESULT
test-ocp4   RUNNING   NOT-AVAILABLE
test-ocp4   RUNNING   NOT-AVAILABLE
test-ocp4   RUNNING   NOT-AVAILABLE
test-ocp4   AGGREGATING   NOT-AVAILABLE
test-ocp4   AGGREGATING   NOT-AVAILABLE
test-ocp4   AGGREGATING   NOT-AVAILABLE
test-ocp4   DONE          NON-COMPLIANT
test-ocp4   DONE          NON-COMPLIANT
^C$ oc get scan
NAME                             PHASE   RESULT
upstream-ocp4-stig               DONE    NON-COMPLIANT
upstream-ocp4-stig-node-master   DONE    NON-COMPLIANT
upstream-ocp4-stig-node-worker   DONE    NON-COMPLIANT
$ oc get cr
NAME                                                              STATE
upstream-ocp4-stig-api-server-encryption-provider-cipher          Applied
upstream-ocp4-stig-audit-profile-set                              Applied
upstream-ocp4-stig-oauth-or-oauthclient-token-maxage              Applied
upstream-ocp4-stig-project-config-and-template-network-policy     Applied
upstream-ocp4-stig-project-config-and-template-network-policy-1   Applied
upstream-ocp4-stig-project-config-and-template-resource-quota     Applied
upstream-ocp4-stig-project-config-and-template-resource-quota-1   Applied
$ oc get ccr -l compliance.openshift.io/automated-remediation=,compliance.openshift.io/check-status=FAIL
NAME                                                            STATUS   SEVERITY
upstream-ocp4-stig-api-server-encryption-provider-cipher        FAIL     medium
upstream-ocp4-stig-audit-profile-set                            FAIL     medium
upstream-ocp4-stig-oauth-or-oauthclient-token-maxage            FAIL     medium
upstream-ocp4-stig-project-config-and-template-network-policy   FAIL     medium
upstream-ocp4-stig-project-config-and-template-resource-quota   FAIL     medium
$ oc-compliance rerun-now scansettingbinding test-ocp4
Rerunning scans from 'test-ocp4': upstream-ocp4-stig, upstream-ocp4-stig-node-master, upstream-ocp4-stig-node-worker
Re-running scan 'openshift-compliance/upstream-ocp4-stig'
Re-running scan 'openshift-compliance/upstream-ocp4-stig-node-master'
Re-running scan 'openshift-compliance/upstream-ocp4-stig-node-worker'
$ oc get suite -w
NAME        PHASE       RESULT
test-ocp4   LAUNCHING   NOT-AVAILABLE
test-ocp4   RUNNING     NOT-AVAILABLE
test-ocp4   RUNNING     NOT-AVAILABLE
test-ocp4   RUNNING     NOT-AVAILABLE
test-ocp4   AGGREGATING   NOT-AVAILABLE
test-ocp4   AGGREGATING   NOT-AVAILABLE
test-ocp4   AGGREGATING   NOT-AVAILABLE
test-ocp4   DONE          NON-COMPLIANT
test-ocp4   DONE          NON-COMPLIANT
$ oc get scan
NAME                             PHASE   RESULT
upstream-ocp4-stig               DONE    NON-COMPLIANT
upstream-ocp4-stig-node-master   DONE    NON-COMPLIANT
upstream-ocp4-stig-node-worker   DONE    NON-COMPLIANT
$ oc get ccr -l compliance.openshift.io/automated-remediation=
NAME                                                                                    STATUS   SEVERITY
upstream-ocp4-stig-api-server-encryption-provider-cipher                                PASS     medium
upstream-ocp4-stig-audit-error-alert-exists                                             PASS     high
upstream-ocp4-stig-audit-profile-set                                                    PASS     medium
upstream-ocp4-stig-node-master-kubelet-configure-event-creation                         PASS     medium
upstream-ocp4-stig-node-master-kubelet-configure-tls-cipher-suites                      PASS     medium
upstream-ocp4-stig-node-master-kubelet-configure-tls-min-version                        PASS     medium
upstream-ocp4-stig-node-master-kubelet-enable-iptables-util-chains                      PASS     medium
upstream-ocp4-stig-node-master-kubelet-enable-protect-kernel-defaults                   PASS     medium
upstream-ocp4-stig-node-master-kubelet-enable-protect-kernel-sysctl                     PASS     medium
upstream-ocp4-stig-node-master-kubelet-enable-streaming-connections                     PASS     medium
upstream-ocp4-stig-node-master-kubelet-eviction-thresholds-set-hard-imagefs-available   PASS     medium
upstream-ocp4-stig-node-master-kubelet-eviction-thresholds-set-hard-memory-available    PASS     medium
upstream-ocp4-stig-node-master-kubelet-eviction-thresholds-set-hard-nodefs-available    PASS     medium
upstream-ocp4-stig-node-master-kubelet-eviction-thresholds-set-hard-nodefs-inodesfree   PASS     medium
upstream-ocp4-stig-node-worker-kubelet-configure-event-creation                         PASS     medium
upstream-ocp4-stig-node-worker-kubelet-configure-tls-cipher-suites                      PASS     medium
upstream-ocp4-stig-node-worker-kubelet-configure-tls-min-version                        PASS     medium
upstream-ocp4-stig-node-worker-kubelet-enable-iptables-util-chains                      PASS     medium
upstream-ocp4-stig-node-worker-kubelet-enable-protect-kernel-defaults                   PASS     medium
upstream-ocp4-stig-node-worker-kubelet-enable-protect-kernel-sysctl                     PASS     medium
upstream-ocp4-stig-node-worker-kubelet-enable-streaming-connections                     PASS     medium
upstream-ocp4-stig-node-worker-kubelet-eviction-thresholds-set-hard-imagefs-available   PASS     medium
upstream-ocp4-stig-node-worker-kubelet-eviction-thresholds-set-hard-memory-available    PASS     medium
upstream-ocp4-stig-node-worker-kubelet-eviction-thresholds-set-hard-nodefs-available    PASS     medium
upstream-ocp4-stig-node-worker-kubelet-eviction-thresholds-set-hard-nodefs-inodesfree   PASS     medium
upstream-ocp4-stig-oauth-or-oauthclient-token-maxage                                    PASS     medium
upstream-ocp4-stig-project-config-and-template-network-policy                           PASS     medium
upstream-ocp4-stig-project-config-and-template-resource-quota                           PASS     medium
$ oc get ccr -l compliance.openshift.io/automated-remediation=,compliance.openshift.io/check-status=FAIL
No resources found in openshift-compliance namespace.
$ oc get cr
NAME                                                              STATE
upstream-ocp4-stig-api-server-encryption-provider-cipher          Applied
upstream-ocp4-stig-audit-profile-set                              Applied
upstream-ocp4-stig-oauth-or-oauthclient-token-maxage              Applied
upstream-ocp4-stig-project-config-and-template-network-policy     Applied
upstream-ocp4-stig-project-config-and-template-network-policy-1   Applied
upstream-ocp4-stig-project-config-and-template-resource-quota     Applied
upstream-ocp4-stig-project-config-and-template-resource-quota-1   Applied
$ oc delete ssb test-ocp4 
scansettingbinding.compliance.openshift.io "test-ocp4" deleted

Scenario 2: rhcos4-stig profile -> PASS

$ oc compliance bind -N test-rhcos4 -S default-auto-apply profile/upstream-rhcos4-stig
Creating ScanSettingBinding test-rhcos4
$ oc get suite -w
NAME          PHASE       RESULT
test-rhcos4   LAUNCHING   NOT-AVAILABLE
test-rhcos4   LAUNCHING   NOT-AVAILABLE
test-rhcos4   RUNNING     NOT-AVAILABLE
test-rhcos4   RUNNING     NOT-AVAILABLE
test-rhcos4   AGGREGATING   NOT-AVAILABLE
test-rhcos4   AGGREGATING   NOT-AVAILABLE
test-rhcos4   DONE          NON-COMPLIANT
$ oc get scan
NAME                          PHASE   RESULT
upstream-rhcos4-stig-master   DONE    NON-COMPLIANT
upstream-rhcos4-stig-worker   DONE    NON-COMPLIANT
$ oc get cr | grep MissingDependencies
upstream-rhcos4-stig-master-usbguard-allow-hid-and-hub                                     MissingDependencies
upstream-rhcos4-stig-worker-usbguard-allow-hid-and-hub                                     MissingDependencies
$ oc get ccr -l compliance.openshift.io/automated-remediation=,compliance.openshift.io/check-status=FAIL
NAME                                                                                       STATUS   SEVERITY
upstream-rhcos4-stig-master-audit-access-failed                                            FAIL     medium
upstream-rhcos4-stig-master-audit-create-failed                                            FAIL     medium
upstream-rhcos4-stig-master-audit-delete-failed                                            FAIL     medium
upstream-rhcos4-stig-master-audit-immutable-login-uids                                     FAIL     medium
upstream-rhcos4-stig-master-audit-modify-failed                                            FAIL     medium
upstream-rhcos4-stig-master-audit-rules-dac-modification-chmod                             FAIL     medium
upstream-rhcos4-stig-master-audit-rules-dac-modification-chown                             FAIL     medium
upstream-rhcos4-stig-master-audit-rules-dac-modification-fchmod                            FAIL     medium
upstream-rhcos4-stig-master-audit-rules-dac-modification-fchmodat                          FAIL     medium
upstream-rhcos4-stig-master-audit-rules-dac-modification-fchown                            FAIL     medium
upstream-rhcos4-stig-master-audit-rules-dac-modification-fchownat                          FAIL     medium
upstream-rhcos4-stig-master-audit-rules-dac-modification-fremovexattr                      FAIL     medium
upstream-rhcos4-stig-master-audit-rules-dac-modification-fsetxattr                         FAIL     medium
upstream-rhcos4-stig-master-audit-rules-dac-modification-lchown                            FAIL     medium
upstream-rhcos4-stig-master-audit-rules-dac-modification-lremovexattr                      FAIL     medium
upstream-rhcos4-stig-master-audit-rules-dac-modification-lsetxattr                         FAIL     medium
upstream-rhcos4-stig-master-audit-rules-dac-modification-removexattr                       FAIL     medium
upstream-rhcos4-stig-master-audit-rules-dac-modification-setxattr                          FAIL     medium
upstream-rhcos4-stig-master-audit-rules-dac-modification-umount                            FAIL     medium
upstream-rhcos4-stig-master-audit-rules-dac-modification-umount2                           FAIL     medium
upstream-rhcos4-stig-master-audit-rules-execution-chcon                                    FAIL     medium
upstream-rhcos4-stig-master-audit-rules-execution-semanage                                 FAIL     medium
upstream-rhcos4-stig-master-audit-rules-execution-setfiles                                 FAIL     medium
upstream-rhcos4-stig-master-audit-rules-execution-setsebool                                FAIL     medium
upstream-rhcos4-stig-master-audit-rules-file-deletion-events-rename                        FAIL     medium
upstream-rhcos4-stig-master-audit-rules-file-deletion-events-renameat                      FAIL     medium
upstream-rhcos4-stig-master-audit-rules-file-deletion-events-rmdir                         FAIL     medium
upstream-rhcos4-stig-master-audit-rules-file-deletion-events-unlink                        FAIL     medium
upstream-rhcos4-stig-master-audit-rules-file-deletion-events-unlinkat                      FAIL     medium
upstream-rhcos4-stig-master-audit-rules-immutable                                          FAIL     medium
upstream-rhcos4-stig-master-audit-rules-kernel-module-loading-delete                       FAIL     medium
upstream-rhcos4-stig-master-audit-rules-kernel-module-loading-finit                        FAIL     medium
upstream-rhcos4-stig-master-audit-rules-kernel-module-loading-init                         FAIL     medium
upstream-rhcos4-stig-master-audit-rules-login-events-faillock                              FAIL     medium
upstream-rhcos4-stig-master-audit-rules-login-events-lastlog                               FAIL     medium
upstream-rhcos4-stig-master-audit-rules-login-events-tallylog                              FAIL     medium
upstream-rhcos4-stig-master-audit-rules-media-export                                       FAIL     medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-chage                          FAIL     medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-chsh                           FAIL     medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-crontab                        FAIL     medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-dbus-daemon-launch-helper      FAIL     medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-fusermount                     FAIL     medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-fusermount3                    FAIL     medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-gpasswd                        FAIL     medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-grub2-set-bootflag             FAIL     medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-mount                          FAIL     medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-mount-nfs                      FAIL     medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-newgrp                         FAIL     medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-pam-timestamp-check            FAIL     medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-passwd                         FAIL     medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-pkexec                         FAIL     medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-polkit-helper                  FAIL     medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-postdrop                       FAIL     medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-postqueue                      FAIL     medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-pt-chown                       FAIL     medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-ssh-keysign                    FAIL     medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-sssd-krb5-child                FAIL     medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-sssd-ldap-child                FAIL     medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-sssd-proxy-child               FAIL     medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-sssd-selinux-child             FAIL     medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-su                             FAIL     medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-sudo                           FAIL     medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-sudoedit                       FAIL     medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-umount                         FAIL     medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-unix-chkpwd                    FAIL     medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-userhelper                     FAIL     medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-utempter                       FAIL     medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-write                          FAIL     medium
upstream-rhcos4-stig-master-audit-rules-session-events                                     FAIL     medium
upstream-rhcos4-stig-master-audit-rules-sysadmin-actions                                   FAIL     medium
upstream-rhcos4-stig-master-audit-rules-unsuccessful-file-modification-creat               FAIL     medium
upstream-rhcos4-stig-master-audit-rules-unsuccessful-file-modification-ftruncate           FAIL     medium
upstream-rhcos4-stig-master-audit-rules-unsuccessful-file-modification-open                FAIL     medium
upstream-rhcos4-stig-master-audit-rules-unsuccessful-file-modification-open-by-handle-at   FAIL     medium
upstream-rhcos4-stig-master-audit-rules-unsuccessful-file-modification-openat              FAIL     medium
upstream-rhcos4-stig-master-audit-rules-unsuccessful-file-modification-rename              FAIL     medium
upstream-rhcos4-stig-master-audit-rules-unsuccessful-file-modification-renameat            FAIL     medium
upstream-rhcos4-stig-master-audit-rules-unsuccessful-file-modification-truncate            FAIL     medium
upstream-rhcos4-stig-master-audit-rules-unsuccessful-file-modification-unlink              FAIL     medium
upstream-rhcos4-stig-master-audit-rules-unsuccessful-file-modification-unlinkat            FAIL     medium
upstream-rhcos4-stig-master-audit-rules-usergroup-modification                             FAIL     medium
upstream-rhcos4-stig-master-audit-rules-usergroup-modification-group                       FAIL     medium
upstream-rhcos4-stig-master-audit-rules-usergroup-modification-gshadow                     FAIL     medium
upstream-rhcos4-stig-master-audit-rules-usergroup-modification-opasswd                     FAIL     medium
upstream-rhcos4-stig-master-audit-rules-usergroup-modification-passwd                      FAIL     medium
upstream-rhcos4-stig-master-audit-rules-usergroup-modification-shadow                      FAIL     medium
upstream-rhcos4-stig-master-auditd-data-disk-error-action                                  FAIL     medium
upstream-rhcos4-stig-master-coreos-audit-backlog-limit-kernel-argument                     FAIL     medium
upstream-rhcos4-stig-master-coreos-audit-option                                            FAIL     medium
upstream-rhcos4-stig-master-coreos-page-poison-kernel-argument                             FAIL     medium
upstream-rhcos4-stig-master-coreos-slub-debug-kernel-argument                              FAIL     medium
upstream-rhcos4-stig-master-kernel-module-usb-storage-disabled                             FAIL     medium
upstream-rhcos4-stig-master-package-usbguard-installed                                     FAIL     medium
upstream-rhcos4-stig-master-service-sshd-disabled                                          FAIL     high
upstream-rhcos4-stig-master-service-usbguard-enabled                                       FAIL     medium
upstream-rhcos4-stig-master-sshd-disable-root-login                                        FAIL     medium
upstream-rhcos4-stig-master-sysctl-kernel-dmesg-restrict                                   FAIL     low
upstream-rhcos4-stig-master-sysctl-kernel-perf-event-paranoid                              FAIL     low
upstream-rhcos4-stig-master-sysctl-kernel-randomize-va-space                               FAIL     medium
upstream-rhcos4-stig-master-usbguard-allow-hid-and-hub                                     FAIL     medium
upstream-rhcos4-stig-worker-audit-access-failed                                            FAIL     medium
upstream-rhcos4-stig-worker-audit-create-failed                                            FAIL     medium
upstream-rhcos4-stig-worker-audit-delete-failed                                            FAIL     medium
upstream-rhcos4-stig-worker-audit-immutable-login-uids                                     FAIL     medium
upstream-rhcos4-stig-worker-audit-modify-failed                                            FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-dac-modification-chmod                             FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-dac-modification-chown                             FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-dac-modification-fchmod                            FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-dac-modification-fchmodat                          FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-dac-modification-fchown                            FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-dac-modification-fchownat                          FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-dac-modification-fremovexattr                      FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-dac-modification-fsetxattr                         FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-dac-modification-lchown                            FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-dac-modification-lremovexattr                      FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-dac-modification-lsetxattr                         FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-dac-modification-removexattr                       FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-dac-modification-setxattr                          FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-dac-modification-umount                            FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-dac-modification-umount2                           FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-execution-chcon                                    FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-execution-semanage                                 FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-execution-setfiles                                 FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-execution-setsebool                                FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-file-deletion-events-rename                        FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-file-deletion-events-renameat                      FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-file-deletion-events-rmdir                         FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-file-deletion-events-unlink                        FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-file-deletion-events-unlinkat                      FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-immutable                                          FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-kernel-module-loading-delete                       FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-kernel-module-loading-finit                        FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-kernel-module-loading-init                         FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-login-events-faillock                              FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-login-events-lastlog                               FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-login-events-tallylog                              FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-media-export                                       FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-chage                          FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-chsh                           FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-crontab                        FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-dbus-daemon-launch-helper      FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-fusermount                     FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-fusermount3                    FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-gpasswd                        FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-grub2-set-bootflag             FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-mount                          FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-mount-nfs                      FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-newgrp                         FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-pam-timestamp-check            FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-passwd                         FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-pkexec                         FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-polkit-helper                  FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-postdrop                       FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-postqueue                      FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-pt-chown                       FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-ssh-keysign                    FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-sssd-krb5-child                FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-sssd-ldap-child                FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-sssd-proxy-child               FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-sssd-selinux-child             FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-su                             FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-sudo                           FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-sudoedit                       FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-umount                         FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-unix-chkpwd                    FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-userhelper                     FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-utempter                       FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-write                          FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-session-events                                     FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-sysadmin-actions                                   FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-unsuccessful-file-modification-creat               FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-unsuccessful-file-modification-ftruncate           FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-unsuccessful-file-modification-open                FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-unsuccessful-file-modification-open-by-handle-at   FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-unsuccessful-file-modification-openat              FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-unsuccessful-file-modification-rename              FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-unsuccessful-file-modification-renameat            FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-unsuccessful-file-modification-truncate            FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-unsuccessful-file-modification-unlink              FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-unsuccessful-file-modification-unlinkat            FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-usergroup-modification                             FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-usergroup-modification-group                       FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-usergroup-modification-gshadow                     FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-usergroup-modification-opasswd                     FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-usergroup-modification-passwd                      FAIL     medium
upstream-rhcos4-stig-worker-audit-rules-usergroup-modification-shadow                      FAIL     medium
upstream-rhcos4-stig-worker-auditd-data-disk-error-action                                  FAIL     medium
upstream-rhcos4-stig-worker-coreos-audit-backlog-limit-kernel-argument                     FAIL     medium
upstream-rhcos4-stig-worker-coreos-audit-option                                            FAIL     medium
upstream-rhcos4-stig-worker-coreos-page-poison-kernel-argument                             FAIL     medium
upstream-rhcos4-stig-worker-coreos-slub-debug-kernel-argument                              FAIL     medium
upstream-rhcos4-stig-worker-kernel-module-usb-storage-disabled                             FAIL     medium
upstream-rhcos4-stig-worker-package-usbguard-installed                                     FAIL     medium
upstream-rhcos4-stig-worker-service-sshd-disabled                                          FAIL     high
upstream-rhcos4-stig-worker-service-usbguard-enabled                                       FAIL     medium
upstream-rhcos4-stig-worker-sshd-disable-root-login                                        FAIL     medium
upstream-rhcos4-stig-worker-sysctl-kernel-dmesg-restrict                                   FAIL     low
upstream-rhcos4-stig-worker-sysctl-kernel-perf-event-paranoid                              FAIL     low
upstream-rhcos4-stig-worker-sysctl-kernel-randomize-va-space                               FAIL     medium
upstream-rhcos4-stig-worker-usbguard-allow-hid-and-hub                                     FAIL     medium

First rescan:

$ oc-compliance rerun-now scansettingbinding test-rhcos4
Rerunning scans from 'test-rhcos4': upstream-rhcos4-stig-master, upstream-rhcos4-stig-worker
Re-running scan 'openshift-compliance/upstream-rhcos4-stig-master'
Re-running scan 'openshift-compliance/upstream-rhcos4-stig-worker'
$ oc get suite -w
NAME          PHASE     RESULT
test-rhcos4   RUNNING   NOT-AVAILABLE
$ oc get mcp
NAME     CONFIG                                             UPDATED   UPDATING   DEGRADED   MACHINECOUNT   READYMACHINECOUNT   UPDATEDMACHINECOUNT   DEGRADEDMACHINECOUNT   AGE
master   rendered-master-7fc95e973deb54d1c76064360d78e8ec   True      False      False      3              3                   3                     0                      105m
worker   rendered-worker-252b6c8f22ecac2d97ca123c439bc3f1   True      False      False      3              3                   3                     0                      105m
There are INCONSISTENT rules after first rescan
$ oc get ccr -l compliance.openshift.io/inconsistent-check
NAME                                                                                       STATUS         SEVERITY
upstream-rhcos4-stig-master-audit-access-failed                                            INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-create-failed                                            INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-delete-failed                                            INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-immutable-login-uids                                     INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-modify-failed                                            INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-dac-modification-chmod                             INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-dac-modification-chown                             INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-dac-modification-fchmod                            INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-dac-modification-fchmodat                          INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-dac-modification-fchown                            INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-dac-modification-fchownat                          INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-dac-modification-fremovexattr                      INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-dac-modification-fsetxattr                         INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-dac-modification-lchown                            INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-dac-modification-lremovexattr                      INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-dac-modification-lsetxattr                         INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-dac-modification-removexattr                       INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-dac-modification-setxattr                          INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-dac-modification-umount                            INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-dac-modification-umount2                           INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-execution-chcon                                    INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-execution-semanage                                 INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-execution-setfiles                                 INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-execution-setsebool                                INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-file-deletion-events-rename                        INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-file-deletion-events-renameat                      INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-file-deletion-events-rmdir                         INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-file-deletion-events-unlink                        INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-file-deletion-events-unlinkat                      INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-immutable                                          INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-kernel-module-loading-delete                       INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-kernel-module-loading-finit                        INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-kernel-module-loading-init                         INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-login-events-faillock                              INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-login-events-lastlog                               INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-login-events-tallylog                              INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-media-export                                       INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-chage                          INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-chsh                           INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-crontab                        INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-dbus-daemon-launch-helper      INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-fusermount                     INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-fusermount3                    INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-gpasswd                        INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-grub2-set-bootflag             INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-mount                          INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-mount-nfs                      INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-newgrp                         INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-pam-timestamp-check            INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-passwd                         INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-pkexec                         INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-polkit-helper                  INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-postdrop                       INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-postqueue                      INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-pt-chown                       INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-ssh-keysign                    INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-sssd-krb5-child                INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-sssd-ldap-child                INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-sssd-proxy-child               INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-sssd-selinux-child             INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-su                             INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-sudo                           INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-sudoedit                       INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-umount                         INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-unix-chkpwd                    INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-userhelper                     INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-utempter                       INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-privileged-commands-write                          INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-session-events                                     INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-sysadmin-actions                                   INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-unsuccessful-file-modification-creat               INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-unsuccessful-file-modification-ftruncate           INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-unsuccessful-file-modification-open                INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-unsuccessful-file-modification-open-by-handle-at   INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-unsuccessful-file-modification-openat              INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-unsuccessful-file-modification-rename              INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-unsuccessful-file-modification-renameat            INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-unsuccessful-file-modification-truncate            INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-unsuccessful-file-modification-unlink              INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-unsuccessful-file-modification-unlinkat            INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-usergroup-modification                             INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-usergroup-modification-group                       INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-usergroup-modification-gshadow                     INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-usergroup-modification-opasswd                     INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-usergroup-modification-passwd                      INCONSISTENT   medium
upstream-rhcos4-stig-master-audit-rules-usergroup-modification-shadow                      INCONSISTENT   medium
upstream-rhcos4-stig-master-auditd-data-disk-error-action                                  INCONSISTENT   medium
upstream-rhcos4-stig-master-configure-usbguard-auditbackend                                INCONSISTENT   low
upstream-rhcos4-stig-master-coreos-audit-backlog-limit-kernel-argument                     INCONSISTENT   medium
upstream-rhcos4-stig-master-coreos-audit-option                                            INCONSISTENT   medium
upstream-rhcos4-stig-master-coreos-page-poison-kernel-argument                             INCONSISTENT   medium
upstream-rhcos4-stig-master-coreos-slub-debug-kernel-argument                              INCONSISTENT   medium
upstream-rhcos4-stig-master-kernel-module-usb-storage-disabled                             INCONSISTENT   medium
upstream-rhcos4-stig-master-package-usbguard-installed                                     INCONSISTENT   medium
upstream-rhcos4-stig-master-service-sshd-disabled                                          INCONSISTENT   high
upstream-rhcos4-stig-master-sshd-disable-root-login                                        INCONSISTENT   medium
upstream-rhcos4-stig-master-sysctl-kernel-dmesg-restrict                                   INCONSISTENT   low
upstream-rhcos4-stig-master-sysctl-kernel-perf-event-paranoid                              INCONSISTENT   low
upstream-rhcos4-stig-master-sysctl-kernel-randomize-va-space                               INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-access-failed                                            INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-create-failed                                            INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-delete-failed                                            INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-immutable-login-uids                                     INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-modify-failed                                            INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-dac-modification-chmod                             INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-dac-modification-chown                             INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-dac-modification-fchmod                            INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-dac-modification-fchmodat                          INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-dac-modification-fchown                            INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-dac-modification-fchownat                          INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-dac-modification-fremovexattr                      INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-dac-modification-fsetxattr                         INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-dac-modification-lchown                            INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-dac-modification-lremovexattr                      INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-dac-modification-lsetxattr                         INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-dac-modification-removexattr                       INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-dac-modification-setxattr                          INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-dac-modification-umount                            INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-dac-modification-umount2                           INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-execution-chcon                                    INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-execution-semanage                                 INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-execution-setfiles                                 INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-execution-setsebool                                INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-file-deletion-events-rename                        INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-file-deletion-events-renameat                      INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-file-deletion-events-rmdir                         INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-file-deletion-events-unlink                        INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-file-deletion-events-unlinkat                      INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-immutable                                          INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-kernel-module-loading-delete                       INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-kernel-module-loading-finit                        INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-kernel-module-loading-init                         INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-login-events-faillock                              INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-login-events-lastlog                               INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-login-events-tallylog                              INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-media-export                                       INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-chage                          INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-chsh                           INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-crontab                        INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-dbus-daemon-launch-helper      INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-fusermount                     INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-fusermount3                    INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-gpasswd                        INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-grub2-set-bootflag             INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-mount                          INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-mount-nfs                      INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-newgrp                         INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-pam-timestamp-check            INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-passwd                         INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-pkexec                         INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-polkit-helper                  INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-postdrop                       INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-postqueue                      INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-pt-chown                       INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-ssh-keysign                    INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-sssd-krb5-child                INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-sssd-ldap-child                INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-sssd-proxy-child               INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-sssd-selinux-child             INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-su                             INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-sudo                           INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-sudoedit                       INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-umount                         INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-unix-chkpwd                    INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-userhelper                     INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-utempter                       INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-privileged-commands-write                          INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-session-events                                     INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-sysadmin-actions                                   INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-unsuccessful-file-modification-creat               INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-unsuccessful-file-modification-ftruncate           INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-unsuccessful-file-modification-open                INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-unsuccessful-file-modification-open-by-handle-at   INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-unsuccessful-file-modification-openat              INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-unsuccessful-file-modification-rename              INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-unsuccessful-file-modification-renameat            INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-unsuccessful-file-modification-truncate            INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-unsuccessful-file-modification-unlink              INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-unsuccessful-file-modification-unlinkat            INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-usergroup-modification                             INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-usergroup-modification-group                       INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-usergroup-modification-gshadow                     INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-usergroup-modification-opasswd                     INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-usergroup-modification-passwd                      INCONSISTENT   medium
upstream-rhcos4-stig-worker-audit-rules-usergroup-modification-shadow                      INCONSISTENT   medium
upstream-rhcos4-stig-worker-auditd-data-disk-error-action                                  INCONSISTENT   medium
upstream-rhcos4-stig-worker-configure-usbguard-auditbackend                                INCONSISTENT   low
upstream-rhcos4-stig-worker-coreos-audit-backlog-limit-kernel-argument                     INCONSISTENT   medium
upstream-rhcos4-stig-worker-coreos-audit-option                                            INCONSISTENT   medium
upstream-rhcos4-stig-worker-coreos-page-poison-kernel-argument                             INCONSISTENT   medium
upstream-rhcos4-stig-worker-coreos-slub-debug-kernel-argument                              INCONSISTENT   medium
upstream-rhcos4-stig-worker-kernel-module-usb-storage-disabled                             INCONSISTENT   medium
upstream-rhcos4-stig-worker-package-usbguard-installed                                     INCONSISTENT   medium
upstream-rhcos4-stig-worker-service-sshd-disabled                                          INCONSISTENT   high
upstream-rhcos4-stig-worker-sshd-disable-root-login                                        INCONSISTENT   medium
upstream-rhcos4-stig-worker-sysctl-kernel-dmesg-restrict                                   INCONSISTENT   low
upstream-rhcos4-stig-worker-sysctl-kernel-perf-event-paranoid                              INCONSISTENT   low
upstream-rhcos4-stig-worker-sysctl-kernel-randomize-va-space                               INCONSISTENT   medium
$ oc get cr | grep MissingDependencies
upstream-rhcos4-stig-master-service-usbguard-enabled                                       MissingDependencies
upstream-rhcos4-stig-master-usbguard-allow-hid-and-hub                                     MissingDependencies
upstream-rhcos4-stig-worker-service-usbguard-enabled                                       MissingDependencies
upstream-rhcos4-stig-worker-usbguard-allow-hid-and-hub                                     MissingDependencies
$ oc get ccr -l compliance.openshift.io/automated-remediation=,compliance.openshift.io/check-status=FAIL
NAME                                                     STATUS   SEVERITY
upstream-rhcos4-stig-master-service-usbguard-enabled     FAIL     medium
upstream-rhcos4-stig-master-usbguard-allow-hid-and-hub   FAIL     medium
upstream-rhcos4-stig-worker-service-usbguard-enabled     FAIL     medium
upstream-rhcos4-stig-worker-usbguard-allow-hid-and-hub   FAIL     medium

Second rescan:

$ oc-compliance rerun-now scansettingbinding test-rhcos4
Rerunning scans from 'test-rhcos4': upstream-rhcos4-stig-master, upstream-rhcos4-stig-worker
Re-running scan 'openshift-compliance/upstream-rhcos4-stig-master'
Re-running scan 'openshift-compliance/upstream-rhcos4-stig-worker'
$ oc get suite
NAME          PHASE       RESULT
test-rhcos4   LAUNCHING   NOT-AVAILABLE
$ oc get suite -w
NAME          PHASE     RESULT
test-rhcos4   RUNNING   NOT-AVAILABLE
test-rhcos4   RUNNING   NOT-AVAILABLE
test-rhcos4   AGGREGATING   NOT-AVAILABLE
test-rhcos4   AGGREGATING   NOT-AVAILABLE
test-rhcos4   DONE          NON-COMPLIANT
test-rhcos4   DONE          NON-COMPLIANT
$ oc get mcp
NAME     CONFIG                                             UPDATED   UPDATING   DEGRADED   MACHINECOUNT   READYMACHINECOUNT   UPDATEDMACHINECOUNT   DEGRADEDMACHINECOUNT   AGE
master   rendered-master-27b1bdefb5066d2bf20b2c8e4190b335   True      False      False      3              3                   3                     0                      130m
worker   rendered-worker-3c5fdf456f0ec1faa366f731fde315a7   True      False      False      3              3                   3                     0                      130m
$ oc get ccr -l compliance.openshift.io/automated-remediation=,compliance.openshift.io/check-status=FAIL
NAME                                                          STATUS   SEVERITY
upstream-rhcos4-stig-master-configure-usbguard-auditbackend   FAIL     low
upstream-rhcos4-stig-master-service-usbguard-enabled          FAIL     medium
upstream-rhcos4-stig-master-usbguard-allow-hid-and-hub        FAIL     medium
upstream-rhcos4-stig-worker-configure-usbguard-auditbackend   FAIL     low
upstream-rhcos4-stig-worker-service-usbguard-enabled          FAIL     medium
upstream-rhcos4-stig-worker-usbguard-allow-hid-and-hub        FAIL     medium
$ oc get cr | grep MissingDependencies
$ oc get ccr -l compliance.openshift.io/inconsistent-check
No resources found in openshift-compliance namespace.
$ oc get suite
NAME          PHASE   RESULT
test-rhcos4   DONE    NON-COMPLIANT

Third rescan:

$ oc-compliance rerun-now scansettingbinding test-rhcos4
Rerunning scans from 'test-rhcos4': upstream-rhcos4-stig-master, upstream-rhcos4-stig-worker
Re-running scan 'openshift-compliance/upstream-rhcos4-stig-master'
Re-running scan 'openshift-compliance/upstream-rhcos4-stig-worker'
$ oc get mcp
NAME     CONFIG                                             UPDATED   UPDATING   DEGRADED   MACHINECOUNT   READYMACHINECOUNT   UPDATEDMACHINECOUNT   DEGRADEDMACHINECOUNT   AGE
master   rendered-master-27b1bdefb5066d2bf20b2c8e4190b335   True      False      False      3              3                   3                     0                      133m
worker   rendered-worker-3c5fdf456f0ec1faa366f731fde315a7   True      False      False      3              3                   3                     0                      133m
$ oc get suite
NAME          PHASE   RESULT
test-rhcos4   DONE    COMPLIANT
$ oc get ccr -l compliance.openshift.io/automated-remediation=,compliance.openshift.io/check-status=FAIL
No resources found in openshift-compliance namespace.
$ oc get ccr -l compliance.openshift.io/inconsistent-check
No resources found in openshift-compliance namespace.

@BhargaviGudi
Copy link
Collaborator

/unhold
/label qe-approved

Copy link

openshift-ci bot commented Feb 13, 2024

@BhargaviGudi: The label(s) qe-approved cannot be applied, because the repository doesn't have them.

In response to this:

/unhold
/label qe-approved

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

@openshift-ci openshift-ci bot removed the do-not-merge/hold Used by openshift-ci-robot bot. label Feb 13, 2024
@rhmdnd
Copy link
Collaborator

rhmdnd commented Feb 13, 2024

/test

Copy link

openshift-ci bot commented Feb 13, 2024

@rhmdnd: The /test command needs one or more targets.
The following commands are available to trigger required jobs:

  • /test 4.13-e2e-aws-ocp4-cis
  • /test 4.13-e2e-aws-ocp4-cis-node
  • /test 4.13-e2e-aws-ocp4-e8
  • /test 4.13-e2e-aws-ocp4-high
  • /test 4.13-e2e-aws-ocp4-high-node
  • /test 4.13-e2e-aws-ocp4-moderate
  • /test 4.13-e2e-aws-ocp4-moderate-node
  • /test 4.13-e2e-aws-ocp4-pci-dss
  • /test 4.13-e2e-aws-ocp4-pci-dss-node
  • /test 4.13-e2e-aws-ocp4-stig
  • /test 4.13-e2e-aws-ocp4-stig-node
  • /test 4.13-e2e-aws-rhcos4-e8
  • /test 4.13-e2e-aws-rhcos4-high
  • /test 4.13-e2e-aws-rhcos4-moderate
  • /test 4.13-e2e-aws-rhcos4-stig
  • /test 4.13-images
  • /test 4.14-images
  • /test 4.15-e2e-aws-ocp4-cis
  • /test 4.15-e2e-aws-ocp4-cis-node
  • /test 4.15-e2e-aws-ocp4-e8
  • /test 4.15-e2e-aws-ocp4-high
  • /test 4.15-e2e-aws-ocp4-high-node
  • /test 4.15-e2e-aws-ocp4-moderate
  • /test 4.15-e2e-aws-ocp4-moderate-node
  • /test 4.15-e2e-aws-ocp4-pci-dss
  • /test 4.15-e2e-aws-ocp4-pci-dss-node
  • /test 4.15-e2e-aws-ocp4-stig
  • /test 4.15-e2e-aws-ocp4-stig-node
  • /test 4.15-e2e-aws-rhcos4-e8
  • /test 4.15-e2e-aws-rhcos4-high
  • /test 4.15-e2e-aws-rhcos4-moderate
  • /test 4.15-e2e-aws-rhcos4-stig
  • /test 4.15-images
  • /test 4.16-e2e-aws-ocp4-cis
  • /test 4.16-e2e-aws-ocp4-cis-node
  • /test 4.16-e2e-aws-ocp4-e8
  • /test 4.16-e2e-aws-ocp4-high
  • /test 4.16-e2e-aws-ocp4-high-node
  • /test 4.16-e2e-aws-ocp4-moderate
  • /test 4.16-e2e-aws-ocp4-moderate-node
  • /test 4.16-e2e-aws-ocp4-pci-dss
  • /test 4.16-e2e-aws-ocp4-pci-dss-node
  • /test 4.16-e2e-aws-ocp4-stig
  • /test 4.16-e2e-aws-ocp4-stig-node
  • /test 4.16-e2e-aws-rhcos4-e8
  • /test 4.16-e2e-aws-rhcos4-high
  • /test 4.16-e2e-aws-rhcos4-moderate
  • /test 4.16-e2e-aws-rhcos4-stig
  • /test 4.16-images
  • /test e2e-aws-ocp4-cis
  • /test e2e-aws-ocp4-cis-node
  • /test e2e-aws-ocp4-e8
  • /test e2e-aws-ocp4-high
  • /test e2e-aws-ocp4-high-node
  • /test e2e-aws-ocp4-moderate
  • /test e2e-aws-ocp4-moderate-node
  • /test e2e-aws-ocp4-pci-dss
  • /test e2e-aws-ocp4-pci-dss-node
  • /test e2e-aws-ocp4-stig
  • /test e2e-aws-ocp4-stig-node
  • /test e2e-aws-rhcos4-e8
  • /test e2e-aws-rhcos4-high
  • /test e2e-aws-rhcos4-moderate
  • /test e2e-aws-rhcos4-stig
  • /test images

Use /test all to run the following jobs that were automatically triggered:

  • pull-ci-ComplianceAsCode-content-master-4.13-images
  • pull-ci-ComplianceAsCode-content-master-4.14-images
  • pull-ci-ComplianceAsCode-content-master-4.15-images
  • pull-ci-ComplianceAsCode-content-master-4.16-images
  • pull-ci-ComplianceAsCode-content-master-images

In response to this:

/test

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

@rhmdnd
Copy link
Collaborator

rhmdnd commented Feb 13, 2024

/test 4.15-e2e-aws-ocp4-stig
/test 4.16-e2e-aws-ocp4-stig
/test 4.13-e2e-aws-ocp4-stig
/test 4.15-e2e-aws-ocp4-stig-node
/test 4.16-e2e-aws-ocp4-stig-node
/test 4.13-e2e-aws-ocp4-stig-node

Copy link
Collaborator

@rhmdnd rhmdnd left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/lgtm

Copy link

openshift-ci bot commented Feb 13, 2024

@yuumasato: The following tests failed, say /retest to rerun all failed tests or /retest-required to rerun all mandatory failed tests:

Test name Commit Details Required Rerun command
ci/prow/e2e-aws-rhcos4-stig b05da3d link true /test e2e-aws-rhcos4-stig
ci/prow/4.16-e2e-aws-ocp4-stig b05da3d link true /test 4.16-e2e-aws-ocp4-stig

Full PR test history. Your PR dashboard.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. I understand the commands that are listed here.

@rhmdnd
Copy link
Collaborator

rhmdnd commented Feb 13, 2024

The 4.16 failure was unrelated and is being fixed in #11545
The rhcos4 failure was fixed in #11544

Copy link
Collaborator

@rhmdnd rhmdnd left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/lgtm

@rhmdnd rhmdnd merged commit 4539cdd into ComplianceAsCode:master Feb 13, 2024
46 of 52 checks passed
@yuumasato yuumasato deleted the fix_stig_ctr_selections branch February 14, 2024 15:57
@Mab879 Mab879 added this to the 0.1.72 milestone May 16, 2024
@Mab879 Mab879 added the Update Profile Issues or pull requests related to Profiles updates. label May 16, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
OpenShift OpenShift product related. STIG STIG Benchmark related. Update Profile Issues or pull requests related to Profiles updates.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants