Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Review CIS RHEL8 v3.0.0 Section 1 - Initial Setup #11445

Merged
merged 20 commits into from
Jan 17, 2024

Conversation

marcusburghardt
Copy link
Member

Description:

Review the cis_rhel8.yml control file and updated the Section 1 - Initial Setup in alignment to CIS RHEL 8 v3.0.0.
The references in related rules were also updated.

Rationale:

Keep RHEL 8 profiles updated with CIS RHEL 8 last version.

Review Hints:

The easiest way is to open the CIS RHEL8 v3.0.0 policy and compare the changes in commits with the respective requirements.

1.1.1 Configure Filesystem Kernel Modules
New requirements were included to disable more file system modules.
4 new rules were included in the control file while other three rules
only had their references updated.
1.1.2 Configure Filesystem Partitions
Requirementes related to quota were removed. Others were reorganized.
References were updated in related rules.
This commit concludes the review of CIS RHEL8 1.1 - Filesystem.
1.2 Configure Software and Patch Management
References were updated in related rules.
1.3 Configure Secure Boot Settings
Requirements related to AIDE were moved to section 5. Section 5 will be
reviewed after.
References were updated in related rules.
Rules related to AIDE were moved to section 5 to be reviewed after,
but their references are already updated.
1.4 Configure Additional Process Hardening
References were updated in related rules.
Requirements for authentication in emergency and singleuser modes were
dropped.
1.5 - Mandatory Access Control
1.5.1 - Configure SELinux
References were updated in related rules.
1.6 - Configure system wide crypto policy
3 new requirements were included. These new requirements are in pending
to be better investigated.
Reference was updated in related rule.
1.7 - Configure Command Line Warning Banners
Only minor updates in titles.
1.8 - Configure GNOME Display Manager
New requirements were included but there were already rules for them.
References were updated in related rules.
This commit concludes the review of CIS RHEL8 v3.0.0 - Section 1.
@marcusburghardt marcusburghardt added RHEL8 Red Hat Enterprise Linux 8 product related. CIS CIS Benchmark related. labels Jan 16, 2024
@marcusburghardt marcusburghardt added this to the 0.1.72 milestone Jan 16, 2024
@marcusburghardt marcusburghardt requested a review from a team as a code owner January 16, 2024 09:29
Copy link

Start a new ephemeral environment with changes proposed in this pull request:

Fedora Environment
Open in Gitpod

Oracle Linux 8 Environment
Open in Gitpod

Copy link

codeclimate bot commented Jan 16, 2024

Code Climate has analyzed commit 6f4fa95 and detected 0 issues on this pull request.

The test coverage on the diff in this pull request is 100.0% (50% is the threshold).

This pull request will bring the total coverage in the repository to 58.5% (0.0% change).

View more on Code Climate.

@jan-cerny jan-cerny self-assigned this Jan 17, 2024
Copy link
Collaborator

@jan-cerny jan-cerny left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I have compared the changes with the PDF version of the CIS RHEL8 Benchmark v3.0.0.

@jan-cerny jan-cerny merged commit 7b68e78 into ComplianceAsCode:master Jan 17, 2024
38 checks passed
evgenyz added a commit to evgenyz/content that referenced this pull request Jan 18, 2024
@vojtapolasek vojtapolasek added the Update Profile Issues or pull requests related to Profiles updates. label Feb 9, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
CIS CIS Benchmark related. RHEL8 Red Hat Enterprise Linux 8 product related. Update Profile Issues or pull requests related to Profiles updates.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants