CMP-4049: Add rules to RHCOS DS#14461
CMP-4049: Add rules to RHCOS DS#14461yuumasato wants to merge 3 commits intoComplianceAsCode:masterfrom
Conversation
69a6a41 to
0854ba4
Compare
rhmdnd
left a comment
There was a problem hiding this comment.
One question on adding additional CCEs for the RHCOS rules now that we're using them there. Otherwise looks good.
linux_os/guide/system/software/system-tools/package_python3-dnf_removed/rule.yml
Outdated
Show resolved
Hide resolved
|
Generally the PR is good. I have created a tailoredprofile for all newly added rules. After autoremediations applied, two rules failed, one rule was accounts-authorized-local-users , the other rule was package-python3-dnf-removed. After add rules "core|containers" to the variable upstream-rhcos4-var-accounts-authorized-local-users-regex, the rule accounts-authorized-local-users could PASS.
|
0854ba4 to
340d167
Compare
0fb640f to
07a0d8c
Compare
|
@rhmdnd Rebased, I'll propose them in separate PR. Makes it easier to merge this one. |
07a0d8c to
2cda2eb
Compare
|
@xiaojiey I have removed the new rules, will add them later. And I added a variable selector for RHCOS4. |
Ensure warning about no automated remediation is shown. Add RHCOS4 variable selector for 'var_accounts_authorized_local_users_regex'.
2cda2eb to
ced8ff7
Compare
rhmdnd
left a comment
There was a problem hiding this comment.
Only one rule recommendation inline, otherwise this looks good.
| - service_cups_disabled | ||
| - audit_rules_networkconfig_modification_network_scripts | ||
| - audit_rules_mac_modification_etc_selinux | ||
| - audit_rules_login_events_faillog |
There was a problem hiding this comment.
What about? That's similar to audit_rules_mac_modifications_etc_selinux.
- audit_rules_mac_modification_usr_share
Description:
defaultprofile.Rationale:
TailoredProfilesin Compliance OperatorReview Hints: