Inital RHEL 10 STIG#11793
Conversation
|
Skipping CI for Draft Pull Request. |
|
🤖 A k8s content image for this PR is available at: Click here to see how to deploy itIf you alread have Compliance Operator deployed: Otherwise deploy the content and operator together by checking out ComplianceAsCode/compliance-operator and: |
jan-cerny
left a comment
There was a problem hiding this comment.
The changes look fine to me
Please rebase this PR on the top of the master branch which should bring in the sssd_enable_pam_service that should make the TF tests green.
To follow recent STIGs from DISA.
This allow the user to lock the session easily. Also part of recent STIGs.
To include more commands to audit
It shouldn't be here. It does not belong.
To match the latest STIGs.
As there are not in RHEL 10.
Keep in line with the rest of the STIG
Move sendmail to mailx
It was mixing up group name and GID
* Set timeout to 15 minutes to match the SRG * Remove old text
* Add package_mcafeetp_installed as other STIGs have this here
To match the other STIGs.
Better covers the requirement and matches the other STIGs
Put variables in the correct file.
To match other STIGs
Currently this project does have any rules to fix this. Based on RHEL 9 STIG.
d4721f6 to
ec615c1
Compare
|
Code Climate has analyzed commit ec615c1 and detected 0 issues on this pull request. The test coverage on the diff in this pull request is 100.0% (50% is the threshold). This pull request will bring the total coverage in the repository to 59.2% (0.0% change). View more on Code Climate. |
Description:
Create the initial RHEL 10 STIG profile.
This is a draft based on RHEL 9.