Skip to content

Commit edeb792

Browse files
committed
Update existing profiles to include sshd_runtime_check configuration for enhanced compliance checks.
1 parent b01b3d6 commit edeb792

35 files changed

+1195
-192
lines changed
Lines changed: 106 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,106 @@
1+
aide_also_checks_audispd: 'yes'
2+
aide_also_checks_rsyslog: 'no'
3+
aide_bin_path: /usr/sbin/aide
4+
aide_conf_path: /etc/aide.conf
5+
audisp_conf_path: /etc/audit
6+
audit_binaries:
7+
- /sbin/auditctl
8+
- /sbin/aureport
9+
- /sbin/ausearch
10+
- /sbin/autrace
11+
- /sbin/auditd
12+
- /sbin/audispd
13+
- /sbin/augenrules
14+
audit_watches_style: legacy
15+
auid: 1000
16+
basic_properties_derived: true
17+
benchmark_id: AL-2023
18+
benchmark_root: ../../linux_os/guide
19+
bootable_containers_supported: 'false'
20+
chrony_conf_path: /etc/chrony.conf
21+
chrony_d_path: /etc/chrony.d/
22+
components_root: ../../components
23+
cpes:
24+
- al2023:
25+
check_id: installed_OS_is_al2023
26+
name: cpe:/o:amazon:amazon_linux:2023
27+
title: Amazon Linux 2023
28+
cpes_root: ../../shared/applicability
29+
dconf_gdm_dir: gdm.d
30+
dynamic_uid_max: 65519
31+
dynamic_uid_min: 61184
32+
faillock_path: /var/log/faillock
33+
full_name: Amazon Linux 2023
34+
gid_min: 1000
35+
groups:
36+
dedicated_ssh_keyowner:
37+
name: ssh_keys
38+
grub2_boot_path: /boot/grub2
39+
grub2_uefi_boot_path: /boot/grub2
40+
grub_helper_executable: grubby
41+
init_system: systemd
42+
journald_conf_dir_path: /etc/systemd/journald.conf.d
43+
login_defs_path: /etc/login.defs
44+
nobody_gid: 65534
45+
nobody_uid: 65534
46+
pkg_manager: dnf
47+
pkg_manager_config_file: /etc/dnf/dnf.conf
48+
pkg_system: rpm
49+
platform_package_overrides:
50+
aarch64_arch: null
51+
grub2: grub2-common
52+
login_defs: shadow-utils
53+
no_ovirt: null
54+
non-uefi: null
55+
not_aarch64_arch: null
56+
not_s390x_arch: null
57+
ovirt: null
58+
s390x_arch: null
59+
sssd: sssd-common
60+
sssd-ldap: null
61+
uefi: null
62+
zipl: s390utils-base
63+
product: al2023
64+
profiles_root: ./profiles
65+
reference_uris:
66+
anssi: https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf
67+
app-srg: https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=application-servers
68+
app-srg-ctr: https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security
69+
bsi: https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Grundschutz/International/bsi_it_gs_comp_2022.pdf
70+
cis: https://www.cisecurity.org/benchmark/amazon_linux/
71+
cis-csc: https://www.cisecurity.org/controls/
72+
cjis: https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf
73+
cobit5: https://www.isaca.org/resources/cobit
74+
cui: http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf
75+
dcid: not_officially_available
76+
disa: https://www.cyber.mil/stigs/cci/
77+
hipaa: https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf
78+
isa-62443-2009: https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat
79+
isa-62443-2013: https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu
80+
ism: https://www.cyber.gov.au/acsc/view-all-content/ism
81+
iso27001-2013: https://www.iso.org/contents/data/standard/05/45/54534.html
82+
nerc-cip: https://www.nerc.com/pa/Stand/AlignRep/One%20Stop%20Shop.xlsx
83+
nist: http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf
84+
nist-csf: https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf
85+
os-srg: https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os
86+
ospp: https://www.niap-ccevs.org/Profile/PP.cfm
87+
pcidss: https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf
88+
pcidss4: https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf
89+
stigid: https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux
90+
stigref: https://www.cyber.mil/stigs/srg-stig-tools/
91+
release_key_fingerprint: B21C50FA44A99720EAA72F7FE951904AD832C631
92+
rsyslog_cafile: /etc/pki/tls/cert.pem
93+
sshd_distributed_config: 'true'
94+
sshd_runtime_check: 'false'
95+
sysctl_remediate_drop_in_file: 'false'
96+
target_oval_version:
97+
- 5
98+
- 11
99+
target_oval_version_str: '5.11'
100+
type: platform
101+
uid_min: 1000
102+
xwindows_packages:
103+
- xorg-x11-server-Xorg
104+
- xorg-x11-server-common
105+
- xorg-x11-server-utils
106+
- xorg-x11-server-Xwayland

tests/data/product_stability/alinux2.yml

Lines changed: 8 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -4,13 +4,13 @@ aide_bin_path: /usr/sbin/aide
44
aide_conf_path: /etc/aide.conf
55
audisp_conf_path: /etc/audit
66
audit_binaries:
7-
- /sbin/auditctl
8-
- /sbin/aureport
9-
- /sbin/ausearch
10-
- /sbin/autrace
11-
- /sbin/auditd
12-
- /sbin/audispd
13-
- /sbin/augenrules
7+
- /sbin/auditctl
8+
- /sbin/aureport
9+
- /sbin/ausearch
10+
- /sbin/autrace
11+
- /sbin/auditd
12+
- /sbin/audispd
13+
- /sbin/augenrules
1414
audit_watches_style: legacy
1515
auid: 1000
1616
basic_properties_derived: true
@@ -85,6 +85,7 @@ reference_uris:
8585
stigref: https://www.cyber.mil/stigs/srg-stig-tools/
8686
rsyslog_cafile: /etc/pki/tls/cert.pem
8787
sshd_distributed_config: 'false'
88+
sshd_runtime_check: 'false'
8889
sysctl_remediate_drop_in_file: 'false'
8990
target_oval_version:
9091
- 5

tests/data/product_stability/alinux3.yml

Lines changed: 8 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -4,13 +4,13 @@ aide_bin_path: /usr/sbin/aide
44
aide_conf_path: /etc/aide.conf
55
audisp_conf_path: /etc/audit
66
audit_binaries:
7-
- /sbin/auditctl
8-
- /sbin/aureport
9-
- /sbin/ausearch
10-
- /sbin/autrace
11-
- /sbin/auditd
12-
- /sbin/audispd
13-
- /sbin/augenrules
7+
- /sbin/auditctl
8+
- /sbin/aureport
9+
- /sbin/ausearch
10+
- /sbin/autrace
11+
- /sbin/auditd
12+
- /sbin/audispd
13+
- /sbin/augenrules
1414
audit_watches_style: legacy
1515
auid: 1000
1616
basic_properties_derived: true
@@ -85,6 +85,7 @@ reference_uris:
8585
stigref: https://www.cyber.mil/stigs/srg-stig-tools/
8686
rsyslog_cafile: /etc/pki/tls/cert.pem
8787
sshd_distributed_config: 'false'
88+
sshd_runtime_check: 'false'
8889
sysctl_remediate_drop_in_file: 'false'
8990
target_oval_version:
9091
- 5
Lines changed: 107 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,107 @@
1+
aide_also_checks_audispd: 'yes'
2+
aide_also_checks_rsyslog: 'no'
3+
aide_bin_path: /usr/sbin/aide
4+
aide_conf_path: /etc/aide.conf
5+
audisp_conf_path: /etc/audit
6+
audit_binaries:
7+
- /sbin/auditctl
8+
- /sbin/aureport
9+
- /sbin/ausearch
10+
- /sbin/autrace
11+
- /sbin/auditd
12+
- /sbin/audispd
13+
- /sbin/augenrules
14+
audit_watches_style: legacy
15+
auid: 1000
16+
basic_properties_derived: true
17+
benchmark_id: ALMALINUX-9
18+
benchmark_root: ../../linux_os/guide
19+
bootable_containers_supported: 'false'
20+
chrony_conf_path: /etc/chrony.conf
21+
chrony_d_path: /etc/chrony.d/
22+
components_root: ../../components
23+
cpes:
24+
- almalinux9:
25+
check_id: installed_OS_is_almalinux9
26+
name: cpe:/o:almalinux:almalinux:9
27+
title: AlmaLinux OS 9
28+
cpes_root: ../../shared/applicability
29+
dconf_gdm_dir: gdm.d
30+
dynamic_uid_max: 65519
31+
dynamic_uid_min: 61184
32+
faillock_path: /var/run/faillock
33+
full_name: AlmaLinux OS 9
34+
gid_min: 1000
35+
groups: {}
36+
grub2_boot_path: /boot/grub2
37+
grub2_uefi_boot_path: /boot/grub2
38+
grub_helper_executable: grubby
39+
init_system: systemd
40+
login_defs_path: /etc/login.defs
41+
major_version_ordinal: 9
42+
nobody_gid: 65534
43+
nobody_uid: 65534
44+
oval_feed_url: https://security.almalinux.org/oval/org.almalinux.alsa-9.xml.bz2
45+
pkg_manager: dnf
46+
pkg_manager_config_file: /etc/dnf/dnf.conf
47+
pkg_release: 61e69f29
48+
pkg_system: rpm
49+
pkg_version: b86b3716
50+
platform_package_overrides:
51+
aarch64_arch: null
52+
grub2: grub2-common
53+
login_defs: login
54+
no_ovirt: null
55+
non-uefi: null
56+
not_aarch64_arch: null
57+
not_s390x_arch: null
58+
ovirt: null
59+
s390x_arch: null
60+
sssd: sssd-common
61+
sssd-ldap: null
62+
uefi: null
63+
zipl: s390utils-base
64+
product: almalinux9
65+
profiles_root: ./profiles
66+
reference_uris:
67+
anssi: https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf
68+
app-srg: https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=application-servers
69+
app-srg-ctr: https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security
70+
bsi: https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Grundschutz/International/bsi_it_gs_comp_2022.pdf
71+
cis: https://www.cisecurity.org/benchmark/almalinuxos_linux/
72+
cis-csc: https://www.cisecurity.org/controls/
73+
cjis: https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf
74+
cobit5: https://www.isaca.org/resources/cobit
75+
cui: http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf
76+
dcid: not_officially_available
77+
disa: https://www.cyber.mil/stigs/cci/
78+
hipaa: https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf
79+
isa-62443-2009: https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat
80+
isa-62443-2013: https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu
81+
ism: https://www.cyber.gov.au/acsc/view-all-content/ism
82+
iso27001-2013: https://www.iso.org/contents/data/standard/05/45/54534.html
83+
nerc-cip: https://www.nerc.com/pa/Stand/AlignRep/One%20Stop%20Shop.xlsx
84+
nist: http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf
85+
nist-csf: https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf
86+
os-srg: https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os
87+
ospp: https://www.niap-ccevs.org/Profile/PP.cfm
88+
pcidss: https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf
89+
pcidss4: https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf
90+
stigid: https://www.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux
91+
stigref: https://www.cyber.mil/stigs/srg-stig-tools/
92+
release_key_fingerprint: BF18AC2876178908D6E71267D36CB86CB86B3716
93+
rsyslog_cafile: /etc/pki/tls/cert.pem
94+
sshd_distributed_config: 'false'
95+
sshd_runtime_check: 'false'
96+
sysctl_remediate_drop_in_file: 'false'
97+
target_oval_version:
98+
- 5
99+
- 11
100+
target_oval_version_str: '5.11'
101+
type: platform
102+
uid_min: 1000
103+
xwindows_packages:
104+
- xorg-x11-server-Xorg
105+
- xorg-x11-server-common
106+
- xorg-x11-server-utils
107+
- xorg-x11-server-Xwayland

tests/data/product_stability/anolis23.yml

Lines changed: 7 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -4,12 +4,12 @@ aide_bin_path: /usr/sbin/aide
44
aide_conf_path: /etc/aide.conf
55
audisp_conf_path: /etc/audit
66
audit_binaries:
7-
- /sbin/auditctl
8-
- /sbin/aureport
9-
- /sbin/ausearch
10-
- /sbin/autrace
11-
- /sbin/auditd
12-
- /sbin/augenrules
7+
- /sbin/auditctl
8+
- /sbin/aureport
9+
- /sbin/ausearch
10+
- /sbin/autrace
11+
- /sbin/auditd
12+
- /sbin/augenrules
1313
audit_watches_style: legacy
1414
auid: 1000
1515
basic_properties_derived: true
@@ -84,6 +84,7 @@ reference_uris:
8484
stigref: https://www.cyber.mil/stigs/srg-stig-tools/
8585
rsyslog_cafile: /etc/pki/tls/cert.pem
8686
sshd_distributed_config: 'false'
87+
sshd_runtime_check: 'false'
8788
sysctl_remediate_drop_in_file: 'false'
8889
target_oval_version:
8990
- 5

tests/data/product_stability/anolis8.yml

Lines changed: 7 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -4,12 +4,12 @@ aide_bin_path: /usr/sbin/aide
44
aide_conf_path: /etc/aide.conf
55
audisp_conf_path: /etc/audit
66
audit_binaries:
7-
- /sbin/auditctl
8-
- /sbin/aureport
9-
- /sbin/ausearch
10-
- /sbin/autrace
11-
- /sbin/auditd
12-
- /sbin/augenrules
7+
- /sbin/auditctl
8+
- /sbin/aureport
9+
- /sbin/ausearch
10+
- /sbin/autrace
11+
- /sbin/auditd
12+
- /sbin/augenrules
1313
audit_watches_style: legacy
1414
auid: 1000
1515
basic_properties_derived: true
@@ -84,6 +84,7 @@ reference_uris:
8484
stigref: https://www.cyber.mil/stigs/srg-stig-tools/
8585
rsyslog_cafile: /etc/pki/tls/cert.pem
8686
sshd_distributed_config: 'false'
87+
sshd_runtime_check: 'false'
8788
sysctl_remediate_drop_in_file: 'false'
8889
target_oval_version:
8990
- 5

tests/data/product_stability/debian11.yml

Lines changed: 8 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -4,13 +4,13 @@ aide_bin_path: /usr/sbin/aide
44
aide_conf_path: /etc/aide.conf
55
audisp_conf_path: /etc/audit
66
audit_binaries:
7-
- /sbin/auditctl
8-
- /sbin/aureport
9-
- /sbin/ausearch
10-
- /sbin/autrace
11-
- /sbin/auditd
12-
- /sbin/audispd
13-
- /sbin/augenrules
7+
- /sbin/auditctl
8+
- /sbin/aureport
9+
- /sbin/ausearch
10+
- /sbin/autrace
11+
- /sbin/auditd
12+
- /sbin/audispd
13+
- /sbin/augenrules
1414
audit_watches_style: legacy
1515
auid: 1000
1616
basic_properties_derived: true
@@ -94,6 +94,7 @@ reference_uris:
9494
stigref: https://www.cyber.mil/stigs/srg-stig-tools/
9595
rsyslog_cafile: /etc/pki/tls/cert.pem
9696
sshd_distributed_config: 'false'
97+
sshd_runtime_check: 'false'
9798
sysctl_remediate_drop_in_file: 'false'
9899
target_oval_version:
99100
- 5

tests/data/product_stability/debian12.yml

Lines changed: 8 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -4,13 +4,13 @@ aide_bin_path: /usr/sbin/aide
44
aide_conf_path: /etc/aide/aide.conf
55
audisp_conf_path: /etc/audit
66
audit_binaries:
7-
- /sbin/auditctl
8-
- /sbin/aureport
9-
- /sbin/ausearch
10-
- /sbin/autrace
11-
- /sbin/auditd
12-
- /sbin/audispd
13-
- /sbin/augenrules
7+
- /sbin/auditctl
8+
- /sbin/aureport
9+
- /sbin/ausearch
10+
- /sbin/autrace
11+
- /sbin/auditd
12+
- /sbin/audispd
13+
- /sbin/augenrules
1414
audit_watches_style: legacy
1515
auid: 1000
1616
basic_properties_derived: true
@@ -95,6 +95,7 @@ reference_uris:
9595
stigref: https://www.cyber.mil/stigs/srg-stig-tools/
9696
rsyslog_cafile: /etc/pki/tls/cert.pem
9797
sshd_distributed_config: 'false'
98+
sshd_runtime_check: 'false'
9899
sysctl_remediate_drop_in_file: 'false'
99100
target_oval_version:
100101
- 5

0 commit comments

Comments
 (0)