Skip to content

Commit c323192

Browse files
authored
Merge pull request #14738 from mrkanon/OL8-v2r8
Update OL8 STIG profile to DISA STIG V2R8
2 parents 90da9b3 + c827a59 commit c323192

19 files changed

Lines changed: 1581 additions & 1046 deletions

File tree

linux_os/guide/services/obsolete/r_services/package_rsh-server_removed/rule.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -34,7 +34,6 @@ references:
3434
nist-csf: PR.AC-3,PR.IP-1,PR.PT-3,PR.PT-4
3535
srg: SRG-OS-000095-GPOS-00049
3636
stigid@ol7: OL07-00-020000
37-
stigid@ol8: OL08-00-040010
3837

3938
{{{ complete_ocil_entry_package_removed("rsh-server") }}}
4039

linux_os/guide/services/ssh/ssh_server/sshd_use_approved_kex_ordered_stig/rule.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -46,7 +46,6 @@ references:
4646
nist: AC-17(2)
4747
srg: SRG-OS-000250-GPOS-00093
4848
stigid@ol7: OL07-00-040712
49-
stigid@ol8: OL08-00-040342
5049
stigid@sle12: SLES-12-030270
5150
stigid@sle15: SLES-15-040450
5251

linux_os/guide/system/accounts/accounts-restrictions/password_expiration/accounts_password_minlen_login_defs/rule.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -42,7 +42,6 @@ references:
4242
nist: IA-5(f),IA-5(1)(a),CM-6(a)
4343
nist-csf: PR.AC-1,PR.AC-6,PR.AC-7
4444
srg: SRG-OS-000078-GPOS-00046
45-
stigid@ol8: OL08-00-020231
4645

4746
ocil_clause: 'it is not set to the required value'
4847

linux_os/guide/system/software/integrity/crypto/configure_bind_crypto_policy/rule.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -30,7 +30,7 @@ references:
3030
nerc-cip: CIP-003-8 R4.2,CIP-007-3 R5.1
3131
nist: SC-13,SC-12(2),SC-12(3)
3232
srg: SRG-OS-000423-GPOS-00187,SRG-OS-000426-GPOS-00190
33-
stigid@ol8: OL08-00-010020
33+
stigid@ol8: OL08-00-010020,OL08-00-010187
3434

3535
ocil_clause: |-
3636
BIND is installed and the BIND config file doesn't contain the

linux_os/guide/system/software/integrity/crypto/configure_crypto_policy/rule.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -68,7 +68,7 @@ references:
6868
nist: AC-17(a),AC-17(2),CM-6(a),MA-4(6),SC-13,SC-12(2),SC-12(3)
6969
ospp: FCS_COP.1(1),FCS_COP.1(2),FCS_COP.1(3),FCS_COP.1(4),FCS_CKM.1,FCS_CKM.2,FCS_TLSC_EXT.1
7070
srg: SRG-OS-000396-GPOS-00176,SRG-OS-000393-GPOS-00173,SRG-OS-000394-GPOS-00174
71-
stigid@ol8: OL08-00-010020
71+
stigid@ol8: OL08-00-010020,OL08-00-010183,OL08-00-010181
7272

7373
ocil_clause: 'cryptographic policy is not configured or is configured incorrectly'
7474

linux_os/guide/system/software/integrity/crypto/configure_gnutls_tls_crypto_policy/rule.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -29,7 +29,6 @@ identifiers:
2929
references:
3030
nist: AC-17(2)
3131
srg: SRG-OS-000250-GPOS-00093,SRG-OS-000423-GPOS-00187
32-
stigid@ol8: OL08-00-010295
3332

3433
ocil_clause: 'cryptographic policy for gnutls is not configured or is configured incorrectly'
3534

linux_os/guide/system/software/integrity/crypto/configure_libreswan_crypto_policy/rule.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -34,7 +34,7 @@ references:
3434
nist: CM-6(a),MA-4(6),SC-13,SC-12(2),SC-12(3)
3535
pcidss: Req-2.2
3636
srg: SRG-OS-000033-GPOS-00014
37-
stigid@ol8: OL08-00-010020
37+
stigid@ol8: OL08-00-010020,OL08-00-010186
3838

3939
ocil_clause: |-
4040
the "IPsec" service is active and the ipsec configuration file does not contain does not contain <tt>include /etc/crypto-policies/back-ends/libreswan.config</tt>

linux_os/guide/system/software/integrity/crypto/configure_openssl_tls_crypto_policy/rule.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -43,7 +43,6 @@ identifiers:
4343
references:
4444
nist: AC-17(2)
4545
srg: SRG-OS-000125-GPOS-00065,SRG-OS-000250-GPOS-00093,SRG-OS-000393-GPOS-00173,SRG-OS-000394-GPOS-00174
46-
stigid@ol8: OL08-00-010294
4746

4847
ocil_clause: 'cryptographic policy for openssl is not configured or is configured incorrectly'
4948

linux_os/guide/system/software/integrity/crypto/configure_ssh_crypto_policy/rule.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -33,7 +33,6 @@ references:
3333
ospp: FCS_SSH_EXT.1,FCS_SSHS_EXT.1,FCS_SSHC_EXT.1
3434
pcidss: Req-2.2
3535
srg: SRG-OS-000250-GPOS-00093
36-
stigid@ol8: OL08-00-010287
3736

3837
ocil_clause: 'the CRYPTO_POLICY variable is set or is not commented out in {{{ sshd_sysconfig }}}'
3938

linux_os/guide/system/software/integrity/crypto/harden_sshd_macs_openssh_conf_crypto_policy/rule.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -29,6 +29,7 @@ identifiers:
2929
references:
3030
nist: AC-17(2)
3131
srg: SRG-OS-000125-GPOS-00065,SRG-OS-000250-GPOS-00093
32+
stigid@ol8: OL08-00-010185
3233

3334
ocil_clause: 'Crypto Policy for OpenSSH client is not configured correctly'
3435

0 commit comments

Comments
 (0)