Skip to content

Commit cae6a6e

Browse files
committed
update profile stability for cis, hipaa, pcidss
1 parent 3d1a3d6 commit cae6a6e

14 files changed

Lines changed: 17 additions & 1 deletion

File tree

linux_os/guide/services/mail/package_postfix_installed/rule.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -15,6 +15,7 @@ severity: medium
1515
identifiers:
1616
cce@rhel8: CCE-85983-5
1717
cce@rhel9: CCE-85984-3
18+
cce@rhel10: CCE-86466-0
1819

1920
references:
2021
srg: SRG-OS-000046-GPOS-00022

shared/references/cce-redhat-avail.txt

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,3 @@
1-
CCE-86466-0
21
CCE-86468-6
32
CCE-86482-7
43
CCE-86483-5

tests/data/profile_stability/rhel10/cis.profile

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -116,6 +116,7 @@ audit_rules_usergroup_modification_shadow
116116
audit_sudo_log_events
117117
auditd_data_disk_error_action
118118
auditd_data_disk_full_action
119+
auditd_data_retention_action_mail_acct
119120
auditd_data_retention_admin_space_left_action
120121
auditd_data_retention_max_log_file
121122
auditd_data_retention_max_log_file_action
@@ -336,6 +337,7 @@ package_net-snmp_removed
336337
package_nginx_removed
337338
package_openldap-clients_removed
338339
package_pam_pwquality_installed
340+
package_postfix_installed
339341
package_rsync_removed
340342
package_samba_removed
341343
package_setroubleshoot_removed
@@ -469,6 +471,7 @@ var_accounts_passwords_pam_faillock_unlock_time=900
469471
var_accounts_tmout=15_min
470472
var_accounts_user_umask=027
471473
var_audit_backlog_limit=8192
474+
var_auditd_action_mail_acct=root
472475
var_auditd_admin_space_left_action=cis_rhel10
473476
var_auditd_disk_error_action=cis_rhel10
474477
var_auditd_disk_full_action=cis_rhel10

tests/data/profile_stability/rhel10/cis_workstation_l2.profile

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -116,6 +116,7 @@ audit_rules_usergroup_modification_shadow
116116
audit_sudo_log_events
117117
auditd_data_disk_error_action
118118
auditd_data_disk_full_action
119+
auditd_data_retention_action_mail_acct
119120
auditd_data_retention_admin_space_left_action
120121
auditd_data_retention_max_log_file
121122
auditd_data_retention_max_log_file_action
@@ -335,6 +336,7 @@ package_net-snmp_removed
335336
package_nginx_removed
336337
package_openldap-clients_removed
337338
package_pam_pwquality_installed
339+
package_postfix_installed
338340
package_rsync_removed
339341
package_samba_removed
340342
package_squid_removed
@@ -465,6 +467,7 @@ var_accounts_passwords_pam_faillock_unlock_time=900
465467
var_accounts_tmout=15_min
466468
var_accounts_user_umask=027
467469
var_audit_backlog_limit=8192
470+
var_auditd_action_mail_acct=root
468471
var_auditd_admin_space_left_action=cis_rhel10
469472
var_auditd_disk_error_action=cis_rhel10
470473
var_auditd_disk_full_action=cis_rhel10

tests/data/profile_stability/rhel10/hipaa.profile

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -118,6 +118,7 @@ no_direct_root_logins
118118
no_empty_passwords
119119
package_audit_installed
120120
package_cron_installed
121+
package_postfix_installed
121122
package_rsyslog_installed
122123
package_sequoia-sq_installed
123124
package_telnet-server_removed

tests/data/profile_stability/rhel10/pci-dss.profile

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -189,6 +189,7 @@ package_libselinux_installed
189189
package_logrotate_installed
190190
package_net-snmp_removed
191191
package_nftables_installed
192+
package_postfix_installed
192193
package_sequoia-sq_installed
193194
package_sudo_installed
194195
package_telnet-server_removed

tests/data/profile_stability/rhel10/stig.profile

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -380,6 +380,7 @@ package_pcsc-lite-ccid_installed
380380
package_pcsc-lite_installed
381381
package_policycoreutils-python-utils_installed
382382
package_policycoreutils_installed
383+
package_postfix_installed
383384
package_rsyslog-gnutls_installed
384385
package_rsyslog_installed
385386
package_s-nail_installed

tests/data/profile_stability/rhel10/stig_gui.profile

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -377,6 +377,7 @@ package_pcsc-lite-ccid_installed
377377
package_pcsc-lite_installed
378378
package_policycoreutils-python-utils_installed
379379
package_policycoreutils_installed
380+
package_postfix_installed
380381
package_rsyslog-gnutls_installed
381382
package_rsyslog_installed
382383
package_s-nail_installed

tests/data/profile_stability/rhel8/hipaa.profile

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -94,6 +94,7 @@ libreswan_approved_tunnels
9494
no_direct_root_logins
9595
no_empty_passwords
9696
no_rsh_trust_files
97+
package_postfix_installed
9798
package_telnet-server_removed
9899
package_telnet_removed
99100
package_xinetd_removed

tests/data/profile_stability/rhel8/pci-dss.profile

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -190,6 +190,7 @@ package_libselinux_installed
190190
package_logrotate_installed
191191
package_net-snmp_removed
192192
package_nftables_installed
193+
package_postfix_installed
193194
package_sudo_installed
194195
package_telnet-server_removed
195196
package_telnet_removed

0 commit comments

Comments
 (0)