|
3 | 3 | "uuid": "6ca8c4fe-f75b-4070-a178-188a41fecbf0", |
4 | 4 | "metadata": { |
5 | 5 | "title": "Component definition for rhel10", |
6 | | - "last-modified": "2026-04-20T15:10:54.961819+00:00", |
7 | | - "version": "1.6", |
| 6 | + "last-modified": "2026-04-20T15:11:18.597692+00:00", |
| 7 | + "version": "1.7", |
8 | 8 | "oscal-version": "1.1.3" |
9 | 9 | }, |
10 | 10 | "components": [ |
@@ -9074,290 +9074,314 @@ |
9074 | 9074 | { |
9075 | 9075 | "name": "Rule_Id", |
9076 | 9076 | "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", |
9077 | | - "value": "configure_firewalld_ports", |
| 9077 | + "value": "package_rsyslog-gnutls_installed", |
9078 | 9078 | "remarks": "rule_set_160" |
9079 | 9079 | }, |
9080 | 9080 | { |
9081 | 9081 | "name": "Rule_Description", |
9082 | 9082 | "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", |
9083 | | - "value": "Configure the Firewalld Ports", |
| 9083 | + "value": "Ensure rsyslog-gnutls is installed", |
9084 | 9084 | "remarks": "rule_set_160" |
9085 | 9085 | }, |
9086 | 9086 | { |
9087 | 9087 | "name": "Check_Id", |
9088 | 9088 | "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", |
9089 | | - "value": "configure_firewalld_ports", |
| 9089 | + "value": "package_rsyslog-gnutls_installed", |
9090 | 9090 | "remarks": "rule_set_160" |
9091 | 9091 | }, |
9092 | 9092 | { |
9093 | 9093 | "name": "Check_Description", |
9094 | 9094 | "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", |
9095 | | - "value": "Configure the Firewalld Ports", |
| 9095 | + "value": "Ensure rsyslog-gnutls is installed", |
9096 | 9096 | "remarks": "rule_set_160" |
9097 | 9097 | }, |
9098 | 9098 | { |
9099 | 9099 | "name": "Rule_Id", |
9100 | 9100 | "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", |
9101 | | - "value": "set_firewalld_default_zone", |
| 9101 | + "value": "configure_firewalld_ports", |
9102 | 9102 | "remarks": "rule_set_161" |
9103 | 9103 | }, |
9104 | 9104 | { |
9105 | 9105 | "name": "Rule_Description", |
9106 | 9106 | "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", |
9107 | | - "value": "Set Default firewalld Zone for Incoming Packets", |
| 9107 | + "value": "Configure the Firewalld Ports", |
9108 | 9108 | "remarks": "rule_set_161" |
9109 | 9109 | }, |
9110 | 9110 | { |
9111 | 9111 | "name": "Check_Id", |
9112 | 9112 | "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", |
9113 | | - "value": "set_firewalld_default_zone", |
| 9113 | + "value": "configure_firewalld_ports", |
9114 | 9114 | "remarks": "rule_set_161" |
9115 | 9115 | }, |
9116 | 9116 | { |
9117 | 9117 | "name": "Check_Description", |
9118 | 9118 | "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", |
9119 | | - "value": "Set Default firewalld Zone for Incoming Packets", |
| 9119 | + "value": "Configure the Firewalld Ports", |
9120 | 9120 | "remarks": "rule_set_161" |
9121 | 9121 | }, |
9122 | 9122 | { |
9123 | 9123 | "name": "Rule_Id", |
9124 | 9124 | "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", |
9125 | | - "value": "package_usbguard_installed", |
| 9125 | + "value": "set_firewalld_default_zone", |
9126 | 9126 | "remarks": "rule_set_162" |
9127 | 9127 | }, |
9128 | 9128 | { |
9129 | 9129 | "name": "Rule_Description", |
9130 | 9130 | "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", |
9131 | | - "value": "Install usbguard Package", |
| 9131 | + "value": "Set Default firewalld Zone for Incoming Packets", |
9132 | 9132 | "remarks": "rule_set_162" |
9133 | 9133 | }, |
9134 | 9134 | { |
9135 | 9135 | "name": "Check_Id", |
9136 | 9136 | "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", |
9137 | | - "value": "package_usbguard_installed", |
| 9137 | + "value": "set_firewalld_default_zone", |
9138 | 9138 | "remarks": "rule_set_162" |
9139 | 9139 | }, |
9140 | 9140 | { |
9141 | 9141 | "name": "Check_Description", |
9142 | 9142 | "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", |
9143 | | - "value": "Install usbguard Package", |
| 9143 | + "value": "Set Default firewalld Zone for Incoming Packets", |
9144 | 9144 | "remarks": "rule_set_162" |
9145 | 9145 | }, |
9146 | 9146 | { |
9147 | 9147 | "name": "Rule_Id", |
9148 | 9148 | "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", |
9149 | | - "value": "service_usbguard_enabled", |
| 9149 | + "value": "package_usbguard_installed", |
9150 | 9150 | "remarks": "rule_set_163" |
9151 | 9151 | }, |
9152 | 9152 | { |
9153 | 9153 | "name": "Rule_Description", |
9154 | 9154 | "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", |
9155 | | - "value": "Enable the USBGuard Service", |
| 9155 | + "value": "Install usbguard Package", |
9156 | 9156 | "remarks": "rule_set_163" |
9157 | 9157 | }, |
9158 | 9158 | { |
9159 | 9159 | "name": "Check_Id", |
9160 | 9160 | "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", |
9161 | | - "value": "service_usbguard_enabled", |
| 9161 | + "value": "package_usbguard_installed", |
9162 | 9162 | "remarks": "rule_set_163" |
9163 | 9163 | }, |
9164 | 9164 | { |
9165 | 9165 | "name": "Check_Description", |
9166 | 9166 | "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", |
9167 | | - "value": "Enable the USBGuard Service", |
| 9167 | + "value": "Install usbguard Package", |
9168 | 9168 | "remarks": "rule_set_163" |
9169 | 9169 | }, |
9170 | 9170 | { |
9171 | 9171 | "name": "Rule_Id", |
9172 | 9172 | "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", |
9173 | | - "value": "system_booted_in_fips_mode", |
| 9173 | + "value": "service_usbguard_enabled", |
9174 | 9174 | "remarks": "rule_set_164" |
9175 | 9175 | }, |
9176 | 9176 | { |
9177 | 9177 | "name": "Rule_Description", |
9178 | 9178 | "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", |
9179 | | - "value": "Verify that the system was booted with fips=1", |
| 9179 | + "value": "Enable the USBGuard Service", |
9180 | 9180 | "remarks": "rule_set_164" |
9181 | 9181 | }, |
9182 | 9182 | { |
9183 | 9183 | "name": "Check_Id", |
9184 | 9184 | "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", |
9185 | | - "value": "system_booted_in_fips_mode", |
| 9185 | + "value": "service_usbguard_enabled", |
9186 | 9186 | "remarks": "rule_set_164" |
9187 | 9187 | }, |
9188 | 9188 | { |
9189 | 9189 | "name": "Check_Description", |
9190 | 9190 | "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", |
9191 | | - "value": "Verify that the system was booted with fips=1", |
| 9191 | + "value": "Enable the USBGuard Service", |
9192 | 9192 | "remarks": "rule_set_164" |
9193 | 9193 | }, |
9194 | 9194 | { |
9195 | 9195 | "name": "Rule_Id", |
9196 | 9196 | "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", |
9197 | | - "value": "enable_fips_mode", |
| 9197 | + "value": "system_booted_in_fips_mode", |
9198 | 9198 | "remarks": "rule_set_165" |
9199 | 9199 | }, |
9200 | 9200 | { |
9201 | 9201 | "name": "Rule_Description", |
9202 | 9202 | "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", |
9203 | | - "value": "Enable FIPS Mode", |
| 9203 | + "value": "Verify that the system was booted with fips=1", |
9204 | 9204 | "remarks": "rule_set_165" |
9205 | 9205 | }, |
9206 | 9206 | { |
9207 | 9207 | "name": "Check_Id", |
9208 | 9208 | "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", |
9209 | | - "value": "enable_fips_mode", |
| 9209 | + "value": "system_booted_in_fips_mode", |
9210 | 9210 | "remarks": "rule_set_165" |
9211 | 9211 | }, |
9212 | 9212 | { |
9213 | 9213 | "name": "Check_Description", |
9214 | 9214 | "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", |
9215 | | - "value": "Enable FIPS Mode", |
| 9215 | + "value": "Verify that the system was booted with fips=1", |
9216 | 9216 | "remarks": "rule_set_165" |
9217 | 9217 | }, |
9218 | 9218 | { |
9219 | 9219 | "name": "Rule_Id", |
9220 | 9220 | "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", |
9221 | | - "value": "file_permissions_sshd_private_key", |
| 9221 | + "value": "enable_fips_mode", |
9222 | 9222 | "remarks": "rule_set_166" |
9223 | 9223 | }, |
9224 | 9224 | { |
9225 | 9225 | "name": "Rule_Description", |
9226 | 9226 | "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", |
9227 | | - "value": "Verify Permissions on SSH Server Private *_key Key Files", |
| 9227 | + "value": "Enable FIPS Mode", |
9228 | 9228 | "remarks": "rule_set_166" |
9229 | 9229 | }, |
9230 | 9230 | { |
9231 | 9231 | "name": "Check_Id", |
9232 | 9232 | "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", |
9233 | | - "value": "file_permissions_sshd_private_key", |
| 9233 | + "value": "enable_fips_mode", |
9234 | 9234 | "remarks": "rule_set_166" |
9235 | 9235 | }, |
9236 | 9236 | { |
9237 | 9237 | "name": "Check_Description", |
9238 | 9238 | "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", |
9239 | | - "value": "Verify Permissions on SSH Server Private *_key Key Files", |
| 9239 | + "value": "Enable FIPS Mode", |
9240 | 9240 | "remarks": "rule_set_166" |
9241 | 9241 | }, |
9242 | 9242 | { |
9243 | 9243 | "name": "Rule_Id", |
9244 | 9244 | "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", |
9245 | | - "value": "dnf-automatic_apply_updates", |
| 9245 | + "value": "file_permissions_sshd_private_key", |
9246 | 9246 | "remarks": "rule_set_167" |
9247 | 9247 | }, |
9248 | 9248 | { |
9249 | 9249 | "name": "Rule_Description", |
9250 | 9250 | "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", |
9251 | | - "value": "Configure dnf-automatic to Install Available Updates Automatically", |
| 9251 | + "value": "Verify Permissions on SSH Server Private *_key Key Files", |
9252 | 9252 | "remarks": "rule_set_167" |
9253 | 9253 | }, |
9254 | 9254 | { |
9255 | 9255 | "name": "Check_Id", |
9256 | 9256 | "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", |
9257 | | - "value": "dnf-automatic_apply_updates", |
| 9257 | + "value": "file_permissions_sshd_private_key", |
9258 | 9258 | "remarks": "rule_set_167" |
9259 | 9259 | }, |
9260 | 9260 | { |
9261 | 9261 | "name": "Check_Description", |
9262 | 9262 | "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", |
9263 | | - "value": "Configure dnf-automatic to Install Available Updates Automatically", |
| 9263 | + "value": "Verify Permissions on SSH Server Private *_key Key Files", |
9264 | 9264 | "remarks": "rule_set_167" |
9265 | 9265 | }, |
9266 | 9266 | { |
9267 | 9267 | "name": "Rule_Id", |
9268 | 9268 | "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", |
9269 | | - "value": "package_libdnf-plugin-subscription-manager_installed", |
| 9269 | + "value": "dnf-automatic_apply_updates", |
9270 | 9270 | "remarks": "rule_set_168" |
9271 | 9271 | }, |
9272 | 9272 | { |
9273 | 9273 | "name": "Rule_Description", |
9274 | 9274 | "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", |
9275 | | - "value": "Install libdnf-plugin-subscription-manager Package", |
| 9275 | + "value": "Configure dnf-automatic to Install Available Updates Automatically", |
9276 | 9276 | "remarks": "rule_set_168" |
9277 | 9277 | }, |
9278 | 9278 | { |
9279 | 9279 | "name": "Check_Id", |
9280 | 9280 | "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", |
9281 | | - "value": "package_libdnf-plugin-subscription-manager_installed", |
| 9281 | + "value": "dnf-automatic_apply_updates", |
9282 | 9282 | "remarks": "rule_set_168" |
9283 | 9283 | }, |
9284 | 9284 | { |
9285 | 9285 | "name": "Check_Description", |
9286 | 9286 | "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", |
9287 | | - "value": "Install libdnf-plugin-subscription-manager Package", |
| 9287 | + "value": "Configure dnf-automatic to Install Available Updates Automatically", |
9288 | 9288 | "remarks": "rule_set_168" |
9289 | 9289 | }, |
9290 | 9290 | { |
9291 | 9291 | "name": "Rule_Id", |
9292 | 9292 | "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", |
9293 | | - "value": "package_subscription-manager_installed", |
| 9293 | + "value": "package_libdnf-plugin-subscription-manager_installed", |
9294 | 9294 | "remarks": "rule_set_169" |
9295 | 9295 | }, |
9296 | 9296 | { |
9297 | 9297 | "name": "Rule_Description", |
9298 | 9298 | "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", |
9299 | | - "value": "Install subscription-manager Package", |
| 9299 | + "value": "Install libdnf-plugin-subscription-manager Package", |
9300 | 9300 | "remarks": "rule_set_169" |
9301 | 9301 | }, |
9302 | 9302 | { |
9303 | 9303 | "name": "Check_Id", |
9304 | 9304 | "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", |
9305 | | - "value": "package_subscription-manager_installed", |
| 9305 | + "value": "package_libdnf-plugin-subscription-manager_installed", |
9306 | 9306 | "remarks": "rule_set_169" |
9307 | 9307 | }, |
9308 | 9308 | { |
9309 | 9309 | "name": "Check_Description", |
9310 | 9310 | "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", |
9311 | | - "value": "Install subscription-manager Package", |
| 9311 | + "value": "Install libdnf-plugin-subscription-manager Package", |
9312 | 9312 | "remarks": "rule_set_169" |
9313 | 9313 | }, |
9314 | 9314 | { |
9315 | 9315 | "name": "Rule_Id", |
9316 | 9316 | "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", |
9317 | | - "value": "no_shelllogin_for_systemaccounts", |
| 9317 | + "value": "package_subscription-manager_installed", |
9318 | 9318 | "remarks": "rule_set_170" |
9319 | 9319 | }, |
9320 | 9320 | { |
9321 | 9321 | "name": "Rule_Description", |
9322 | 9322 | "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", |
9323 | | - "value": "Ensure that System Accounts Do Not Run a Shell Upon Login", |
| 9323 | + "value": "Install subscription-manager Package", |
9324 | 9324 | "remarks": "rule_set_170" |
9325 | 9325 | }, |
9326 | 9326 | { |
9327 | 9327 | "name": "Check_Id", |
9328 | 9328 | "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", |
9329 | | - "value": "no_shelllogin_for_systemaccounts", |
| 9329 | + "value": "package_subscription-manager_installed", |
9330 | 9330 | "remarks": "rule_set_170" |
9331 | 9331 | }, |
9332 | 9332 | { |
9333 | 9333 | "name": "Check_Description", |
9334 | 9334 | "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", |
9335 | | - "value": "Ensure that System Accounts Do Not Run a Shell Upon Login", |
| 9335 | + "value": "Install subscription-manager Package", |
9336 | 9336 | "remarks": "rule_set_170" |
9337 | 9337 | }, |
9338 | 9338 | { |
9339 | 9339 | "name": "Rule_Id", |
9340 | 9340 | "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", |
9341 | | - "value": "secure_boot_enabled", |
| 9341 | + "value": "no_shelllogin_for_systemaccounts", |
9342 | 9342 | "remarks": "rule_set_171" |
9343 | 9343 | }, |
9344 | 9344 | { |
9345 | 9345 | "name": "Rule_Description", |
9346 | 9346 | "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", |
9347 | | - "value": "Ensure that Secure Boot is enabled", |
| 9347 | + "value": "Ensure that System Accounts Do Not Run a Shell Upon Login", |
9348 | 9348 | "remarks": "rule_set_171" |
9349 | 9349 | }, |
9350 | 9350 | { |
9351 | 9351 | "name": "Check_Id", |
9352 | 9352 | "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", |
9353 | | - "value": "secure_boot_enabled", |
| 9353 | + "value": "no_shelllogin_for_systemaccounts", |
9354 | 9354 | "remarks": "rule_set_171" |
9355 | 9355 | }, |
9356 | 9356 | { |
9357 | 9357 | "name": "Check_Description", |
9358 | 9358 | "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", |
9359 | | - "value": "Ensure that Secure Boot is enabled", |
| 9359 | + "value": "Ensure that System Accounts Do Not Run a Shell Upon Login", |
9360 | 9360 | "remarks": "rule_set_171" |
| 9361 | + }, |
| 9362 | + { |
| 9363 | + "name": "Rule_Id", |
| 9364 | + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", |
| 9365 | + "value": "secure_boot_enabled", |
| 9366 | + "remarks": "rule_set_172" |
| 9367 | + }, |
| 9368 | + { |
| 9369 | + "name": "Rule_Description", |
| 9370 | + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", |
| 9371 | + "value": "Ensure that Secure Boot is enabled", |
| 9372 | + "remarks": "rule_set_172" |
| 9373 | + }, |
| 9374 | + { |
| 9375 | + "name": "Check_Id", |
| 9376 | + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", |
| 9377 | + "value": "secure_boot_enabled", |
| 9378 | + "remarks": "rule_set_172" |
| 9379 | + }, |
| 9380 | + { |
| 9381 | + "name": "Check_Description", |
| 9382 | + "ns": "https://oscal-compass.github.io/compliance-trestle/schemas/oscal/cd", |
| 9383 | + "value": "Ensure that Secure Boot is enabled", |
| 9384 | + "remarks": "rule_set_172" |
9361 | 9385 | } |
9362 | 9386 | ], |
9363 | 9387 | "control-implementations": [ |
|
0 commit comments