You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
* removing vagrant from list of default users in inspec.yml
Signed-off-by: Will <[email protected]>
* rhel9 v2r4 delta
* 270175, 270176, 270177, 270178, 270180, 272488
* 270174
* SV-257837 gui check
* bugs in dconf control grep commands
Signed-off-by: Will <[email protected]>
* fixing busted regex in 258032
Signed-off-by: Will <[email protected]>
* include --> match for SV-258026
Signed-off-by: Will <[email protected]>
* SV-258024 also needed match and not include
Signed-off-by: Will <[email protected]>
* more dconf
Signed-off-by: Will <[email protected]>
* var options needs its own hash
Signed-off-by: Will <[email protected]>
* typo
Signed-off-by: Will <[email protected]>
* typo
Signed-off-by: Will <[email protected]>
* fixing SV-258024
Signed-off-by: Will <[email protected]>
* typo 8-->9
Signed-off-by: Will <[email protected]>
* Adjust Chrony_Conf Control (#70)
* update chrony ctrl and inspec.yml
* remove explicit space char in split call
Was making the linter sad
---------
Co-authored-by: wdower <[email protected]>
* fixes#74
Signed-off-by: Will <[email protected]>
* Root CA File Hash (like rhel8) (#76)
* Update inspec.yml
* Update SV-258131.rb
* cookstyle
---------
Co-authored-by: Jon Metzger <[email protected]>
* fips updates
* Update inspec.yml
* use input from rhel8
* taken from rhel8
* Update SV-258237.rb
* Update SV-258236.rb
* Update inspec.yml
* Delete controls/SV-258010.rb
Deprecated... rhel8 too https://www.tenable.com/audits/items/DISA_STIG_Red_Hat_Enterprise_Linux_9_v1r1.audit:3baf360f4c45501641cc9da71d8d7ccd
* Update SV-258236.rb
* stop_idle_session_sec from rhel8
taken from rhel8
* kerberos
* fix idle time
* fix client path
* cookstyle
* input update
* typo in fix description
* 10 min intervals (latest nessus)
* add back PrivSeparation (dep in later releases)
* cookstyle
* Apply suggestions from code review
Co-authored-by: Jonathan Metzger <[email protected]>
* calculating the SHA so that it matches GitHub's own, to make it easier to find the right pipeline run in Heimdall
Signed-off-by: wdower <[email protected]>
* typo in aws key
Signed-off-by: wdower <[email protected]>
* update 257978, 257987, 258003, 258171, 272496
* update inspec.yml
* rerun delta with new profile.json
* Dconf (#87)
* removing vagrant from list of default users in inspec.yml
Signed-off-by: Will <[email protected]>
* bugs in dconf control grep commands
Signed-off-by: Will <[email protected]>
* fixing busted regex in 258032
Signed-off-by: Will <[email protected]>
* include --> match for SV-258026
Signed-off-by: Will <[email protected]>
* SV-258024 also needed match and not include
Signed-off-by: Will <[email protected]>
* more dconf
Signed-off-by: Will <[email protected]>
* var options needs its own hash
Signed-off-by: Will <[email protected]>
* typo
Signed-off-by: Will <[email protected]>
* typo
Signed-off-by: Will <[email protected]>
* fixing SV-258024
Signed-off-by: Will <[email protected]>
* typo 8-->9
Signed-off-by: Will <[email protected]>
* Adjust Chrony_Conf Control (#70)
* update chrony ctrl and inspec.yml
* remove explicit space char in split call
Was making the linter sad
---------
Co-authored-by: wdower <[email protected]>
* fixes#74
Signed-off-by: Will <[email protected]>
* Root CA File Hash (like rhel8) (#76)
* Update inspec.yml
* Update SV-258131.rb
* cookstyle
---------
Co-authored-by: Jon Metzger <[email protected]>
* fips updates
* Update inspec.yml
* use input from rhel8
* taken from rhel8
* Update SV-258237.rb
* Update SV-258236.rb
* Update inspec.yml
* Delete controls/SV-258010.rb
Deprecated... rhel8 too https://www.tenable.com/audits/items/DISA_STIG_Red_Hat_Enterprise_Linux_9_v1r1.audit:3baf360f4c45501641cc9da71d8d7ccd
* Update SV-258236.rb
* stop_idle_session_sec from rhel8
taken from rhel8
* kerberos
* fix idle time
* fix client path
* cookstyle
* input update
* typo in fix description
* 10 min intervals (latest nessus)
* add back PrivSeparation (dep in later releases)
* cookstyle
* Apply suggestions from code review
Co-authored-by: Jonathan Metzger <[email protected]>
* calculating the SHA so that it matches GitHub's own, to make it easier to find the right pipeline run in Heimdall
Signed-off-by: wdower <[email protected]>
* typo in aws key
Signed-off-by: wdower <[email protected]>
* better tagged suites, adapting to use local repo vars in pipeline
Signed-off-by: wdower <[email protected]>
* testing new workflow pattern
Signed-off-by: wdower <[email protected]>
* working out kitchen + workflow file
Signed-off-by: wdower <[email protected]>
* realizing we need all files committed to support the workflow
Signed-off-by: wdower <[email protected]>
* typo'd line in kitchen
Signed-off-by: wdower <[email protected]>
* taking out currently unused sg and subnet vars
Signed-off-by: wdower <[email protected]>
* trying to match report file
Signed-off-by: wdower <[email protected]>
* updating the other workflows to match the disa one
Signed-off-by: wdower <[email protected]>
* another broken regex fix for 258015
Signed-off-by: Will <[email protected]>
* accounting for server pools in 257945
Signed-off-by: Will <[email protected]>
* kernel.core_pattern update (#81)
|/bin/false
* audit_conf_mode outside of resource (#82)
* audit_conf_mode outside of resource
* Update controls/SV-258171.rb
* renaming the workflows
Signed-off-by: wdower <[email protected]>
* deleted too much of the kitchen command last time
Signed-off-by: wdower <[email protected]>
* fixing linter issues
Signed-off-by: wdower <[email protected]>
* typo in kitchenfile
Signed-off-by: wdower <[email protected]>
* too much detail in suite name
Signed-off-by: wdower <[email protected]>
* turns out we do actually want the github.sha in the context of a pulkl request - these workflows should only run for PRs anywayu
Signed-off-by: wdower <[email protected]>
* using local IB vars to check if we have a good account
Signed-off-by: wdower <[email protected]>
* missed describe block in SV-230484
Signed-off-by: Will <[email protected]>
* replacing SAF vars for the pipeline
Signed-off-by: Will <[email protected]>
---------
Signed-off-by: Will <[email protected]>
Signed-off-by: wdower <[email protected]>
Co-authored-by: DMedina6 <[email protected]>
Co-authored-by: Jonathan Metzger <[email protected]>
Co-authored-by: Jon Metzger <[email protected]>
* updating version tag
Signed-off-by: Will <[email protected]>
* rhel9 v2r4 delta
* bugs in dconf control grep commands
Signed-off-by: Will <[email protected]>
* Adjust Chrony_Conf Control (#70)
* update chrony ctrl and inspec.yml
* remove explicit space char in split call
Was making the linter sad
---------
Co-authored-by: wdower <[email protected]>
* Root CA File Hash (like rhel8) (#76)
* Update inspec.yml
* Update SV-258131.rb
* cookstyle
---------
Co-authored-by: Jon Metzger <[email protected]>
* kerberos
* fix idle time
* input update
* rerun delta with new profile.json
* remove extra files
* remove rhel8 mentions, fix 258022 and 258143
* add missing inspec input for SV-258143
* revert 257974
* bumping version in inspec.yml, using different aws account
Signed-off-by: Will <[email protected]>
* updating luks control SV-257879
Signed-off-by: Will <[email protected]>
* update controls and inputs
* update controls and run rubocop
* update controls
* update controls and inputs
* rubocop
* update controls and fix lint issue
* remove uncessary check, add luks default
* removing unneeded steps in lint, fixing filename in ec2 jobs
Signed-off-by: Will <[email protected]>
* making linter happy, swapping keys
Signed-off-by: Will <[email protected]>
* Revert change since it's causing us to overwrite the results file with the summary file
* Revert change cause it's causing us to overwrite the results file with the summary file
* Readme now has the correct version number
* Fix typo in readme
* swapping keys
Signed-off-by: Will <[email protected]>
---------
Signed-off-by: Will <[email protected]>
Signed-off-by: wdower <[email protected]>
Co-authored-by: Will <[email protected]>
Co-authored-by: DMedina6 <[email protected]>
Co-authored-by: wdower <[email protected]>
Co-authored-by: Jonathan Metzger <[email protected]>
Co-authored-by: Jon Metzger <[email protected]>
Co-authored-by: Amndeep Singh Mann <[email protected]>
Copy file name to clipboardExpand all lines: README.md
+19-18Lines changed: 19 additions & 18 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -2,8 +2,8 @@
2
2
3
3
The Redhat Enterprise Linux 9.X Security Technical Implementation Guide (RHEL9.x STIG) InSpec Profile can help programs automate their compliance checks of RedHat Enterprise Linux 9.x System to Department of Defense (DoD) requirements.
4
4
5
-
- Profile Version: `1.2.2`
6
-
- RedHat Enterprise Linux 9 Security Technical Implementation Guide v1r2
5
+
- Profile Version: `2.4.0`
6
+
- RedHat Enterprise Linux 9 Security Technical Implementation Guide v2r4
7
7
8
8
This profile was developed to reduce the time it takes to perform a security checks based upon the STIG Guidance from the Defense Information Systems Agency (DISA) in partnership between the DISA Services Directorate (SD) and the DISA Risk Management Executive (RME) office.
9
9
@@ -14,17 +14,17 @@ The RHEL8 STIG Profile uses the [InSpec](https://github.com/inspec/inspec) open-
14
14
Table of Contents
15
15
=================
16
16
17
-
*[RedHat Enterprise Linux 9.x Security Technical Implementation Guide InSpec Profile](#redhat-enterprise-linux-9x-security-technical-implementation-guide-inspec-profile)
18
-
*[RedHat 9.x Enterprise Linux Security Technical Implementation Guide (RHEL9 STIG)](#redhat-9x-enterprise-linux-security-technical-implementation-guide-rhel9-stig)
19
-
*[Getting Started and Intended Usage](#getting-started-and-intended-usage)
20
-
*[Intended Usage - main vs releases](#intended-usage---main-vs-releases)
*[Tailoring to Your Environment](#tailoring-to-your-environment)
23
-
*[Running the Profile](#running-the-profile)
24
-
*[(connected) Running the Profile Directly](#connected-running-the-profile-directly)
25
-
*[(disconnected) Running the profile from a local archive copy](#disconnected-running-the-profile-from-a-local-archive-copy)
26
-
*[Different Run Options](#different-run-options)
27
-
*[Using Heimdall for Viewing Test Results and Exporting for Checklist and eMASS](#using-heimdall-for-viewing-test-results-and-exporting-for-checklist-and-emass)
17
+
-[RedHat Enterprise Linux 9.x Security Technical Implementation Guide InSpec Profile](#redhat-enterprise-linux-9x-security-technical-implementation-guide-inspec-profile)
18
+
-[RedHat 9.x Enterprise Linux Security Technical Implementation Guide (RHEL9 STIG)](#redhat-9x-enterprise-linux-security-technical-implementation-guide-rhel9-stig)
19
+
-[Getting Started and Intended Usage](#getting-started-and-intended-usage)
20
+
-[Intended Usage - main vs releases](#intended-usage---main-vs-releases)
-[Tailoring to Your Environment](#tailoring-to-your-environment)
23
+
-[Running the Profile](#running-the-profile)
24
+
-[(connected) Running the Profile Directly](#connected-running-the-profile-directly)
25
+
-[(disconnected) Running the profile from a local archive copy](#disconnected-running-the-profile-from-a-local-archive-copy)
26
+
-[Different Run Options](#different-run-options)
27
+
-[Using Heimdall for Viewing Test Results and Exporting for Checklist and eMASS](#using-heimdall-for-viewing-test-results-and-exporting-for-checklist-and-emass)
0 commit comments