scap-security-guide/SOURCES/scap-security-guide-0.1.58-remove_RHEL_08_040162-PR_7369.patch
2021-11-02 16:51:38 +00:00

64 lines
2.6 KiB
Diff

From 8fa9ca61649a36dd1f3d5e5c72c0162a4dbfe694 Mon Sep 17 00:00:00 2001
From: Gabriel Becker <ggasparb@redhat.com>
Date: Tue, 10 Aug 2021 09:45:56 +0200
Subject: [PATCH] Remove RHEL-08-040162 from STIG profile.
This item has been removed in version RHEL8 DISA STIG V1R3.
---
.../services/ssh/ssh_client/ssh_client_rekey_limit/rule.yml | 1 -
products/rhel8/profiles/stig.profile | 3 ---
tests/data/profile_stability/rhel8/stig.profile | 1 -
tests/data/profile_stability/rhel8/stig_gui.profile | 1 -
4 files changed, 6 deletions(-)
diff --git a/linux_os/guide/services/ssh/ssh_client/ssh_client_rekey_limit/rule.yml b/linux_os/guide/services/ssh/ssh_client/ssh_client_rekey_limit/rule.yml
index 1852313216a..f43f92c2f15 100644
--- a/linux_os/guide/services/ssh/ssh_client/ssh_client_rekey_limit/rule.yml
+++ b/linux_os/guide/services/ssh/ssh_client/ssh_client_rekey_limit/rule.yml
@@ -32,7 +32,6 @@ references:
disa: CCI-000068
ospp: FCS_SSHS_EXT.1
srg: SRG-OS-000423-GPOS-00187,SRG-OS-000033-GPOS-00014
- stigid@rhel8: RHEL-08-040162
ocil_clause: 'it is commented out or is not set'
diff --git a/products/rhel8/profiles/stig.profile b/products/rhel8/profiles/stig.profile
index a358f61dba5..9d4d1965141 100644
--- a/products/rhel8/profiles/stig.profile
+++ b/products/rhel8/profiles/stig.profile
@@ -1071,9 +1071,6 @@ selections:
# RHEL-08-040161
- sshd_rekey_limit
- # RHEL-08-040162
- - ssh_client_rekey_limit
-
# RHEL-08-040170
- disable_ctrlaltdel_reboot
diff --git a/tests/data/profile_stability/rhel8/stig.profile b/tests/data/profile_stability/rhel8/stig.profile
index 7d54a7505fb..fca5842cf22 100644
--- a/tests/data/profile_stability/rhel8/stig.profile
+++ b/tests/data/profile_stability/rhel8/stig.profile
@@ -323,7 +323,6 @@ selections:
- service_usbguard_enabled
- set_password_hashing_algorithm_logindefs
- set_password_hashing_algorithm_systemauth
-- ssh_client_rekey_limit
- sshd_disable_compression
- sshd_disable_empty_passwords
- sshd_disable_gssapi_auth
diff --git a/tests/data/profile_stability/rhel8/stig_gui.profile b/tests/data/profile_stability/rhel8/stig_gui.profile
index 97291230e7c..35fa9ddea2b 100644
--- a/tests/data/profile_stability/rhel8/stig_gui.profile
+++ b/tests/data/profile_stability/rhel8/stig_gui.profile
@@ -334,7 +334,6 @@ selections:
- service_usbguard_enabled
- set_password_hashing_algorithm_logindefs
- set_password_hashing_algorithm_systemauth
-- ssh_client_rekey_limit
- sshd_disable_compression
- sshd_disable_empty_passwords
- sshd_disable_gssapi_auth