DISA STIG RHEL8 V1R3 questions (scap-security-guide/ansible roles/DISA SCAP content) #7627
-
Hi, I'm trying to map the checks I find in the DISA STIG for RHEL8 vs the checks in the role at https://github.com/RedHatOfficial/ansible-role-rhel8-stig. The tasks within that role when following the directions and running "ansible-galaxy install RedHatOfficial.rhel8_stig" An example is:
Does anyone know where this sysctl setting originated? I can't find it anywhere within the published DISA STIG for RHEL8. |
Beta Was this translation helpful? Give feedback.
Replies: 3 comments 2 replies
-
This is a new item part of DISA STIG for RHEL8 V1R3 here is the XML text (STIG id: RHEL-08-040286) of it:
|
Beta Was this translation helpful? Give feedback.
-
Thanks, but is there a way to audit this using oscap? Without a way of generating a compliance report making a system compliant to V1R3 isn't very useful. When we try, we get errors, and we found this RHN article: https://access.redhat.com/solutions/2484341 which states: However, the files included in that package don't appear to include any of the items from V1R3. |
Beta Was this translation helpful? Give feedback.
-
To further confuse the issue, the page at https://github.com/RedHatOfficial/ansible-role-rhel8-stig states that "This profile contains configuration checks that align to the DISA STIG for Red Hat Enterprise Linux 8 V1R2.", and then includes instructions to run "Run ansible-galaxy install RedHatOfficial.rhel8_stig to download and install the role.", but this role actually includes checks for V1R3? We could really use some clarity on this. |
Beta Was this translation helpful? Give feedback.
This is a new item part of DISA STIG for RHEL8 V1R3 here is the XML text (STIG id: RHEL-08-040286) of it: