From 59f5ec14e40915bff661f28e50a941d596c34893 Mon Sep 17 00:00:00 2001 From: rchikov Date: Mon, 26 Aug 2024 15:08:18 +0200 Subject: [PATCH] Updated packages related to openssh to support slem --- controls/stig_slmicro5.yml | 10 ++++++---- .../ssh/package_openssh-server_installed/rule.yml | 1 + .../guide/services/ssh/service_sshd_enabled/rule.yml | 2 ++ shared/references/cce-slmicro5-avail.txt | 2 -- 4 files changed, 9 insertions(+), 6 deletions(-) diff --git a/controls/stig_slmicro5.yml b/controls/stig_slmicro5.yml index b83781dcfb8..2059a529f8b 100644 --- a/controls/stig_slmicro5.yml +++ b/controls/stig_slmicro5.yml @@ -584,8 +584,9 @@ controls: title: SLEM 5 must have SSH installed to protect the confidentiality and integrity of transmitted information. - rules: [] - status: pending + rules: + - package_openssh-server_installed + status: automated - id: SLEM-05-255015 levels: @@ -593,8 +594,9 @@ controls: title: SLEM 5 must use SSH to protect the confidentiality and integrity of transmitted information. - rules: [] - status: pending + rules: + - service_sshd_enabled + status: automated - id: SLEM-05-255020 levels: diff --git a/linux_os/guide/services/ssh/package_openssh-server_installed/rule.yml b/linux_os/guide/services/ssh/package_openssh-server_installed/rule.yml index 9ccb296efb6..c46aea1f6c1 100644 --- a/linux_os/guide/services/ssh/package_openssh-server_installed/rule.yml +++ b/linux_os/guide/services/ssh/package_openssh-server_installed/rule.yml @@ -17,6 +17,7 @@ identifiers: cce@rhel8: CCE-83303-8 cce@rhel9: CCE-90823-6 cce@rhel10: CCE-89241-4 + cce@slmicro5: CCE-93770-6 references: cis-csc: 13,14 diff --git a/linux_os/guide/services/ssh/service_sshd_enabled/rule.yml b/linux_os/guide/services/ssh/service_sshd_enabled/rule.yml index d035c6c4c9b..0082b5e2b1c 100644 --- a/linux_os/guide/services/ssh/service_sshd_enabled/rule.yml +++ b/linux_os/guide/services/ssh/service_sshd_enabled/rule.yml @@ -26,6 +26,7 @@ identifiers: cce@rhel10: CCE-88621-8 cce@sle12: CCE-83201-4 cce@sle15: CCE-83297-2 + cce@slmicro5: CCE-93771-4 references: cis-csc: 13,14 @@ -61,6 +62,7 @@ template: packagename: openssh-server packagename@sle12: openssh packagename@sle15: openssh + packagename@slmicro5: openssh fixtext: |- {{{ fixtext_service_enabled("sshd") }}} diff --git a/shared/references/cce-slmicro5-avail.txt b/shared/references/cce-slmicro5-avail.txt index d128593a230..0476683a318 100644 --- a/shared/references/cce-slmicro5-avail.txt +++ b/shared/references/cce-slmicro5-avail.txt @@ -21,8 +21,6 @@ CCE-93764-9 CCE-93765-6 CCE-93766-4 CCE-93767-2 -CCE-93770-6 -CCE-93771-4 CCE-93774-8 CCE-93775-5 CCE-93776-3