|
|
dac76a |
From f2024fe66e871a4f7dc54454065f59f4b2bf31db Mon Sep 17 00:00:00 2001
|
|
|
dac76a |
From: Vojtech Polasek <vpolasek@redhat.com>
|
|
|
dac76a |
Date: Thu, 19 Mar 2020 16:48:52 +0100
|
|
|
dac76a |
Subject: [PATCH] add rule
|
|
|
dac76a |
|
|
|
dac76a |
---
|
|
|
dac76a |
.../obsolete/service_rsyncd_disabled/rule.yml | 33 +++++++++++++++++++
|
|
|
dac76a |
shared/references/cce-redhat-avail.txt | 2 --
|
|
|
dac76a |
2 files changed, 33 insertions(+), 2 deletions(-)
|
|
|
dac76a |
create mode 100644 linux_os/guide/services/obsolete/service_rsyncd_disabled/rule.yml
|
|
|
dac76a |
|
|
|
dac76a |
diff --git a/linux_os/guide/services/obsolete/service_rsyncd_disabled/rule.yml b/linux_os/guide/services/obsolete/service_rsyncd_disabled/rule.yml
|
|
|
dac76a |
new file mode 100644
|
|
|
dac76a |
index 0000000000..9cb9d15dcc
|
|
|
dac76a |
--- /dev/null
|
|
|
dac76a |
+++ b/linux_os/guide/services/obsolete/service_rsyncd_disabled/rule.yml
|
|
|
dac76a |
@@ -0,0 +1,33 @@
|
|
|
dac76a |
+documentation_complete: true
|
|
|
dac76a |
+
|
|
|
dac76a |
+prodtype: rhel7,ol7,rhel8,ol8,fedora,rhv4,ocp4
|
|
|
dac76a |
+
|
|
|
dac76a |
+title: 'Ensure rsyncd service is diabled'
|
|
|
dac76a |
+
|
|
|
dac76a |
+description: |-
|
|
|
dac76a |
+ {{{ describe_service_disable("rsyncd") }}}
|
|
|
dac76a |
+
|
|
|
dac76a |
+rationale: |-
|
|
|
dac76a |
+ The rsyncd service presents a security risk as it uses unencrypted protocols for
|
|
|
dac76a |
+ communication.
|
|
|
dac76a |
+
|
|
|
dac76a |
+severity: medium
|
|
|
dac76a |
+
|
|
|
dac76a |
+identifiers:
|
|
|
dac76a |
+ cce@rhel7: 83334-3
|
|
|
dac76a |
+ cce@rhel8: 83335-0
|
|
|
dac76a |
+
|
|
|
dac76a |
+references:
|
|
|
dac76a |
+ cis@rhel7: 2.2.21
|
|
|
dac76a |
+ cis@rhel8: 2.2.3
|
|
|
dac76a |
+
|
|
|
dac76a |
+ocil_clause: 'the service is not disabled'
|
|
|
dac76a |
+
|
|
|
dac76a |
+ocil: |-
|
|
|
dac76a |
+ {{{ ocil_service_disabled("rsyncd") }}}
|
|
|
dac76a |
+
|
|
|
dac76a |
+template:
|
|
|
dac76a |
+ name: service_disabled
|
|
|
dac76a |
+ vars:
|
|
|
dac76a |
+ servicename: rsyncd
|
|
|
dac76a |
+ packagename: rsync
|
|
|
dac76a |
diff --git a/shared/references/cce-redhat-avail.txt b/shared/references/cce-redhat-avail.txt
|
|
|
dac76a |
index a0b117a964..67fa853d75 100644
|
|
|
dac76a |
--- a/shared/references/cce-redhat-avail.txt
|
|
|
dac76a |
+++ b/shared/references/cce-redhat-avail.txt
|
|
|
dac76a |
@@ -45,8 +45,6 @@ CCE-83330-1
|
|
|
dac76a |
CCE-83331-9
|
|
|
dac76a |
CCE-83332-7
|
|
|
dac76a |
CCE-83333-5
|
|
|
dac76a |
-CCE-83334-3
|
|
|
dac76a |
-CCE-83335-0
|
|
|
dac76a |
CCE-83336-8
|
|
|
dac76a |
CCE-83337-6
|
|
|
dac76a |
CCE-83338-4
|