|
 |
ff1465 |
commit 94a680f9601fc2119c08fc6514712611d7f0d935
|
|
 |
ff1465 |
Author: Gabriel Becker <ggasparb@redhat.com>
|
|
 |
ff1465 |
Date: Fri Feb 25 14:43:33 2022 +0100
|
|
 |
ff1465 |
|
|
 |
ff1465 |
Manual edited patch scap-security-guide-0.1.61-update_RHEL_STIG-PR_8130.patch.
|
|
 |
ff1465 |
|
|
 |
ff1465 |
diff --git a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_group_ownership_library_dirs/rule.yml b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_group_ownership_library_dirs/rule.yml
|
|
 |
ff1465 |
index 10203c9..3c9e460 100644
|
|
 |
ff1465 |
--- a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_group_ownership_library_dirs/rule.yml
|
|
 |
ff1465 |
+++ b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_group_ownership_library_dirs/rule.yml
|
|
 |
ff1465 |
@@ -37,7 +37,7 @@ references:
|
|
 |
ff1465 |
disa: CCI-001499
|
|
 |
ff1465 |
nist: CM-5(6),CM-5(6).1
|
|
 |
ff1465 |
srg: SRG-OS-000259-GPOS-00100
|
|
 |
ff1465 |
- stigid@rhel8: RHEL-08-010350
|
|
 |
ff1465 |
+ stigid@rhel8: RHEL-08-010351
|
|
 |
ff1465 |
stigid@sle12: SLES-12-010876
|
|
 |
ff1465 |
stigid@sle15: SLES-15-010356
|
|
 |
ff1465 |
stigid@ubuntu2004: UBTU-20-010431
|
|
 |
ff1465 |
diff --git a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_group_ownership_library_dirs/tests/all_dirs_ok.pass.sh b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_group_ownership_library_dirs/tests/all_dirs_ok.pass.sh
|
|
 |
ff1465 |
index 50fdb17..6a05a2b 100644
|
|
 |
ff1465 |
--- a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_group_ownership_library_dirs/tests/all_dirs_ok.pass.sh
|
|
 |
ff1465 |
+++ b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_group_ownership_library_dirs/tests/all_dirs_ok.pass.sh
|
|
 |
ff1465 |
@@ -1,4 +1,4 @@
|
|
 |
ff1465 |
-# platform = multi_platform_sle,Red Hat Enterprise Linux 8,multi_platform_fedora
|
|
 |
ff1465 |
+# platform = multi_platform_sle,multi_platform_rhel,multi_platform_fedora
|
|
 |
ff1465 |
|
|
 |
ff1465 |
DIRS="/lib /lib64 /usr/lib /usr/lib64"
|
|
 |
ff1465 |
for dirPath in $DIRS; do
|
|
 |
ff1465 |
diff --git a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_group_ownership_library_dirs/tests/correct_groupowner.pass.sh b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_group_ownership_library_dirs/tests/correct_groupowner.pass.sh
|
|
 |
ff1465 |
new file mode 100644
|
|
 |
ff1465 |
index 0000000..6a05a2b
|
|
 |
ff1465 |
--- /dev/null
|
|
 |
ff1465 |
+++ b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_group_ownership_library_dirs/tests/correct_groupowner.pass.sh
|
|
 |
ff1465 |
@@ -0,0 +1,6 @@
|
|
 |
ff1465 |
+# platform = multi_platform_sle,multi_platform_rhel,multi_platform_fedora
|
|
 |
ff1465 |
+
|
|
 |
ff1465 |
+DIRS="/lib /lib64 /usr/lib /usr/lib64"
|
|
 |
ff1465 |
+for dirPath in $DIRS; do
|
|
 |
ff1465 |
+ find "$dirPath" -type d -exec chgrp root '{}' \;
|
|
 |
ff1465 |
+done
|
|
 |
ff1465 |
diff --git a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_group_ownership_library_dirs/tests/incorrect_groupowner.fail.sh b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_group_ownership_library_dirs/tests/incorrect_groupowner.fail.sh
|
|
 |
ff1465 |
new file mode 100644
|
|
 |
ff1465 |
index 0000000..36461f5
|
|
 |
ff1465 |
--- /dev/null
|
|
 |
ff1465 |
+++ b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_group_ownership_library_dirs/tests/incorrect_groupowner.fail.sh
|
|
 |
ff1465 |
@@ -0,0 +1,6 @@
|
|
 |
ff1465 |
+# platform = multi_platform_sle,multi_platform_rhel,multi_platform_fedora
|
|
 |
ff1465 |
+
|
|
 |
ff1465 |
+DIRS="/lib /lib64 /usr/lib /usr/lib64"
|
|
 |
ff1465 |
+for dirPath in $DIRS; do
|
|
 |
ff1465 |
+ mkdir -p "$dirPath/testme" && chgrp nobody "$dirPath/testme"
|
|
 |
ff1465 |
+done
|
|
 |
ff1465 |
diff --git a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_group_ownership_library_dirs/tests/incorrect_groupowner_2.fail.sh b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_group_ownership_library_dirs/tests/incorrect_groupowner_2.fail.sh
|
|
 |
ff1465 |
new file mode 100644
|
|
 |
ff1465 |
index 0000000..3f09e3d
|
|
 |
ff1465 |
--- /dev/null
|
|
 |
ff1465 |
+++ b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_group_ownership_library_dirs/tests/incorrect_groupowner_2.fail.sh
|
|
 |
ff1465 |
@@ -0,0 +1,6 @@
|
|
 |
ff1465 |
+# platform = multi_platform_sle,multi_platform_rhel,multi_platform_fedora
|
|
 |
ff1465 |
+
|
|
 |
ff1465 |
+DIRS="/lib /lib64 /usr/lib /usr/lib64"
|
|
 |
ff1465 |
+for dirPath in $DIRS; do
|
|
 |
ff1465 |
+ mkdir -p "$dirPath/testme/test2" && chgrp nobody "$dirPath/testme/test2"
|
|
 |
ff1465 |
+done
|
|
 |
ff1465 |
diff --git a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_group_ownership_library_dirs/tests/nobody_group_owned_dir_on_lib.fail.sh b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_group_ownership_library_dirs/tests/nobody_group_owned_dir_on_lib.fail.sh
|
|
 |
ff1465 |
index 043ad6b..36461f5 100644
|
|
 |
ff1465 |
--- a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_group_ownership_library_dirs/tests/nobody_group_owned_dir_on_lib.fail.sh
|
|
 |
ff1465 |
+++ b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_group_ownership_library_dirs/tests/nobody_group_owned_dir_on_lib.fail.sh
|
|
 |
ff1465 |
@@ -1,4 +1,4 @@
|
|
 |
ff1465 |
-# platform = multi_platform_sle,Red Hat Enterprise Linux 8,multi_platform_fedora
|
|
 |
ff1465 |
+# platform = multi_platform_sle,multi_platform_rhel,multi_platform_fedora
|
|
 |
ff1465 |
|
|
 |
ff1465 |
DIRS="/lib /lib64 /usr/lib /usr/lib64"
|
|
 |
ff1465 |
for dirPath in $DIRS; do
|
|
 |
ff1465 |
diff --git a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_ownership_binary_dirs/rule.yml b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_ownership_binary_dirs/rule.yml
|
|
 |
ff1465 |
index e236238..ba923d8 100644
|
|
 |
ff1465 |
--- a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_ownership_binary_dirs/rule.yml
|
|
 |
ff1465 |
+++ b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_ownership_binary_dirs/rule.yml
|
|
 |
ff1465 |
@@ -27,7 +27,7 @@ references:
|
|
 |
ff1465 |
srg: SRG-OS-000258-GPOS-00099
|
|
 |
ff1465 |
stigid@ubuntu2004: UBTU-20-010424
|
|
 |
ff1465 |
|
|
 |
ff1465 |
-ocil_clause: 'any system exectables directories are found to not be owned by root'
|
|
 |
ff1465 |
+ocil_clause: 'any system executables directories are found to not be owned by root'
|
|
 |
ff1465 |
|
|
 |
ff1465 |
ocil: |-
|
|
 |
ff1465 |
System executables are stored in the following directories by default:
|
|
 |
ff1465 |
diff --git a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_ownership_library_dirs/oval/shared.xml b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_ownership_library_dirs/oval/shared.xml
|
|
 |
ff1465 |
deleted file mode 100644
|
|
 |
ff1465 |
index 28e193f..0000000
|
|
 |
ff1465 |
--- a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_ownership_library_dirs/oval/shared.xml
|
|
 |
ff1465 |
+++ /dev/null
|
|
 |
ff1465 |
@@ -1,28 +0,0 @@
|
|
 |
ff1465 |
-<def-group>
|
|
 |
ff1465 |
- <definition class="compliance" id="dir_ownership_library_dirs" version="1">
|
|
 |
ff1465 |
- {{{ oval_metadata("
|
|
 |
ff1465 |
- Checks that /lib, /lib64, /usr/lib, /usr/lib64, /lib/modules, and
|
|
 |
ff1465 |
- directories therein, are owned by root.
|
|
 |
ff1465 |
- ") }}}
|
|
 |
ff1465 |
- <criteria operator="AND">
|
|
 |
ff1465 |
- <criterion test_ref="test_dir_ownership_lib_dir" />
|
|
 |
ff1465 |
- </criteria>
|
|
 |
ff1465 |
- </definition>
|
|
 |
ff1465 |
-
|
|
 |
ff1465 |
- <unix:file_test check="all" check_existence="none_exist" comment="library directories uid root" id="test_dir_ownership_lib_dir" version="1">
|
|
 |
ff1465 |
- <unix:object object_ref="object_dir_ownership_lib_dir" />
|
|
 |
ff1465 |
- </unix:file_test>
|
|
 |
ff1465 |
-
|
|
 |
ff1465 |
-
|
|
 |
ff1465 |
- <unix:file_object comment="library directories" id="object_dir_ownership_lib_dir" version="1">
|
|
 |
ff1465 |
-
|
|
 |
ff1465 |
- <unix:path operation="pattern match">^\/lib(|64)\/|^\/usr\/lib(|64)\/</unix:path>
|
|
 |
ff1465 |
- <unix:filename xsi:nil="true" />
|
|
 |
ff1465 |
- <filter action="include">state_owner_library_dirs_not_root</filter>
|
|
 |
ff1465 |
- </unix:file_object>
|
|
 |
ff1465 |
-
|
|
 |
ff1465 |
- <unix:file_state id="state_owner_library_dirs_not_root" version="1">
|
|
 |
ff1465 |
- <unix:user_id datatype="int" operation="not equal">0</unix:user_id>
|
|
 |
ff1465 |
- </unix:file_state>
|
|
 |
ff1465 |
-
|
|
 |
ff1465 |
-</def-group>
|
|
 |
ff1465 |
diff --git a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_ownership_library_dirs/rule.yml b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_ownership_library_dirs/rule.yml
|
|
 |
ff1465 |
index d6a0bed..f0781b3 100644
|
|
 |
ff1465 |
--- a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_ownership_library_dirs/rule.yml
|
|
 |
ff1465 |
+++ b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_ownership_library_dirs/rule.yml
|
|
 |
ff1465 |
@@ -27,6 +27,8 @@ rationale: |-
|
|
 |
ff1465 |
severity: medium
|
|
 |
ff1465 |
|
|
 |
ff1465 |
identifiers:
|
|
 |
ff1465 |
+ cce@rhel8: CCE-89021-0
|
|
 |
ff1465 |
+ cce@rhel9: CCE-89022-8
|
|
 |
ff1465 |
cce@sle12: CCE-83236-0
|
|
 |
ff1465 |
cce@sle15: CCE-85735-9
|
|
 |
ff1465 |
|
|
 |
ff1465 |
@@ -34,6 +36,7 @@ references:
|
|
 |
ff1465 |
disa: CCI-001499
|
|
 |
ff1465 |
nist: CM-5(6),CM-5(6).1
|
|
 |
ff1465 |
srg: SRG-OS-000259-GPOS-00100
|
|
 |
ff1465 |
+ stigid@rhel8: RHEL-08-010341
|
|
 |
ff1465 |
stigid@sle12: SLES-12-010874
|
|
 |
ff1465 |
stigid@sle15: SLES-15-010354
|
|
 |
ff1465 |
stigid@ubuntu2004: UBTU-20-010429
|
|
 |
ff1465 |
@@ -49,3 +52,14 @@ ocil: |-
|
|
 |
ff1465 |
For each of these directories, run the following command to find files not
|
|
 |
ff1465 |
owned by root:
|
|
 |
ff1465 |
$ sudo find -L $DIR ! -user root -type d -exec chown root {} \;
|
|
 |
ff1465 |
+
|
|
 |
ff1465 |
+template:
|
|
 |
ff1465 |
+ name: file_owner
|
|
 |
ff1465 |
+ vars:
|
|
 |
ff1465 |
+ filepath:
|
|
 |
ff1465 |
+ - /lib/
|
|
 |
ff1465 |
+ - /lib64/
|
|
 |
ff1465 |
+ - /usr/lib/
|
|
 |
ff1465 |
+ - /usr/lib64/
|
|
 |
ff1465 |
+ recursive: 'true'
|
|
 |
ff1465 |
+ fileuid: '0'
|
|
 |
ff1465 |
diff --git a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_ownership_library_dirs/tests/all_dirs_ok.pass.sh b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_ownership_library_dirs/tests/correct_owner.pass.sh
|
|
 |
ff1465 |
similarity index 69%
|
|
 |
ff1465 |
rename from linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_ownership_library_dirs/tests/all_dirs_ok.pass.sh
|
|
 |
ff1465 |
rename to linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_ownership_library_dirs/tests/correct_owner.pass.sh
|
|
 |
ff1465 |
index 0189166..a0d4990 100644
|
|
 |
ff1465 |
--- a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_ownership_library_dirs/tests/all_dirs_ok.pass.sh
|
|
 |
ff1465 |
+++ b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_ownership_library_dirs/tests/correct_owner.pass.sh
|
|
 |
ff1465 |
@@ -1,4 +1,4 @@
|
|
 |
ff1465 |
-# platform = multi_platform_sle
|
|
 |
ff1465 |
+# platform = multi_platform_sle,multi_platform_rhel
|
|
 |
ff1465 |
DIRS="/lib /lib64 /usr/lib /usr/lib64"
|
|
 |
ff1465 |
for dirPath in $DIRS; do
|
|
 |
ff1465 |
find "$dirPath" -type d -exec chown root '{}' \;
|
|
 |
ff1465 |
diff --git a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_ownership_library_dirs/tests/nobody_owned_dir_on_lib.fail.sh b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_ownership_library_dirs/tests/incorrect_owner.fail.sh
|
|
 |
ff1465 |
similarity index 63%
|
|
 |
ff1465 |
rename from linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_ownership_library_dirs/tests/nobody_owned_dir_on_lib.fail.sh
|
|
 |
ff1465 |
rename to linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_ownership_library_dirs/tests/incorrect_owner.fail.sh
|
|
 |
ff1465 |
index 59b8a18..f366c2d 100644
|
|
 |
ff1465 |
--- a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_ownership_library_dirs/tests/nobody_owned_dir_on_lib.fail.sh
|
|
 |
ff1465 |
+++ b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_ownership_library_dirs/tests/incorrect_owner.fail.sh
|
|
 |
ff1465 |
@@ -1,4 +1,5 @@
|
|
 |
ff1465 |
-# platform = multi_platform_sle
|
|
 |
ff1465 |
+# platform = multi_platform_sle,multi_platform_rhel
|
|
 |
ff1465 |
+groupadd nogroup
|
|
 |
ff1465 |
DIRS="/lib /lib64"
|
|
 |
ff1465 |
for dirPath in $DIRS; do
|
|
 |
ff1465 |
mkdir -p "$dirPath/testme" && chown nobody:nogroup "$dirPath/testme"
|
|
 |
ff1465 |
diff --git a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_permissions_library_dirs/oval/shared.xml b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_permissions_library_dirs/oval/shared.xml
|
|
 |
ff1465 |
index a0e4e24..add26b2 100644
|
|
 |
ff1465 |
--- a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_permissions_library_dirs/oval/shared.xml
|
|
 |
ff1465 |
+++ b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_permissions_library_dirs/oval/shared.xml
|
|
 |
ff1465 |
@@ -1,8 +1,8 @@
|
|
 |
ff1465 |
<def-group>
|
|
 |
ff1465 |
<definition class="compliance" id="dir_permissions_library_dirs" version="1">
|
|
 |
ff1465 |
{{{ oval_metadata("
|
|
 |
ff1465 |
- Checks that /lib, /lib64, /usr/lib, /usr/lib64, /lib/modules, and
|
|
 |
ff1465 |
- objects therein, are not group-writable or world-writable.
|
|
 |
ff1465 |
+ Checks that the directories /lib, /lib64, /usr/lib and /usr/lib64
|
|
 |
ff1465 |
+ are not group-writable or world-writable.
|
|
 |
ff1465 |
") }}}
|
|
 |
ff1465 |
<criteria operator="AND">
|
|
 |
ff1465 |
<criterion test_ref="dir_test_perms_lib_dir" />
|
|
 |
ff1465 |
@@ -19,7 +19,7 @@
|
|
 |
ff1465 |
<unix:path operation="pattern match">^\/lib(|64)|^\/usr\/lib(|64)</unix:path>
|
|
 |
ff1465 |
<unix:filename xsi:nil="true" />
|
|
 |
ff1465 |
<filter action="include">dir_state_perms_nogroupwrite_noworldwrite</filter>
|
|
 |
ff1465 |
- <filter action="exclude">dir_perms_state_symlink</filter>
|
|
 |
ff1465 |
+ <filter action="exclude">dir_perms_state_nogroupwrite_noworldwrite_symlink</filter>
|
|
 |
ff1465 |
</unix:file_object>
|
|
 |
ff1465 |
|
|
 |
ff1465 |
<unix:file_state id="dir_state_perms_nogroupwrite_noworldwrite" version="1" operator="OR">
|
|
 |
ff1465 |
@@ -27,7 +27,7 @@
|
|
 |
ff1465 |
<unix:owrite datatype="boolean">true</unix:owrite>
|
|
 |
ff1465 |
</unix:file_state>
|
|
 |
ff1465 |
|
|
 |
ff1465 |
- <unix:file_state id="dir_perms_state_symlink" version="1">
|
|
 |
ff1465 |
+ <unix:file_state id="dir_perms_state_nogroupwrite_noworldwrite_symlink" version="1">
|
|
 |
ff1465 |
<unix:type operation="equals">symbolic link</unix:type>
|
|
 |
ff1465 |
</unix:file_state>
|
|
 |
ff1465 |
|
|
 |
ff1465 |
diff --git a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_permissions_library_dirs/rule.yml b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_permissions_library_dirs/rule.yml
|
|
 |
ff1465 |
index 853f8ac..558eaa7 100644
|
|
 |
ff1465 |
--- a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_permissions_library_dirs/rule.yml
|
|
 |
ff1465 |
+++ b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_permissions_library_dirs/rule.yml
|
|
 |
ff1465 |
@@ -60,3 +60,14 @@ ocil: |-
|
|
 |
ff1465 |
To find shared libraries that are group-writable or world-writable,
|
|
 |
ff1465 |
run the following command for each directory DIR which contains shared libraries:
|
|
 |
ff1465 |
$ sudo find -L DIR -perm /022 -type d
|
|
 |
ff1465 |
+
|
|
 |
ff1465 |
+template:
|
|
 |
ff1465 |
+ name: file_permissions
|
|
 |
ff1465 |
+ vars:
|
|
 |
ff1465 |
+ filepath:
|
|
 |
ff1465 |
+ - /lib/
|
|
 |
ff1465 |
+ - /lib64/
|
|
 |
ff1465 |
+ - /usr/lib/
|
|
 |
ff1465 |
+ - /usr/lib64/
|
|
 |
ff1465 |
+ recursive: 'true'
|
|
 |
ff1465 |
+ filemode: '0755'
|
|
 |
ff1465 |
diff --git a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_groupownership_system_commands_dirs/ansible/shared.yml b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_groupownership_system_commands_dirs/ansible/shared.yml
|
|
 |
ff1465 |
index 7168288..eec7485 100644
|
|
 |
ff1465 |
--- a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_groupownership_system_commands_dirs/ansible/shared.yml
|
|
 |
ff1465 |
+++ b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_groupownership_system_commands_dirs/ansible/shared.yml
|
|
 |
ff1465 |
@@ -1,4 +1,4 @@
|
|
 |
ff1465 |
-# platform = multi_platform_sle,Red Hat Enterprise Linux 8,multi_platform_fedora
|
|
 |
ff1465 |
+# platform = multi_platform_sle,Oracle Linux 8,multi_platform_rhel,multi_platform_fedora
|
|
 |
ff1465 |
# reboot = false
|
|
 |
ff1465 |
# strategy = restrict
|
|
 |
ff1465 |
# complexity = medium
|
|
 |
ff1465 |
diff --git a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_groupownership_system_commands_dirs/bash/shared.sh b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_groupownership_system_commands_dirs/bash/shared.sh
|
|
 |
ff1465 |
index a9e8c7d..e352dd3 100644
|
|
 |
ff1465 |
--- a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_groupownership_system_commands_dirs/bash/shared.sh
|
|
 |
ff1465 |
+++ b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_groupownership_system_commands_dirs/bash/shared.sh
|
|
 |
ff1465 |
@@ -1,4 +1,4 @@
|
|
 |
ff1465 |
-# platform = multi_platform_sle,Oracle Linux 8,Red Hat Enterprise Linux 8,multi_platform_fedora,multi_platform_ubuntu
|
|
 |
ff1465 |
+# platform = multi_platform_sle,Oracle Linux 8,multi_platform_rhel,multi_platform_fedora,multi_platform_ubuntu
|
|
 |
ff1465 |
|
|
 |
ff1465 |
for SYSCMDFILES in /bin /sbin /usr/bin /usr/sbin /usr/local/bin /usr/local/sbin
|
|
 |
ff1465 |
do
|
|
 |
ff1465 |
diff --git a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_ownership_library_dirs/ansible/shared.yml b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_ownership_library_dirs/ansible/shared.yml
|
|
 |
ff1465 |
deleted file mode 100644
|
|
 |
ff1465 |
index de81a37..0000000
|
|
 |
ff1465 |
--- a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_ownership_library_dirs/ansible/shared.yml
|
|
 |
ff1465 |
+++ /dev/null
|
|
 |
ff1465 |
@@ -1,18 +0,0 @@
|
|
 |
ff1465 |
-# platform = Red Hat Virtualization 4,multi_platform_fedora,multi_platform_rhel,multi_platform_ol,multi_platform_sle
|
|
 |
ff1465 |
-# reboot = false
|
|
 |
ff1465 |
-# strategy = restrict
|
|
 |
ff1465 |
-# complexity = medium
|
|
 |
ff1465 |
-# disruption = medium
|
|
 |
ff1465 |
-- name: "Read list libraries without root ownership"
|
|
 |
ff1465 |
- command: "find -L /usr/lib /usr/lib64 /lib /lib64 \\! -user root"
|
|
 |
ff1465 |
- register: libraries_not_owned_by_root
|
|
 |
ff1465 |
- changed_when: False
|
|
 |
ff1465 |
- failed_when: False
|
|
 |
ff1465 |
- check_mode: no
|
|
 |
ff1465 |
-
|
|
 |
ff1465 |
-- name: "Set ownership of system libraries to root"
|
|
 |
ff1465 |
- file:
|
|
 |
ff1465 |
- path: "{{ item }}"
|
|
 |
ff1465 |
- owner: "root"
|
|
 |
ff1465 |
- with_items: "{{ libraries_not_owned_by_root.stdout_lines }}"
|
|
 |
ff1465 |
- when: libraries_not_owned_by_root | length > 0
|
|
 |
ff1465 |
diff --git a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_ownership_library_dirs/bash/shared.sh b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_ownership_library_dirs/bash/shared.sh
|
|
 |
ff1465 |
deleted file mode 100644
|
|
 |
ff1465 |
index c75167d..0000000
|
|
 |
ff1465 |
--- a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_ownership_library_dirs/bash/shared.sh
|
|
 |
ff1465 |
+++ /dev/null
|
|
 |
ff1465 |
@@ -1,8 +0,0 @@
|
|
 |
ff1465 |
-# platform = Red Hat Virtualization 4,multi_platform_fedora,multi_platform_rhel,multi_platform_ol,multi_platform_sle
|
|
 |
ff1465 |
-for LIBDIR in /usr/lib /usr/lib64 /lib /lib64
|
|
 |
ff1465 |
-do
|
|
 |
ff1465 |
- if [ -d $LIBDIR ]
|
|
 |
ff1465 |
- then
|
|
 |
ff1465 |
- find -L $LIBDIR \! -user root -exec chown root {} \;
|
|
 |
ff1465 |
- fi
|
|
 |
ff1465 |
-done
|
|
 |
ff1465 |
diff --git a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_ownership_library_dirs/oval/shared.xml b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_ownership_library_dirs/oval/shared.xml
|
|
 |
ff1465 |
deleted file mode 100644
|
|
 |
ff1465 |
index 59ee3d8..0000000
|
|
 |
ff1465 |
--- a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_ownership_library_dirs/oval/shared.xml
|
|
 |
ff1465 |
+++ /dev/null
|
|
 |
ff1465 |
@@ -1,39 +0,0 @@
|
|
 |
ff1465 |
-<def-group>
|
|
 |
ff1465 |
- <definition class="compliance" id="file_ownership_library_dirs" version="1">
|
|
 |
ff1465 |
- {{{ oval_metadata("
|
|
 |
ff1465 |
- Checks that /lib, /lib64, /usr/lib, /usr/lib64, /lib/modules, and
|
|
 |
ff1465 |
- objects therein, are owned by root.
|
|
 |
ff1465 |
- ") }}}
|
|
 |
ff1465 |
- <criteria operator="AND">
|
|
 |
ff1465 |
- <criterion test_ref="test_ownership_lib_dir" />
|
|
 |
ff1465 |
- <criterion test_ref="test_ownership_lib_files" />
|
|
 |
ff1465 |
- </criteria>
|
|
 |
ff1465 |
- </definition>
|
|
 |
ff1465 |
-
|
|
 |
ff1465 |
- <unix:file_test check="all" check_existence="none_exist" comment="library directories uid root" id="test_ownership_lib_dir" version="1">
|
|
 |
ff1465 |
- <unix:object object_ref="object_file_ownership_lib_dir" />
|
|
 |
ff1465 |
- </unix:file_test>
|
|
 |
ff1465 |
-
|
|
 |
ff1465 |
- <unix:file_test check="all" check_existence="none_exist" comment="library files uid root" id="test_ownership_lib_files" version="1">
|
|
 |
ff1465 |
- <unix:object object_ref="object_file_ownership_lib_files" />
|
|
 |
ff1465 |
- </unix:file_test>
|
|
 |
ff1465 |
-
|
|
 |
ff1465 |
- <unix:file_object comment="library directories" id="object_file_ownership_lib_dir" version="1">
|
|
 |
ff1465 |
-
|
|
 |
ff1465 |
- <unix:path operation="pattern match">^\/lib(|64)\/|^\/usr\/lib(|64)\/</unix:path>
|
|
 |
ff1465 |
- <unix:filename xsi:nil="true" />
|
|
 |
ff1465 |
- <filter action="include">state_owner_libraries_not_root</filter>
|
|
 |
ff1465 |
- </unix:file_object>
|
|
 |
ff1465 |
-
|
|
 |
ff1465 |
- <unix:file_object comment="library files" id="object_file_ownership_lib_files" version="1">
|
|
 |
ff1465 |
-
|
|
 |
ff1465 |
- <unix:path operation="pattern match">^\/lib(|64)\/|^\/usr\/lib(|64)\/</unix:path>
|
|
 |
ff1465 |
- <unix:filename operation="pattern match">^.*$</unix:filename>
|
|
 |
ff1465 |
- <filter action="include">state_owner_libraries_not_root</filter>
|
|
 |
ff1465 |
- </unix:file_object>
|
|
 |
ff1465 |
-
|
|
 |
ff1465 |
- <unix:file_state id="state_owner_libraries_not_root" version="1">
|
|
 |
ff1465 |
- <unix:user_id datatype="int" operation="not equal">0</unix:user_id>
|
|
 |
ff1465 |
- </unix:file_state>
|
|
 |
ff1465 |
-
|
|
 |
ff1465 |
-</def-group>
|
|
 |
ff1465 |
diff --git a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_ownership_library_dirs/rule.yml b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_ownership_library_dirs/rule.yml
|
|
 |
ff1465 |
index dfedd25..81089d3 100644
|
|
 |
ff1465 |
--- a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_ownership_library_dirs/rule.yml
|
|
 |
ff1465 |
+++ b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_ownership_library_dirs/rule.yml
|
|
 |
ff1465 |
@@ -59,3 +59,14 @@ ocil: |-
|
|
 |
ff1465 |
For each of these directories, run the following command to find files not
|
|
 |
ff1465 |
owned by root:
|
|
 |
ff1465 |
$ sudo find -L $DIR ! -user root -exec chown root {} \;
|
|
 |
ff1465 |
+
|
|
 |
ff1465 |
+template:
|
|
 |
ff1465 |
+ name: file_owner
|
|
 |
ff1465 |
+ vars:
|
|
 |
ff1465 |
+ filepath:
|
|
 |
ff1465 |
+ - /lib/
|
|
 |
ff1465 |
+ - /lib64/
|
|
 |
ff1465 |
+ - /usr/lib/
|
|
 |
ff1465 |
+ - /usr/lib64/
|
|
 |
ff1465 |
+ file_regex: ^.*$
|
|
 |
ff1465 |
+ fileuid: '0'
|
|
 |
ff1465 |
diff --git a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_ownership_library_dirs/tests/correct_owner.pass.sh b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_ownership_library_dirs/tests/correct_owner.pass.sh
|
|
 |
ff1465 |
new file mode 100644
|
|
 |
ff1465 |
index 0000000..92c6a08
|
|
 |
ff1465 |
--- /dev/null
|
|
 |
ff1465 |
+++ b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_ownership_library_dirs/tests/correct_owner.pass.sh
|
|
 |
ff1465 |
@@ -0,0 +1,9 @@
|
|
 |
ff1465 |
+# platform = multi_platform_sle,multi_platform_rhel,multi_platform_fedora,multi_platform_ubuntu
|
|
 |
ff1465 |
+
|
|
 |
ff1465 |
+for SYSLIBDIRS in /lib /lib64 /usr/lib /usr/lib64
|
|
 |
ff1465 |
+do
|
|
 |
ff1465 |
+ if [[ -d $SYSLIBDIRS ]]
|
|
 |
ff1465 |
+ then
|
|
 |
ff1465 |
+ find $SYSLIBDIRS ! -user root -type f -exec chown root '{}' \;
|
|
 |
ff1465 |
+ fi
|
|
 |
ff1465 |
+done
|
|
 |
ff1465 |
diff --git a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_ownership_library_dirs/tests/incorrect_owner.fail.sh b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_ownership_library_dirs/tests/incorrect_owner.fail.sh
|
|
 |
ff1465 |
new file mode 100644
|
|
 |
ff1465 |
index 0000000..84da71f
|
|
 |
ff1465 |
--- /dev/null
|
|
 |
ff1465 |
+++ b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_ownership_library_dirs/tests/incorrect_owner.fail.sh
|
|
 |
ff1465 |
@@ -0,0 +1,11 @@
|
|
 |
ff1465 |
+# platform = multi_platform_sle,multi_platform_rhel,multi_platform_fedora,multi_platform_ubuntu
|
|
 |
ff1465 |
+
|
|
 |
ff1465 |
+useradd user_test
|
|
 |
ff1465 |
+for TESTFILE in /lib/test_me /lib64/test_me /usr/lib/test_me /usr/lib64/test_me
|
|
 |
ff1465 |
+do
|
|
 |
ff1465 |
+ if [[ ! -f $TESTFILE ]]
|
|
 |
ff1465 |
+ then
|
|
 |
ff1465 |
+ touch $TESTFILE
|
|
 |
ff1465 |
+ fi
|
|
 |
ff1465 |
+ chown user_test $TESTFILE
|
|
 |
ff1465 |
+done
|
|
 |
ff1465 |
diff --git a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_permissions_library_dirs/ansible/shared.yml b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_permissions_library_dirs/ansible/shared.yml
|
|
 |
ff1465 |
deleted file mode 100644
|
|
 |
ff1465 |
index cf9eeba..0000000
|
|
 |
ff1465 |
--- a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_permissions_library_dirs/ansible/shared.yml
|
|
 |
ff1465 |
+++ /dev/null
|
|
 |
ff1465 |
@@ -1,18 +0,0 @@
|
|
 |
ff1465 |
-# platform = Red Hat Virtualization 4,multi_platform_fedora,multi_platform_rhel,multi_platform_ol,multi_platform_sle
|
|
 |
ff1465 |
-# reboot = false
|
|
 |
ff1465 |
-# strategy = restrict
|
|
 |
ff1465 |
-# complexity = high
|
|
 |
ff1465 |
-# disruption = medium
|
|
 |
ff1465 |
-- name: "Read list of world and group writable files in libraries directories"
|
|
 |
ff1465 |
- command: "find /lib /lib64 /usr/lib /usr/lib64 -perm /022 -type f"
|
|
 |
ff1465 |
- register: world_writable_library_files
|
|
 |
ff1465 |
- changed_when: False
|
|
 |
ff1465 |
- failed_when: False
|
|
 |
ff1465 |
- check_mode: no
|
|
 |
ff1465 |
-
|
|
 |
ff1465 |
-- name: "Disable world/group writability to library files"
|
|
 |
ff1465 |
- file:
|
|
 |
ff1465 |
- path: "{{ item }}"
|
|
 |
ff1465 |
- mode: "go-w"
|
|
 |
ff1465 |
- with_items: "{{ world_writable_library_files.stdout_lines }}"
|
|
 |
ff1465 |
- when: world_writable_library_files.stdout_lines | length > 0
|
|
 |
ff1465 |
diff --git a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_permissions_library_dirs/bash/shared.sh b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_permissions_library_dirs/bash/shared.sh
|
|
 |
ff1465 |
deleted file mode 100644
|
|
 |
ff1465 |
index af04ad6..0000000
|
|
 |
ff1465 |
--- a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_permissions_library_dirs/bash/shared.sh
|
|
 |
ff1465 |
+++ /dev/null
|
|
 |
ff1465 |
@@ -1,5 +0,0 @@
|
|
 |
ff1465 |
-# platform = multi_platform_all
|
|
 |
ff1465 |
-DIRS="/lib /lib64 /usr/lib /usr/lib64"
|
|
 |
ff1465 |
-for dirPath in $DIRS; do
|
|
 |
ff1465 |
- find "$dirPath" -perm /022 -type f -exec chmod go-w '{}' \;
|
|
 |
ff1465 |
-done
|
|
 |
ff1465 |
diff --git a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_permissions_library_dirs/oval/shared.xml b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_permissions_library_dirs/oval/shared.xml
|
|
 |
ff1465 |
deleted file mode 100644
|
|
 |
ff1465 |
index f25c522..0000000
|
|
 |
ff1465 |
--- a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_permissions_library_dirs/oval/shared.xml
|
|
 |
ff1465 |
+++ /dev/null
|
|
 |
ff1465 |
@@ -1,46 +0,0 @@
|
|
 |
ff1465 |
-<def-group>
|
|
 |
ff1465 |
- <definition class="compliance" id="file_permissions_library_dirs" version="1">
|
|
 |
ff1465 |
- {{{ oval_metadata("
|
|
 |
ff1465 |
- Checks that /lib, /lib64, /usr/lib, /usr/lib64, /lib/modules, and
|
|
 |
ff1465 |
- objects therein, are not group-writable or world-writable.
|
|
 |
ff1465 |
- ") }}}
|
|
 |
ff1465 |
- <criteria operator="AND">
|
|
 |
ff1465 |
- <criterion test_ref="test_perms_lib_dir" />
|
|
 |
ff1465 |
- <criterion test_ref="test_perms_lib_files" />
|
|
 |
ff1465 |
- </criteria>
|
|
 |
ff1465 |
- </definition>
|
|
 |
ff1465 |
-
|
|
 |
ff1465 |
- <unix:file_test check="all" check_existence="none_exist" comment="library directories go-w" id="test_perms_lib_dir" version="1">
|
|
 |
ff1465 |
- <unix:object object_ref="object_file_permissions_lib_dir" />
|
|
 |
ff1465 |
- </unix:file_test>
|
|
 |
ff1465 |
-
|
|
 |
ff1465 |
- <unix:file_test check="all" check_existence="none_exist" comment="library files go-w" id="test_perms_lib_files" version="1">
|
|
 |
ff1465 |
- <unix:object object_ref="object_file_permissions_lib_files" />
|
|
 |
ff1465 |
- </unix:file_test>
|
|
 |
ff1465 |
-
|
|
 |
ff1465 |
- <unix:file_object comment="library directories" id="object_file_permissions_lib_dir" version="1">
|
|
 |
ff1465 |
-
|
|
 |
ff1465 |
- <unix:path operation="pattern match">^\/lib(|64)|^\/usr\/lib(|64)</unix:path>
|
|
 |
ff1465 |
- <unix:filename xsi:nil="true" />
|
|
 |
ff1465 |
- <filter action="include">state_perms_nogroupwrite_noworldwrite</filter>
|
|
 |
ff1465 |
- <filter action="exclude">perms_state_symlink</filter>
|
|
 |
ff1465 |
- </unix:file_object>
|
|
 |
ff1465 |
-
|
|
 |
ff1465 |
- <unix:file_object comment="library files" id="object_file_permissions_lib_files" version="1">
|
|
 |
ff1465 |
-
|
|
 |
ff1465 |
- <unix:path operation="pattern match">^\/lib(|64)|^\/usr\/lib(|64)</unix:path>
|
|
 |
ff1465 |
- <unix:filename operation="pattern match">^.*$</unix:filename>
|
|
 |
ff1465 |
- <filter action="include">state_perms_nogroupwrite_noworldwrite</filter>
|
|
 |
ff1465 |
- <filter action="exclude">perms_state_symlink</filter>
|
|
 |
ff1465 |
- </unix:file_object>
|
|
 |
ff1465 |
-
|
|
 |
ff1465 |
- <unix:file_state id="state_perms_nogroupwrite_noworldwrite" version="1" operator="OR">
|
|
 |
ff1465 |
- <unix:gwrite datatype="boolean">true</unix:gwrite>
|
|
 |
ff1465 |
- <unix:owrite datatype="boolean">true</unix:owrite>
|
|
 |
ff1465 |
- </unix:file_state>
|
|
 |
ff1465 |
-
|
|
 |
ff1465 |
- <unix:file_state id="perms_state_symlink" version="1">
|
|
 |
ff1465 |
- <unix:type operation="equals">symbolic link</unix:type>
|
|
 |
ff1465 |
- </unix:file_state>
|
|
 |
ff1465 |
-
|
|
 |
ff1465 |
-</def-group>
|
|
 |
ff1465 |
diff --git a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_permissions_library_dirs/rule.yml b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_permissions_library_dirs/rule.yml
|
|
 |
ff1465 |
index 902d8b5..e9afb91 100644
|
|
 |
ff1465 |
--- a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_permissions_library_dirs/rule.yml
|
|
 |
ff1465 |
+++ b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_permissions_library_dirs/rule.yml
|
|
 |
ff1465 |
@@ -60,3 +60,14 @@ ocil: |-
|
|
 |
ff1465 |
To find shared libraries that are group-writable or world-writable,
|
|
 |
ff1465 |
run the following command for each directory DIR which contains shared libraries:
|
|
 |
ff1465 |
$ sudo find -L DIR -perm /022 -type f
|
|
 |
ff1465 |
+
|
|
 |
ff1465 |
+template:
|
|
 |
ff1465 |
+ name: file_permissions
|
|
 |
ff1465 |
+ vars:
|
|
 |
ff1465 |
+ filepath:
|
|
 |
ff1465 |
+ - /lib/
|
|
 |
ff1465 |
+ - /lib64/
|
|
 |
ff1465 |
+ - /usr/lib/
|
|
 |
ff1465 |
+ - /usr/lib64/
|
|
 |
ff1465 |
+ file_regex: ^.*$
|
|
 |
ff1465 |
+ filemode: '0755'
|
|
 |
ff1465 |
diff --git a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_permissions_library_dirs/tests/incorrect_permissions.fail.sh b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_permissions_library_dirs/tests/lenient_permissions.fail.sh
|
|
 |
ff1465 |
similarity index 100%
|
|
 |
ff1465 |
rename from linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_permissions_library_dirs/tests/incorrect_permissions.fail.sh
|
|
 |
ff1465 |
rename to linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_permissions_library_dirs/tests/lenient_permissions.fail.sh
|
|
 |
ff1465 |
diff --git a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/root_permissions_syslibrary_files/rule.yml b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/root_permissions_syslibrary_files/rule.yml
|
|
 |
ff1465 |
index 3b983de..3a1e5ba 100644
|
|
 |
ff1465 |
--- a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/root_permissions_syslibrary_files/rule.yml
|
|
 |
ff1465 |
+++ b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/root_permissions_syslibrary_files/rule.yml
|
|
 |
ff1465 |
@@ -4,7 +4,7 @@ prodtype: fedora,ol8,rhel8,rhel9,sle12,sle15,ubuntu2004
|
|
 |
ff1465 |
|
|
 |
ff1465 |
title: |-
|
|
 |
ff1465 |
Verify the system-wide library files in directories
|
|
 |
ff1465 |
- "/lib", "/lib64", "/usr/lib/" and "/usr/lib64" are owned by root.
|
|
 |
ff1465 |
+ "/lib", "/lib64", "/usr/lib/" and "/usr/lib64" are group-owned by root.
|
|
 |
ff1465 |
|
|
 |
ff1465 |
description: |-
|
|
 |
ff1465 |
System-wide library files are stored in the following directories
|
|
 |
ff1465 |
@@ -15,7 +15,7 @@ description: |-
|
|
 |
ff1465 |
/usr/lib64
|
|
 |
ff1465 |
|
|
 |
ff1465 |
All system-wide shared library files should be protected from unauthorised
|
|
 |
ff1465 |
- access. If any of these files is not owned by root, correct its owner with
|
|
 |
ff1465 |
+ access. If any of these files is not group-owned by root, correct its group-owner with
|
|
 |
ff1465 |
the following command:
|
|
 |
ff1465 |
$ sudo chgrp root FILE
|
|
 |
ff1465 |
|
|
 |
ff1465 |
@@ -46,7 +46,7 @@ references:
|
|
 |
ff1465 |
stigid@sle15: SLES-15-010355
|
|
 |
ff1465 |
stigid@ubuntu2004: UBTU-20-01430
|
|
 |
ff1465 |
|
|
 |
ff1465 |
-ocil_clause: 'system wide library files are not group owned by root'
|
|
 |
ff1465 |
+ocil_clause: 'system wide library files are not group-owned by root'
|
|
 |
ff1465 |
|
|
 |
ff1465 |
ocil: |-
|
|
 |
ff1465 |
System-wide library files are stored in the following directories:
|
|
 |
ff1465 |
diff --git a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/root_permissions_syslibrary_files/tests/correct_groupowner.pass.sh b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/root_permissions_syslibrary_files/tests/correct_groupowner.pass.sh
|
|
 |
ff1465 |
index a4ae285..5356d37 100644
|
|
 |
ff1465 |
--- a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/root_permissions_syslibrary_files/tests/correct_groupowner.pass.sh
|
|
 |
ff1465 |
+++ b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/root_permissions_syslibrary_files/tests/correct_groupowner.pass.sh
|
|
 |
ff1465 |
@@ -1,4 +1,4 @@
|
|
 |
ff1465 |
-# platform = multi_platform_sle,Red Hat Enterprise Linux 8,multi_platform_fedora
|
|
 |
ff1465 |
+# platform = multi_platform_sle,multi_platform_rhel,multi_platform_fedora,multi_platform_ubuntu
|
|
 |
ff1465 |
|
|
 |
ff1465 |
for SYSLIBDIRS in /lib /lib64 /usr/lib /usr/lib64
|
|
 |
ff1465 |
do
|
|
 |
ff1465 |
diff --git a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/root_permissions_syslibrary_files/tests/incorrect_groupowner.fail.sh b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/root_permissions_syslibrary_files/tests/incorrect_groupowner.fail.sh
|
|
 |
ff1465 |
index c96f65b..9636acf 100644
|
|
 |
ff1465 |
--- a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/root_permissions_syslibrary_files/tests/incorrect_groupowner.fail.sh
|
|
 |
ff1465 |
+++ b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/root_permissions_syslibrary_files/tests/incorrect_groupowner.fail.sh
|
|
 |
ff1465 |
@@ -1,4 +1,4 @@
|
|
 |
ff1465 |
-# platform = multi_platform_sle,Red Hat Enterprise Linux 8,multi_platform_fedora
|
|
 |
ff1465 |
+# platform = multi_platform_sle,multi_platform_rhel,multi_platform_fedora,multi_platform_ubuntu
|
|
 |
ff1465 |
|
|
 |
ff1465 |
for TESTFILE in /lib/test_me /lib64/test_me /usr/lib/test_me /usr/lib64/test_me
|
|
 |
ff1465 |
do
|
|
 |
ff1465 |
diff --git a/products/rhel8/profiles/stig.profile b/products/rhel8/profiles/stig.profile
|
|
 |
ff1465 |
index d6f0793..5b2cc0f 100644
|
|
 |
ff1465 |
--- a/products/rhel8/profiles/stig.profile
|
|
 |
ff1465 |
+++ b/products/rhel8/profiles/stig.profile
|
|
 |
ff1465 |
@@ -233,8 +233,13 @@ selections:
|
|
 |
ff1465 |
# RHEL-08-010340
|
|
 |
ff1465 |
- file_ownership_library_dirs
|
|
 |
ff1465 |
|
|
 |
ff1465 |
+ # RHEL-08-010341
|
|
 |
ff1465 |
+ - dir_ownership_library_dirs
|
|
 |
ff1465 |
+
|
|
 |
ff1465 |
# RHEL-08-010350
|
|
 |
ff1465 |
- root_permissions_syslibrary_files
|
|
 |
ff1465 |
+
|
|
 |
ff1465 |
+ # RHEL-08-010351
|
|
 |
ff1465 |
- dir_group_ownership_library_dirs
|
|
 |
ff1465 |
|
|
 |
ff1465 |
# RHEL-08-010359
|
|
 |
ff1465 |
diff --git a/shared/references/cce-redhat-avail.txt b/shared/references/cce-redhat-avail.txt
|
|
 |
ff1465 |
index d8daeb3..0584677 100644
|
|
 |
ff1465 |
--- a/shared/references/cce-redhat-avail.txt
|
|
 |
ff1465 |
+++ b/shared/references/cce-redhat-avail.txt
|
|
 |
ff1465 |
@@ -3074,8 +3074,6 @@ CCE-89017-8
|
|
 |
ff1465 |
CCE-89018-6
|
|
 |
ff1465 |
CCE-89019-4
|
|
 |
ff1465 |
CCE-89020-2
|
|
 |
ff1465 |
-CCE-89021-0
|
|
 |
ff1465 |
-CCE-89022-8
|
|
 |
ff1465 |
CCE-89023-6
|
|
 |
ff1465 |
CCE-89024-4
|
|
 |
ff1465 |
CCE-89025-1
|
|
 |
ff1465 |
diff --git a/shared/templates/file_groupowner/ansible.template b/shared/templates/file_groupowner/ansible.template
|
|
 |
ff1465 |
index 68fc2e1..0b4ab59 100644
|
|
 |
ff1465 |
--- a/shared/templates/file_groupowner/ansible.template
|
|
 |
ff1465 |
+++ b/shared/templates/file_groupowner/ansible.template
|
|
 |
ff1465 |
@@ -12,6 +12,7 @@
|
|
 |
ff1465 |
paths: "{{{ path }}}"
|
|
 |
ff1465 |
patterns: {{{ FILE_REGEX[loop.index0] }}}
|
|
 |
ff1465 |
use_regex: yes
|
|
 |
ff1465 |
+ hidden: yes
|
|
 |
ff1465 |
register: files_found
|
|
 |
ff1465 |
|
|
 |
ff1465 |
- name: Ensure group owner on {{{ path }}} file(s) matching {{{ FILE_REGEX[loop.index0] }}}
|
|
 |
ff1465 |
diff --git a/shared/templates/file_groupowner/oval.template b/shared/templates/file_groupowner/oval.template
|
|
 |
ff1465 |
index fd2e5db..64a4944 100644
|
|
 |
ff1465 |
--- a/shared/templates/file_groupowner/oval.template
|
|
 |
ff1465 |
+++ b/shared/templates/file_groupowner/oval.template
|
|
 |
ff1465 |
@@ -45,6 +45,10 @@
|
|
 |
ff1465 |
{{%- else %}}
|
|
 |
ff1465 |
<unix:filepath{{% if FILEPATH_IS_REGEX %}} operation="pattern match"{{% endif %}}>{{{ filepath }}}</unix:filepath>
|
|
 |
ff1465 |
{{%- endif %}}
|
|
 |
ff1465 |
+ <filter action="exclude">symlink_file_groupowner{{{ FILEID }}}_uid_{{{ FILEGID }}}</filter>
|
|
 |
ff1465 |
</unix:file_object>
|
|
 |
ff1465 |
{{% endfor %}}
|
|
 |
ff1465 |
+ <unix:file_state id="symlink_file_groupowner{{{ FILEID }}}_uid_{{{ FILEGID }}}" version="1">
|
|
 |
ff1465 |
+ <unix:type operation="equals">symbolic link</unix:type>
|
|
 |
ff1465 |
+ </unix:file_state>
|
|
 |
ff1465 |
</def-group>
|
|
 |
ff1465 |
diff --git a/shared/templates/file_owner/ansible.template b/shared/templates/file_owner/ansible.template
|
|
 |
ff1465 |
index 590c9fc..dba9e65 100644
|
|
 |
ff1465 |
--- a/shared/templates/file_owner/ansible.template
|
|
 |
ff1465 |
+++ b/shared/templates/file_owner/ansible.template
|
|
 |
ff1465 |
@@ -12,6 +12,7 @@
|
|
 |
ff1465 |
paths: "{{{ path }}}"
|
|
 |
ff1465 |
patterns: {{{ FILE_REGEX[loop.index0] }}}
|
|
 |
ff1465 |
use_regex: yes
|
|
 |
ff1465 |
+ hidden: yes
|
|
 |
ff1465 |
register: files_found
|
|
 |
ff1465 |
|
|
 |
ff1465 |
- name: Ensure group owner on {{{ path }}} file(s) matching {{{ FILE_REGEX[loop.index0] }}}
|
|
 |
ff1465 |
diff --git a/shared/templates/file_owner/oval.template b/shared/templates/file_owner/oval.template
|
|
 |
ff1465 |
index 105e29c..777831d 100644
|
|
 |
ff1465 |
--- a/shared/templates/file_owner/oval.template
|
|
 |
ff1465 |
+++ b/shared/templates/file_owner/oval.template
|
|
 |
ff1465 |
@@ -44,6 +44,10 @@
|
|
 |
ff1465 |
{{%- else %}}
|
|
 |
ff1465 |
<unix:filepath{{% if FILEPATH_IS_REGEX %}} operation="pattern match"{{% endif %}}>{{{ filepath }}}</unix:filepath>
|
|
 |
ff1465 |
{{%- endif %}}
|
|
 |
ff1465 |
+ <filter action="exclude">symlink_file_owner{{{ FILEID }}}_uid_{{{ FILEUID }}}</filter>
|
|
 |
ff1465 |
</unix:file_object>
|
|
 |
ff1465 |
{{% endfor %}}
|
|
 |
ff1465 |
+ <unix:file_state id="symlink_file_owner{{{ FILEID }}}_uid_{{{ FILEUID }}}" version="1">
|
|
 |
ff1465 |
+ <unix:type operation="equals">symbolic link</unix:type>
|
|
 |
ff1465 |
+ </unix:file_state>
|
|
 |
ff1465 |
</def-group>
|
|
 |
ff1465 |
diff --git a/shared/templates/file_permissions/ansible.template b/shared/templates/file_permissions/ansible.template
|
|
 |
ff1465 |
index fc211bd..6d4dedc 100644
|
|
 |
ff1465 |
--- a/shared/templates/file_permissions/ansible.template
|
|
 |
ff1465 |
+++ b/shared/templates/file_permissions/ansible.template
|
|
 |
ff1465 |
@@ -12,6 +12,7 @@
|
|
 |
ff1465 |
paths: "{{{ path }}}"
|
|
 |
ff1465 |
patterns: {{{ FILE_REGEX[loop.index0] }}}
|
|
 |
ff1465 |
use_regex: yes
|
|
 |
ff1465 |
+ hidden: yes
|
|
 |
ff1465 |
register: files_found
|
|
 |
ff1465 |
|
|
 |
ff1465 |
- name: Set permissions for {{{ path }}} file(s)
|
|
 |
ff1465 |
diff --git a/tests/data/profile_stability/rhel8/stig.profile b/tests/data/profile_stability/rhel8/stig.profile
|
|
 |
ff1465 |
index 1b4b955..c2522c9 100644
|
|
 |
ff1465 |
--- a/tests/data/profile_stability/rhel8/stig.profile
|
|
 |
ff1465 |
+++ b/tests/data/profile_stability/rhel8/stig.profile
|
|
 |
ff1465 |
@@ -175,6 +175,7 @@ selections:
|
|
 |
ff1465 |
- dconf_gnome_screensaver_idle_delay
|
|
 |
ff1465 |
- dconf_gnome_screensaver_lock_enabled
|
|
 |
ff1465 |
- dir_group_ownership_library_dirs
|
|
 |
ff1465 |
+- dir_ownership_library_dirs
|
|
 |
ff1465 |
- dir_permissions_library_dirs
|
|
 |
ff1465 |
- dir_perms_world_writable_root_owned
|
|
 |
ff1465 |
- dir_perms_world_writable_sticky_bits
|
|
 |
ff1465 |
diff --git a/tests/data/profile_stability/rhel8/stig_gui.profile b/tests/data/profile_stability/rhel8/stig_gui.profile
|
|
 |
ff1465 |
index 3568e07..95d87fd 100644
|
|
 |
ff1465 |
--- a/tests/data/profile_stability/rhel8/stig_gui.profile
|
|
 |
ff1465 |
+++ b/tests/data/profile_stability/rhel8/stig_gui.profile
|
|
 |
ff1465 |
@@ -186,6 +186,7 @@ selections:
|
|
 |
ff1465 |
- dconf_gnome_screensaver_idle_delay
|
|
 |
ff1465 |
- dconf_gnome_screensaver_lock_enabled
|
|
 |
ff1465 |
- dir_group_ownership_library_dirs
|
|
 |
ff1465 |
+- dir_ownership_library_dirs
|
|
 |
ff1465 |
- dir_permissions_library_dirs
|
|
 |
ff1465 |
- dir_perms_world_writable_root_owned
|
|
 |
ff1465 |
- dir_perms_world_writable_sticky_bits
|