RHEL 7 Vendor STIG Content Peculiarities - Mount-opts for /tmp
Got word from our organization's authorization office: given that the DISA STIG looks to be far longer in coming than they'd hoped (see prior discussion), they're now willing for us to move forward with the vendor STIG. So, started the process of aligning our build to that STIG.
Naturally, using anything other than the "common" profile, our scan results are not 100%. Yes - even after running
oscap--remediate/tmp//tmpnoexecnosuidnodev/etc/fstabnoauto/usr/lib/systemd/system/tmp.mountOptions[Mount]... [Mount] What=tmpfs Where=/tmp Type=tmpfs Options=mode=1777,strictatime ...
Unfortunately, the
/usr/lib/systemd/system/tmp.mountoscap/etc/fstab/tmpWere the systemd RPM to have declared the
/usr/lib/systemd/system/tmp.mountWhat's Red Hat's recommendation around properly handling mount-options in this scenario?
Responses