The OCP4 STIG profile is missing existing rules
Issue
- The STIG profile is missing rules from ComplianceAsCode/content that fulfils requirements on the published STIG for OCP4.
List of rules missing in the profile:
- ocp4-oauth-or-oauthclient-token-maxage
- rhcos4-audit-delete-failed
- rhcos4-audit-immutable-login-uids
- rhcos4-audit-rules-privileged-commands-pt-chown
- rhcos4-audit-rules-privileged-commands-write
- rhcos4-audit-rules-unsuccessful-file-modification-rename
- rhcos4-audit-rules-unsuccessful-file-modification-renameat
- rhcos4-audit-rules-unsuccessful-file-modification-unlink
- rhcos4-audit-rules-unsuccessful-file-modification-unlinkat
- rhcos4-configure-usbguard-auditbackend
- rhcos4-coreos-audit-backlog-limit-kernel-argument
- rhcos4-kernel-module-usb-storage
- rhcos4-kernel-module-usb-storage-disabled
- rhcos4-package-usbguard-installed
- rhcos4-service-sshd-disabled
- rhcos4-service-usbguard-enabled
- rhcos4-usbguard-allow-hid-and-hub
Environment
- Red Hat OpenShift Container Platform 4.x
- Compliance Operator 1.3.x
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.