Please push. Thanks for the testing! Expect a patch from me shortly (long overdue) to show the completed tests in a table.
On 08/12/2013 03:54 PM, Maura Dailey wrote: > > Signed-off-by: Maura Dailey <[email protected]> > --- > .../checks/accounts_disable_post_pw_expiration.xml | 1 + > .../checks/accounts_maximum_age_login_defs.xml | 1 + > .../checks/accounts_minimum_age_login_defs.xml | 3 ++- > RHEL6/input/checks/accounts_no_uid_except_zero.xml | 1 + > RHEL6/input/checks/accounts_umask_bashrc.xml | 1 + > RHEL6/input/checks/accounts_umask_cshrc.xml | 1 + > RHEL6/input/checks/accounts_umask_etc_profile.xml | 1 + > RHEL6/input/checks/accounts_umask_login_defs.xml | 1 + > RHEL6/input/checks/core_dumps_limitsconf.xml | 4 ++-- > .../checks/ensure_gpgcheck_never_disabled.xml | 9 ++++----- > RHEL6/input/checks/file_owner_etc_group.xml | 1 + > RHEL6/input/checks/file_owner_etc_gshadow.xml | 1 + > RHEL6/input/checks/file_owner_etc_passwd.xml | 1 + > RHEL6/input/checks/file_owner_etc_shadow.xml | 1 + > RHEL6/input/checks/no_netrc_files.xml | 1 + > RHEL6/input/checks/no_rsh_trust_files.xml | 3 ++- > .../checks/yum_gpgcheck_global_activation.xml | 7 ++++--- > 17 files changed, 26 insertions(+), 12 deletions(-) > > diff --git a/RHEL6/input/checks/accounts_disable_post_pw_expiration.xml > b/RHEL6/input/checks/accounts_disable_post_pw_expiration.xml > index 429e9db..16e95e1 100644 > --- a/RHEL6/input/checks/accounts_disable_post_pw_expiration.xml > +++ b/RHEL6/input/checks/accounts_disable_post_pw_expiration.xml > @@ -6,6 +6,7 @@ > <platform>Red Hat Enterprise Linux 6</platform> > </affected> > <description>The accounts should be configured to expire automatically > following password expiration.</description> > + <reference source="MED" ref_id="20130807" ref_url="test_attestation" /> > </metadata> > <criteria comment="the value INACTIVE parameter should be set > appropriately in /etc/default/useradd"> > <criterion test_ref="test_etc_default_useradd_inactive" /> > diff --git a/RHEL6/input/checks/accounts_maximum_age_login_defs.xml > b/RHEL6/input/checks/accounts_maximum_age_login_defs.xml > index 090435a..8b989c5 100644 > --- a/RHEL6/input/checks/accounts_maximum_age_login_defs.xml > +++ b/RHEL6/input/checks/accounts_maximum_age_login_defs.xml > @@ -7,6 +7,7 @@ > </affected> > <description>The maximum password age policy should meet > minimum requirements.</description> > + <reference source="MED" ref_id="20130807" ref_url="test_attestation" /> > </metadata> > <criteria comment="the value PASS_MAX_DAYS should be set appropriately > in /etc/login.defs"> > <criterion test_ref="test_pass_max_days" /> > diff --git a/RHEL6/input/checks/accounts_minimum_age_login_defs.xml > b/RHEL6/input/checks/accounts_minimum_age_login_defs.xml > index 6de9779..423cd60 100644 > --- a/RHEL6/input/checks/accounts_minimum_age_login_defs.xml > +++ b/RHEL6/input/checks/accounts_minimum_age_login_defs.xml > @@ -6,6 +6,7 @@ > <platform>Red Hat Enterprise Linux 6</platform> > </affected> > <description>The minimum password age policy should be set > appropriately.</description> > + <reference source="MED" ref_id="20130807" ref_url="test_attestation" /> > </metadata> > <criteria comment="the value PASS_MIN_DAYS should be set appropriately > in /etc/login.defs"> > <criterion test_ref="test_pass_min_days" /> > @@ -13,7 +14,7 @@ > </definition> > > <ind:textfilecontent54_test check="all" > - comment="Tests the value of PASS_MIN_DAYS in /etc/login.defs" > + comment="Tests the value of PASS_MIN_DAYS in /etc/login.defs" > id="test_pass_min_days" version="1"> > <ind:object object_ref="object_etc_login_defs_pass_min_age" /> > <ind:state state_ref="state_etc_login_defs_pass_min_age" /> > diff --git a/RHEL6/input/checks/accounts_no_uid_except_zero.xml > b/RHEL6/input/checks/accounts_no_uid_except_zero.xml > index 5ef2452..bcd4d07 100644 > --- a/RHEL6/input/checks/accounts_no_uid_except_zero.xml > +++ b/RHEL6/input/checks/accounts_no_uid_except_zero.xml > @@ -6,6 +6,7 @@ > <platform>Red Hat Enterprise Linux 6</platform> > </affected> > <description>Only the root account should be assigned a user id of > 0.</description> > + <reference source="MED" ref_id="20130807" ref_url="test_attestation" /> > </metadata> > <criteria> > <criterion comment="tests for reg exp ^[^r][^o][^o][^t].*:0 in > /etc/passwd file" test_ref="test_accounts_no_uid_except_root" /> > diff --git a/RHEL6/input/checks/accounts_umask_bashrc.xml > b/RHEL6/input/checks/accounts_umask_bashrc.xml > index 3857f4c..32c98d1 100644 > --- a/RHEL6/input/checks/accounts_umask_bashrc.xml > +++ b/RHEL6/input/checks/accounts_umask_bashrc.xml > @@ -6,6 +6,7 @@ > <platform>Red Hat Enterprise Linux 6</platform> > </affected> > <description>The default umask for users of the bash > shell</description> > + <reference source="MED" ref_id="20130812" ref_url="test_attestation" /> > </metadata> > <criteria> > <criterion test_ref="test_accounts_umask_bashrc" /> > diff --git a/RHEL6/input/checks/accounts_umask_cshrc.xml > b/RHEL6/input/checks/accounts_umask_cshrc.xml > index bdafcb2..86921e1 100644 > --- a/RHEL6/input/checks/accounts_umask_cshrc.xml > +++ b/RHEL6/input/checks/accounts_umask_cshrc.xml > @@ -7,6 +7,7 @@ > <platform>Red Hat Enterprise Linux 6</platform> > </affected> > <description>The default umask for users of the csh shell</description> > + <reference source="MED" ref_id="20130812" ref_url="test_attestation" /> > </metadata> > <criteria> > <criterion test_ref="test_accounts_umask_cshrc" /> > diff --git a/RHEL6/input/checks/accounts_umask_etc_profile.xml > b/RHEL6/input/checks/accounts_umask_etc_profile.xml > index 4125baa..c7e753e 100644 > --- a/RHEL6/input/checks/accounts_umask_etc_profile.xml > +++ b/RHEL6/input/checks/accounts_umask_etc_profile.xml > @@ -9,6 +9,7 @@ > </affected> > <description>The default umask for all users should be set > correctly</description> > + <reference source="MED" ref_id="20130807" ref_url="test_attestation" /> > </metadata> > <criteria> > <criterion test_ref="test_accounts_umask_etc_profile" /> > diff --git a/RHEL6/input/checks/accounts_umask_login_defs.xml > b/RHEL6/input/checks/accounts_umask_login_defs.xml > index 8e19cbf..28f707e 100644 > --- a/RHEL6/input/checks/accounts_umask_login_defs.xml > +++ b/RHEL6/input/checks/accounts_umask_login_defs.xml > @@ -8,6 +8,7 @@ > <platform>Red Hat Enterprise Linux 6</platform> > </affected> > <description>The default umask for all users specified in > /etc/login.defs</description> > + <reference source="MED" ref_id="20130807" ref_url="test_attestation" /> > </metadata> > <criteria> > <criterion test_ref="test_accounts_umask_login_defs" /> > diff --git a/RHEL6/input/checks/core_dumps_limitsconf.xml > b/RHEL6/input/checks/core_dumps_limitsconf.xml > index 4107aae..6732cdb 100644 > --- a/RHEL6/input/checks/core_dumps_limitsconf.xml > +++ b/RHEL6/input/checks/core_dumps_limitsconf.xml > @@ -6,6 +6,7 @@ > <platform>Red Hat Enterprise Linux 6</platform> > </affected> > <description>Core dumps for all users should be disabled</description> > + <reference source="MED" ref_id="20130807" ref_url="test_attestation" /> > </metadata> > <criteria> > <criterion comment="Are core dumps disabled" > @@ -24,8 +25,7 @@ > <ind:textfilecontent54_object id="object_core_dumps_limitsconf" > version="1"> > <ind:path>/etc/security</ind:path> > <ind:filename>limits.conf</ind:filename> > - <ind:pattern operation="pattern match"> > - ^[\s]*\*[\s]+hard[\s]+core[\s]+([\d]+)</ind:pattern> > + <ind:pattern operation="pattern > match">^[\s]*\*[\s]+hard[\s]+core[\s]+([\d]+)</ind:pattern> > <ind:instance datatype="int">1</ind:instance> > </ind:textfilecontent54_object> > </def-group> > diff --git a/RHEL6/input/checks/ensure_gpgcheck_never_disabled.xml > b/RHEL6/input/checks/ensure_gpgcheck_never_disabled.xml > index a155cb9..c9ee687 100644 > --- a/RHEL6/input/checks/ensure_gpgcheck_never_disabled.xml > +++ b/RHEL6/input/checks/ensure_gpgcheck_never_disabled.xml > @@ -1,21 +1,20 @@ > <def-group> > - <definition class="compliance" > - id="ensure_gpgcheck_never_disabled" version="1"> > + <definition class="compliance" id="ensure_gpgcheck_never_disabled" > + version="1"> > <metadata> > <title>Ensure gpgcheck Enabled For All Yum Package Repositories</title> > <affected family="unix"> > <platform>Red Hat Enterprise Linux 6</platform> > </affected> > <description>Ensure all yum repositories utilize signature > checking.</description> > + <reference source="MED" ref_id="20130807" ref_url="test_attestation" /> > </metadata> > <criteria comment="ensure all yum repositories utilize signiature > checking" operator="AND"> > <criterion comment="verify no gpgpcheck=0 present in /etc/yum.repos.d > files" > test_ref="test_ensure_gpgcheck_never_disabled" /> > </criteria> > </definition> > - > - <ind:textfilecontent54_test check="all" > - check_existence="none_exist" > + <ind:textfilecontent54_test check="all" check_existence="none_exist" > comment="check for existence of gpgcheck=0 in /etc/yum.repos.d/ files" > id="test_ensure_gpgcheck_never_disabled" version="1"> > <ind:object object_ref="obj_ensure_gpgcheck_never_disabled" /> > diff --git a/RHEL6/input/checks/file_owner_etc_group.xml > b/RHEL6/input/checks/file_owner_etc_group.xml > index a74ef27..e6bc24c 100644 > --- a/RHEL6/input/checks/file_owner_etc_group.xml > +++ b/RHEL6/input/checks/file_owner_etc_group.xml > @@ -7,6 +7,7 @@ > </affected> > <description>The /etc/group file should be owned by the appropriate > user.</description> > + <reference source="MED" ref_id="20130807" ref_url="test_attestation" /> > </metadata> > <criteria> > <criterion test_ref="test_file_owner_etc_group" /> > diff --git a/RHEL6/input/checks/file_owner_etc_gshadow.xml > b/RHEL6/input/checks/file_owner_etc_gshadow.xml > index a33952e..5a41bc5 100644 > --- a/RHEL6/input/checks/file_owner_etc_gshadow.xml > +++ b/RHEL6/input/checks/file_owner_etc_gshadow.xml > @@ -7,6 +7,7 @@ > </affected> > <description>The /etc/gshadow file should be owned by the appropriate > user.</description> > + <reference source="MED" ref_id="20130807" ref_url="test_attestation" /> > </metadata> > <criteria> > <criterion test_ref="test_file_owner_etc_gshadow" /> > diff --git a/RHEL6/input/checks/file_owner_etc_passwd.xml > b/RHEL6/input/checks/file_owner_etc_passwd.xml > index 5fb621d..44d3e18 100644 > --- a/RHEL6/input/checks/file_owner_etc_passwd.xml > +++ b/RHEL6/input/checks/file_owner_etc_passwd.xml > @@ -7,6 +7,7 @@ > </affected> > <description>The /etc/passwd file should be owned by the appropriate > user.</description> > + <reference source="MED" ref_id="20130807" ref_url="test_attestation" /> > </metadata> > <criteria> > <criterion test_ref="test_file_owner_etc_passwd" /> > diff --git a/RHEL6/input/checks/file_owner_etc_shadow.xml > b/RHEL6/input/checks/file_owner_etc_shadow.xml > index 9c15af2..dc108c1 100644 > --- a/RHEL6/input/checks/file_owner_etc_shadow.xml > +++ b/RHEL6/input/checks/file_owner_etc_shadow.xml > @@ -8,6 +8,7 @@ > </affected> > <description>The /etc/shadow file should be owned by the > appropriate user.</description> > + <reference source="MED" ref_id="20130807" ref_url="test_attestation" /> > </metadata> > <criteria> > <criterion comment="Check file ownership of /etc/shadow" > diff --git a/RHEL6/input/checks/no_netrc_files.xml > b/RHEL6/input/checks/no_netrc_files.xml > index c69c8e6..205191f 100644 > --- a/RHEL6/input/checks/no_netrc_files.xml > +++ b/RHEL6/input/checks/no_netrc_files.xml > @@ -6,6 +6,7 @@ > <platform>Red Hat Enterprise Linux 6</platform> > </affected> > <description>The .netrc files contain login information used to > auto-login into FTP servers and reside in the user's home directory. Any > .netrc files should be removed.</description> > + <reference source="MED" ref_id="20130807" ref_url="test_attestation" /> > </metadata> > <criteria> > <criterion test_ref="test_no_netrc_files_home" negate="true" /> > diff --git a/RHEL6/input/checks/no_rsh_trust_files.xml > b/RHEL6/input/checks/no_rsh_trust_files.xml > index 22c1c82..8b62ae3 100644 > --- a/RHEL6/input/checks/no_rsh_trust_files.xml > +++ b/RHEL6/input/checks/no_rsh_trust_files.xml > @@ -6,6 +6,7 @@ > <platform>Red Hat Enterprise Linux 6</platform> > </affected> > <description>There should not be any .rhosts or hosts.equiv files on > the system.</description> > + <reference source="MED" ref_id="20130807" ref_url="test_attestation" /> > </metadata> > <criteria operator="AND"> > <criterion test_ref="test_no_rsh_trust_files_root" negate="true" /> > @@ -33,6 +34,6 @@ > </unix:file_object> > <unix:file_object comment="look for /etc/hosts.equiv or /etc/shosts.equiv" > id="object_no_rsh_trust_files_etc" version="1"> > <unix:path operation="equals">/etc</unix:path> > - <unix:filename operation="pattern match">^s?hosts.equiv$</unix:filename> > + <unix:filename operation="pattern match">^s?hosts\.equiv$</unix:filename> > </unix:file_object> > </def-group> > diff --git a/RHEL6/input/checks/yum_gpgcheck_global_activation.xml > b/RHEL6/input/checks/yum_gpgcheck_global_activation.xml > index 55c600c..6482dce 100644 > --- a/RHEL6/input/checks/yum_gpgcheck_global_activation.xml > +++ b/RHEL6/input/checks/yum_gpgcheck_global_activation.xml > @@ -5,9 +5,10 @@ > <affected family="unix"> > <platform>Red Hat Enterprise Linux 6</platform> > </affected> > - <description>The gpgcheck option should be used to ensure > - that checking of an RPM package's signature always occurs > - prior to its installation.</description> > + <description>The gpgcheck option should be used to ensure that checking > + of an RPM package's signature always occurs prior to its > + installation.</description> > + <reference source="MED" ref_id="20130807" ref_url="test_attestation" /> > </metadata> > <criteria> > <criterion comment="check value of gpgcheck in /etc/yum.conf" > test_ref="test_yum_gpgcheck_global_activation" /> > -- ___________________________ Jeffrey Blank 410-854-8675 Technology and Systems Analysis / Network Components NSA Information Assurance _______________________________________________ scap-security-guide mailing list [email protected] https://lists.fedorahosted.org/mailman/listinfo/scap-security-guide
