Blame SOURCES/scap-security-guide-0.1.49-add-rsyslog-to-stig.patch

54c0d5
From 716cccfe5a253be61e2b2f46b972ae2153a09ad2 Mon Sep 17 00:00:00 2001
54c0d5
From: Watson Sato <wsato@redhat.com>
54c0d5
Date: Tue, 4 Feb 2020 17:38:45 +0100
54c0d5
Subject: [PATCH] Add rules to configure rsyslog TLS
54c0d5
54c0d5
---
54c0d5
 rhel8/profiles/stig.profile | 6 ++++++
54c0d5
 1 file changed, 6 insertions(+)
54c0d5
54c0d5
diff --git a/rhel8/profiles/stig.profile b/rhel8/profiles/stig.profile
54c0d5
index d85e18e9d0..821cc26914 100644
54c0d5
--- a/rhel8/profiles/stig.profile
54c0d5
+++ b/rhel8/profiles/stig.profile
54c0d5
@@ -33,3 +33,9 @@ selections:
54c0d5
     - encrypt_partitions
54c0d5
     - sysctl_net_ipv4_tcp_syncookies
54c0d5
     - clean_components_post_updating
54c0d5
+
54c0d5
+    # Configure TLS for remote logging
54c0d5
+    - package_rsyslog_installed
54c0d5
+    - package_rsyslog-gnutls_installed
54c0d5
+    - rsyslog_remote_tls
54c0d5
+    - rsyslog_remote_tls_cacert