Blame SOURCES/scap-security-guide-0.1.50-fix_rule_rsyslog_nolisten_regex_PR_5557.patch

dac76a
From 0a22bbbaeabd9c13254ef251479e9d74143620e6 Mon Sep 17 00:00:00 2001
dac76a
From: Ilya Okomin <ilya.okomin@oracle.com>
dac76a
Date: Mon, 23 Mar 2020 20:07:47 -0400
dac76a
Subject: [PATCH] Fix rsyslog_nolisten regex to match rule description
dac76a
dac76a
Signed-off-by: Ilya Okomin <ilya.okomin@oracle.com>
dac76a
---
dac76a
 .../rsyslog_nolisten/oval/shared.xml                          | 4 ++--
dac76a
 1 file changed, 2 insertions(+), 2 deletions(-)
dac76a
dac76a
diff --git a/linux_os/guide/system/logging/rsyslog_accepting_remote_messages/rsyslog_nolisten/oval/shared.xml b/linux_os/guide/system/logging/rsyslog_accepting_remote_messages/rsyslog_nolisten/oval/shared.xml
dac76a
index e38dee5bbc..b56281e283 100644
dac76a
--- a/linux_os/guide/system/logging/rsyslog_accepting_remote_messages/rsyslog_nolisten/oval/shared.xml
dac76a
+++ b/linux_os/guide/system/logging/rsyslog_accepting_remote_messages/rsyslog_nolisten/oval/shared.xml
dac76a
@@ -16,13 +16,13 @@
dac76a
     </criteria>
dac76a
   </definition>
dac76a
   
dac76a
-  comment="Ensure that the /etc/rsyslog.conf does not contain $InputTCPServerRun | $UDPServerRun | $InputRELPServerRun"
dac76a
+  comment="Ensure that the /etc/rsyslog.conf does not contain $InputTCPServerRun | $UDPServerRun | $InputRELPServerRun | $ModLoad imtcp | $ModLoad imudp | $ModLoad imrelp"
dac76a
   id="test_rsyslog_nolisten" version="1">
dac76a
     <ind:object object_ref="object_rsyslog_nolisten" />
dac76a
   </ind:textfilecontent54_test>
dac76a
   <ind:textfilecontent54_object id="object_rsyslog_nolisten" version="2">
dac76a
     <ind:filepath>/etc/rsyslog.conf</ind:filepath>
dac76a
-    <ind:pattern operation="pattern match">^[\s]*\$(?:Input(?:TCP|RELP)|UDP)ServerRun</ind:pattern>
dac76a
+    <ind:pattern operation="pattern match">^[\s]*\$((?:Input(?:TCP|RELP)|UDP)ServerRun|ModLoad[\s]+(imtcp|imudp|imrelp))</ind:pattern>
dac76a
     <ind:instance datatype="int">1</ind:instance>
dac76a
   </ind:textfilecontent54_object>
dac76a
 </def-group>