From 7843a356be24c8b5c3cb148658d0420988dc3f9c Mon Sep 17 00:00:00 2001 From: Gabriel Becker Date: Thu, 8 Oct 2020 11:02:55 +0200 Subject: [PATCH] Remove platform net-snmp from the group and use it in individual rules. --- linux_os/guide/services/snmp/snmp_configure_server/group.yml | 1 - .../snmp/snmp_configure_server/snmpd_no_rwusers/rule.yml | 2 ++ .../snmp_configure_server/snmpd_not_default_password/rule.yml | 2 ++ .../snmp_configure_server/snmpd_use_newer_protocol/rule.yml | 2 ++ 4 files changed, 6 insertions(+), 1 deletion(-) diff --git a/linux_os/guide/services/snmp/snmp_configure_server/group.yml b/linux_os/guide/services/snmp/snmp_configure_server/group.yml index 8052ade2f6..c5a3fd75a1 100644 --- a/linux_os/guide/services/snmp/snmp_configure_server/group.yml +++ b/linux_os/guide/services/snmp/snmp_configure_server/group.yml @@ -18,4 +18,3 @@ description: |-
  • ensure that permissions on the snmpd.conf configuration file (by default, in /etc/snmp) are 640 or more restrictive
  • ensure that any MIB files' permissions are also 640 or more restrictive
  • -platform: net-snmp diff --git a/linux_os/guide/services/snmp/snmp_configure_server/snmpd_no_rwusers/rule.yml b/linux_os/guide/services/snmp/snmp_configure_server/snmpd_no_rwusers/rule.yml index 6bf32ef62e..e50eaa9f4e 100644 --- a/linux_os/guide/services/snmp/snmp_configure_server/snmpd_no_rwusers/rule.yml +++ b/linux_os/guide/services/snmp/snmp_configure_server/snmpd_no_rwusers/rule.yml @@ -27,3 +27,5 @@ ocil: |- To ensure there are no read-write users, run the following command:
    $ sudo grep -v "^#" /etc/snmp/snmpd.conf| grep 'rwuser'
    There should be no output. + +platform: net-snmp diff --git a/linux_os/guide/services/snmp/snmp_configure_server/snmpd_not_default_password/rule.yml b/linux_os/guide/services/snmp/snmp_configure_server/snmpd_not_default_password/rule.yml index 72d2495713..43c6c38b70 100644 --- a/linux_os/guide/services/snmp/snmp_configure_server/snmpd_not_default_password/rule.yml +++ b/linux_os/guide/services/snmp/snmp_configure_server/snmpd_not_default_password/rule.yml @@ -45,3 +45,5 @@ ocil: |- To ensure the default password is not set, run the following command:
    $ sudo grep -v "^#" /etc/snmp/snmpd.conf| grep -E 'public|private'
    There should be no output. + +platform: net-snmp diff --git a/linux_os/guide/services/snmp/snmp_configure_server/snmpd_use_newer_protocol/rule.yml b/linux_os/guide/services/snmp/snmp_configure_server/snmpd_use_newer_protocol/rule.yml index d10939d2e9..e128d64390 100644 --- a/linux_os/guide/services/snmp/snmp_configure_server/snmpd_use_newer_protocol/rule.yml +++ b/linux_os/guide/services/snmp/snmp_configure_server/snmpd_use_newer_protocol/rule.yml @@ -30,3 +30,5 @@ ocil: |- To ensure only SNMPv3 or newer is used, run the following command:
    $ sudo grep 'rocommunity\|rwcommunity\|com2sec' /etc/snmp/snmpd.conf | grep -v "^#"
    There should be no output. + +platform: net-snmp