Blame SOURCES/scap-security-guide-0.1.50-add_service_rsyncd_disabled_PR_5318.patch

dac76a
From f2024fe66e871a4f7dc54454065f59f4b2bf31db Mon Sep 17 00:00:00 2001
dac76a
From: Vojtech Polasek <vpolasek@redhat.com>
dac76a
Date: Thu, 19 Mar 2020 16:48:52 +0100
dac76a
Subject: [PATCH] add rule
dac76a
dac76a
---
dac76a
 .../obsolete/service_rsyncd_disabled/rule.yml | 33 +++++++++++++++++++
dac76a
 shared/references/cce-redhat-avail.txt        |  2 --
dac76a
 2 files changed, 33 insertions(+), 2 deletions(-)
dac76a
 create mode 100644 linux_os/guide/services/obsolete/service_rsyncd_disabled/rule.yml
dac76a
dac76a
diff --git a/linux_os/guide/services/obsolete/service_rsyncd_disabled/rule.yml b/linux_os/guide/services/obsolete/service_rsyncd_disabled/rule.yml
dac76a
new file mode 100644
dac76a
index 0000000000..9cb9d15dcc
dac76a
--- /dev/null
dac76a
+++ b/linux_os/guide/services/obsolete/service_rsyncd_disabled/rule.yml
dac76a
@@ -0,0 +1,33 @@
dac76a
+documentation_complete: true
dac76a
+
dac76a
+prodtype: rhel7,ol7,rhel8,ol8,fedora,rhv4,ocp4
dac76a
+
dac76a
+title: 'Ensure rsyncd service is diabled'
dac76a
+
dac76a
+description: |-
dac76a
+    {{{ describe_service_disable("rsyncd") }}}
dac76a
+
dac76a
+rationale: |-
dac76a
+    The rsyncd service presents a security risk as it uses unencrypted protocols for
dac76a
+    communication.
dac76a
+
dac76a
+severity: medium
dac76a
+
dac76a
+identifiers:
dac76a
+    cce@rhel7: 83334-3
dac76a
+    cce@rhel8: 83335-0
dac76a
+
dac76a
+references:
dac76a
+    cis@rhel7: 2.2.21
dac76a
+    cis@rhel8: 2.2.3
dac76a
+
dac76a
+ocil_clause: 'the service is not disabled'
dac76a
+
dac76a
+ocil: |-
dac76a
+    {{{ ocil_service_disabled("rsyncd") }}}
dac76a
+
dac76a
+template:
dac76a
+    name: service_disabled
dac76a
+    vars:
dac76a
+        servicename: rsyncd
dac76a
+        packagename: rsync
dac76a
diff --git a/shared/references/cce-redhat-avail.txt b/shared/references/cce-redhat-avail.txt
dac76a
index a0b117a964..67fa853d75 100644
dac76a
--- a/shared/references/cce-redhat-avail.txt
dac76a
+++ b/shared/references/cce-redhat-avail.txt
dac76a
@@ -45,8 +45,6 @@ CCE-83330-1
dac76a
 CCE-83331-9
dac76a
 CCE-83332-7
dac76a
 CCE-83333-5
dac76a
-CCE-83334-3
dac76a
-CCE-83335-0
dac76a
 CCE-83336-8
dac76a
 CCE-83337-6
dac76a
 CCE-83338-4