|
|
76240a |
diff --git a/linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_overflow_action/ansible/shared.yml b/linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_overflow_action/ansible/shared.yml
|
|
|
76240a |
new file mode 100644
|
|
|
76240a |
index 0000000000..4f88ed361d
|
|
|
76240a |
--- /dev/null
|
|
|
76240a |
+++ b/linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_overflow_action/ansible/shared.yml
|
|
|
76240a |
@@ -0,0 +1,8 @@
|
|
|
76240a |
+# platform = multi_platform_fedora,multi_platform_rhel
|
|
|
76240a |
+
|
|
|
76240a |
+{{{ ansible_set_config_file(file="/etc/audit/auditd.conf",
|
|
|
76240a |
+ parameter="overflow_action",
|
|
|
76240a |
+ value="syslog",
|
|
|
76240a |
+ separator="=",
|
|
|
76240a |
+ separator_regex="=",
|
|
|
76240a |
+ prefix_regex="^\s*") }}}
|
|
|
76240a |
diff --git a/linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_overflow_action/bash/shared.sh b/linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_overflow_action/bash/shared.sh
|
|
|
76240a |
new file mode 100644
|
|
|
76240a |
index 0000000000..539b9b6582
|
|
|
76240a |
--- /dev/null
|
|
|
76240a |
+++ b/linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_overflow_action/bash/shared.sh
|
|
|
76240a |
@@ -0,0 +1,12 @@
|
|
|
76240a |
+# platform = multi_platform_fedora,multi_platform_rhel
|
|
|
76240a |
+# reboot = true
|
|
|
76240a |
+# strategy = restrict
|
|
|
76240a |
+# complexity = low
|
|
|
76240a |
+# disruption = low
|
|
|
76240a |
+
|
|
|
76240a |
+{{{set_config_file(path="/etc/audit/auditd.conf",
|
|
|
76240a |
+ parameter="overflow_action",
|
|
|
76240a |
+ value="syslog",
|
|
|
76240a |
+ separator="=",
|
|
|
76240a |
+ separator_regex="=",
|
|
|
76240a |
+ prefix_regex="^\s*")}}}
|
|
|
76240a |
diff --git a/linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_overflow_action/oval/shared.xml b/linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_overflow_action/oval/shared.xml
|
|
|
76240a |
new file mode 100644
|
|
|
76240a |
index 0000000000..fd45280e4e
|
|
|
76240a |
--- /dev/null
|
|
|
76240a |
+++ b/linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_overflow_action/oval/shared.xml
|
|
|
76240a |
@@ -0,0 +1,6 @@
|
|
|
76240a |
+{{{ oval_check_config_file(
|
|
|
76240a |
+ path="/etc/audit/auditd.conf",
|
|
|
76240a |
+ prefix_regex="^(?:.*\\n)*\s*",
|
|
|
76240a |
+ parameter="overflow_action",
|
|
|
76240a |
+ value="syslog|single|halt",
|
|
|
76240a |
+ separator_regex="\s*=\s*") }}}
|
|
|
76240a |
diff --git a/linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_overflow_action/rule.yml b/linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_overflow_action/rule.yml
|
|
|
76240a |
new file mode 100644
|
|
|
76240a |
index 0000000000..d41ca00076
|
|
|
76240a |
--- /dev/null
|
|
|
76240a |
+++ b/linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_overflow_action/rule.yml
|
|
|
76240a |
@@ -0,0 +1,36 @@
|
|
|
76240a |
+documentation_complete: true
|
|
|
76240a |
+
|
|
|
76240a |
+title: Appropriate Action Must be Setup When the Internal Audit Event Queue is Full
|
|
|
76240a |
+
|
|
|
76240a |
+description: |-
|
|
|
76240a |
+ The audit system should have an action setup in the event the internal event queue becomes full.
|
|
|
76240a |
+ To setup an overflow action edit <tt>/etc/audit/auditd.conf</tt>. Set <tt>overflow_action</tt>
|
|
|
76240a |
+ to one of the following values: <tt>syslog</tt>, <tt>single</tt>, <tt>halt</tt>.
|
|
|
76240a |
+
|
|
|
76240a |
+
|
|
|
76240a |
+rationale: |-
|
|
|
76240a |
+ The audit system should have an action setup in the event the internal event queue becomes full
|
|
|
76240a |
+ so that no data is lost.
|
|
|
76240a |
+
|
|
|
76240a |
+severity: medium
|
|
|
76240a |
+
|
|
|
76240a |
+identifiers:
|
|
|
76240a |
+ cce@rhel8: CCE-85889-4
|
|
|
76240a |
+
|
|
|
76240a |
+references:
|
|
|
76240a |
+ disa: CCI-001851
|
|
|
76240a |
+ nist: AU-4(1)
|
|
|
76240a |
+ srg: SRG-OS-000342-GPOS-00133,SRG-OS-000479-GPOS-00224
|
|
|
76240a |
+ stigid@rhel8: RHEL-08-030700
|
|
|
76240a |
+
|
|
|
76240a |
+ocil_clause: 'auditd overflow action is not setup correctly'
|
|
|
76240a |
+
|
|
|
76240a |
+ocil: |-
|
|
|
76240a |
+ Verify the audit system is configured to take an appropriate action when the internal event queue is full:
|
|
|
76240a |
+ $ sudo grep -i overflow_action /etc/audit/auditd.conf
|
|
|
76240a |
+
|
|
|
76240a |
+ The output should contain be like <tt>overflow_action = syslog</tt>
|
|
|
76240a |
+
|
|
|
76240a |
+ If the value of the "overflow_action" option is not set to <tt>syslog</tt>,
|
|
|
76240a |
+ <tt>single</tt>, <tt>halt</tt> or the line is commented out, ask the System Administrator
|
|
|
76240a |
+ to indicate how the audit logs are off-loaded to a different system or media.
|
|
|
76240a |
diff --git a/linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_overflow_action/tests/commented_out.fail.sh b/linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_overflow_action/tests/commented_out.fail.sh
|
|
|
76240a |
new file mode 100644
|
|
|
76240a |
index 0000000000..ec7525b195
|
|
|
76240a |
--- /dev/null
|
|
|
76240a |
+++ b/linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_overflow_action/tests/commented_out.fail.sh
|
|
|
76240a |
@@ -0,0 +1,5 @@
|
|
|
76240a |
+#!/bin/bash
|
|
|
76240a |
+# Ensure test system has proper directories/files for test scenario
|
|
|
76240a |
+bash -x setup.sh
|
|
|
76240a |
+
|
|
|
76240a |
+echo "# overflow_action = syslog" >> /etc/audit/auditd.conf
|
|
|
76240a |
diff --git a/linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_overflow_action/tests/empty.fail.sh b/linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_overflow_action/tests/empty.fail.sh
|
|
|
76240a |
new file mode 100644
|
|
|
76240a |
index 0000000000..e4d173ab37
|
|
|
76240a |
--- /dev/null
|
|
|
76240a |
+++ b/linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_overflow_action/tests/empty.fail.sh
|
|
|
76240a |
@@ -0,0 +1,7 @@
|
|
|
76240a |
+#!/bin/bash
|
|
|
76240a |
+# Ensure test system has proper directories/files for test scenario
|
|
|
76240a |
+bash -x setup.sh
|
|
|
76240a |
+
|
|
|
76240a |
+if [[ -f $config_file ]]; then
|
|
|
76240a |
+ echo '' > $config_file
|
|
|
76240a |
+fi
|
|
|
76240a |
diff --git a/linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_overflow_action/tests/file_not_present.fail.sh b/linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_overflow_action/tests/file_not_present.fail.sh
|
|
|
76240a |
new file mode 100644
|
|
|
76240a |
index 0000000000..f26cd7cddf
|
|
|
76240a |
--- /dev/null
|
|
|
76240a |
+++ b/linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_overflow_action/tests/file_not_present.fail.sh
|
|
|
76240a |
@@ -0,0 +1,7 @@
|
|
|
76240a |
+#!/bin/bash
|
|
|
76240a |
+
|
|
|
76240a |
+config_file=/etc/audit/auditd.conf
|
|
|
76240a |
+
|
|
|
76240a |
+if [[ -f $config_file ]]; then
|
|
|
76240a |
+ rm -f $config_file
|
|
|
76240a |
+fi
|
|
|
76240a |
diff --git a/linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_overflow_action/tests/halt.pass.sh b/linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_overflow_action/tests/halt.pass.sh
|
|
|
76240a |
new file mode 100644
|
|
|
76240a |
index 0000000000..0ec591b25b
|
|
|
76240a |
--- /dev/null
|
|
|
76240a |
+++ b/linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_overflow_action/tests/halt.pass.sh
|
|
|
76240a |
@@ -0,0 +1,5 @@
|
|
|
76240a |
+#!/bin/bash
|
|
|
76240a |
+# Ensure test system has proper directories/files for test scenario
|
|
|
76240a |
+bash -x setup.sh
|
|
|
76240a |
+
|
|
|
76240a |
+echo "overflow_action = halt" >> /etc/audit/auditd.conf
|
|
|
76240a |
diff --git a/linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_overflow_action/tests/ignore.fail.sh b/linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_overflow_action/tests/ignore.fail.sh
|
|
|
76240a |
new file mode 100644
|
|
|
76240a |
index 0000000000..236ad543fe
|
|
|
76240a |
--- /dev/null
|
|
|
76240a |
+++ b/linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_overflow_action/tests/ignore.fail.sh
|
|
|
76240a |
@@ -0,0 +1,5 @@
|
|
|
76240a |
+#!/bin/bash
|
|
|
76240a |
+# Ensure test system has proper directories/files for test scenario
|
|
|
76240a |
+bash -x setup.sh
|
|
|
76240a |
+
|
|
|
76240a |
+echo "overflow_action = ignore" >> /etc/audit/auditd.conf
|
|
|
76240a |
diff --git a/linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_overflow_action/tests/not_present.fail.sh b/linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_overflow_action/tests/not_present.fail.sh
|
|
|
76240a |
new file mode 100644
|
|
|
76240a |
index 0000000000..74efdcafee
|
|
|
76240a |
--- /dev/null
|
|
|
76240a |
+++ b/linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_overflow_action/tests/not_present.fail.sh
|
|
|
76240a |
@@ -0,0 +1,5 @@
|
|
|
76240a |
+#!/bin/bash
|
|
|
76240a |
+# Ensure test system has proper directories/files for test scenario
|
|
|
76240a |
+bash -x setup.sh
|
|
|
76240a |
+config_file=/etc/audit/auditd.conf
|
|
|
76240a |
+sed -i "s/^.*overflow_action.*$//" $config_file
|
|
|
76240a |
diff --git a/linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_overflow_action/tests/setup.sh b/linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_overflow_action/tests/setup.sh
|
|
|
76240a |
new file mode 100644
|
|
|
76240a |
index 0000000000..de11126320
|
|
|
76240a |
--- /dev/null
|
|
|
76240a |
+++ b/linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_overflow_action/tests/setup.sh
|
|
|
76240a |
@@ -0,0 +1,9 @@
|
|
|
76240a |
+#!/bin/bash
|
|
|
76240a |
+# Use this script to ensure the audit directory structure and audit conf file
|
|
|
76240a |
+# exist in the test env.
|
|
|
76240a |
+config_file=/etc/audit/auditd.conf
|
|
|
76240a |
+
|
|
|
76240a |
+# Ensure directory structure exists (useful for container based testing)
|
|
|
76240a |
+test -d /etc/audit/ || mkdir -p /etc/audit/
|
|
|
76240a |
+
|
|
|
76240a |
+test -f $config_file || touch $config_file
|
|
|
76240a |
diff --git a/linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_overflow_action/tests/single.pass.sh b/linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_overflow_action/tests/single.pass.sh
|
|
|
76240a |
new file mode 100644
|
|
|
76240a |
index 0000000000..f9fa7a935c
|
|
|
76240a |
--- /dev/null
|
|
|
76240a |
+++ b/linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_overflow_action/tests/single.pass.sh
|
|
|
76240a |
@@ -0,0 +1,5 @@
|
|
|
76240a |
+#!/bin/bash
|
|
|
76240a |
+# Ensure test system has proper directories/files for test scenario
|
|
|
76240a |
+bash -x setup.sh
|
|
|
76240a |
+
|
|
|
76240a |
+echo "overflow_action = single" >> /etc/audit/auditd.conf
|
|
|
76240a |
diff --git a/linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_overflow_action/tests/syslog.pass.sh b/linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_overflow_action/tests/syslog.pass.sh
|
|
|
76240a |
new file mode 100644
|
|
|
76240a |
index 0000000000..1c625fb752
|
|
|
76240a |
--- /dev/null
|
|
|
76240a |
+++ b/linux_os/guide/system/auditing/configure_auditd_data_retention/auditd_overflow_action/tests/syslog.pass.sh
|
|
|
76240a |
@@ -0,0 +1,5 @@
|
|
|
76240a |
+#!/bin/bash
|
|
|
76240a |
+# Ensure test system has proper directories/files for test scenario
|
|
|
76240a |
+bash -x setup.sh
|
|
|
76240a |
+
|
|
|
76240a |
+echo "overflow_action = syslog" >> /etc/audit/auditd.conf
|
|
|
76240a |
diff --git a/products/rhel8/profiles/stig.profile b/products/rhel8/profiles/stig.profile
|
|
|
76240a |
index 6372d13cfc..5cac78e00d 100644
|
|
|
76240a |
--- a/products/rhel8/profiles/stig.profile
|
|
|
76240a |
+++ b/products/rhel8/profiles/stig.profile
|
|
|
76240a |
@@ -826,6 +826,7 @@ selections:
|
|
|
76240a |
- rsyslog_remote_loghost
|
|
|
76240a |
|
|
|
76240a |
# RHEL-08-030700
|
|
|
76240a |
+ - auditd_overflow_action
|
|
|
76240a |
|
|
|
76240a |
# RHEL-08-030710
|
|
|
76240a |
|
|
|
76240a |
diff --git a/shared/references/cce-redhat-avail.txt b/shared/references/cce-redhat-avail.txt
|
|
|
76240a |
index 24e8149168..b3d9596e1f 100644
|
|
|
76240a |
--- a/shared/references/cce-redhat-avail.txt
|
|
|
76240a |
+++ b/shared/references/cce-redhat-avail.txt
|
|
|
76240a |
@@ -27,7 +27,6 @@ CCE-85885-2
|
|
|
76240a |
CCE-85886-0
|
|
|
76240a |
CCE-85887-8
|
|
|
76240a |
CCE-85888-6
|
|
|
76240a |
-CCE-85889-4
|
|
|
76240a |
CCE-85890-2
|
|
|
76240a |
CCE-85891-0
|
|
|
76240a |
CCE-85892-8
|
|
|
76240a |
diff --git a/tests/data/profile_stability/rhel8/stig.profile b/tests/data/profile_stability/rhel8/stig.profile
|
|
|
76240a |
index 32f1a24a7a..c9d23ed1dc 100644
|
|
|
76240a |
--- a/tests/data/profile_stability/rhel8/stig.profile
|
|
|
76240a |
+++ b/tests/data/profile_stability/rhel8/stig.profile
|
|
|
76240a |
@@ -73,6 +73,7 @@ selections:
|
|
|
76240a |
- auditd_local_events
|
|
|
76240a |
- auditd_log_format
|
|
|
76240a |
- auditd_name_format
|
|
|
76240a |
+- auditd_overflow_action
|
|
|
76240a |
- banner_etc_issue
|
|
|
76240a |
- bios_enable_execution_restrictions
|
|
|
76240a |
- chronyd_client_only
|
|
|
76240a |
diff --git a/tests/data/profile_stability/rhel8/stig_gui.profile b/tests/data/profile_stability/rhel8/stig_gui.profile
|
|
|
76240a |
index d6a27c67dc..7303145141 100644
|
|
|
76240a |
--- a/tests/data/profile_stability/rhel8/stig_gui.profile
|
|
|
76240a |
+++ b/tests/data/profile_stability/rhel8/stig_gui.profile
|
|
|
76240a |
@@ -84,6 +84,7 @@ selections:
|
|
|
76240a |
- auditd_local_events
|
|
|
76240a |
- auditd_log_format
|
|
|
76240a |
- auditd_name_format
|
|
|
76240a |
+- auditd_overflow_action
|
|
|
76240a |
- banner_etc_issue
|
|
|
76240a |
- bios_enable_execution_restrictions
|
|
|
76240a |
- chronyd_client_only
|