|
|
07cb6b |
diff --git a/products/rhel8/profiles/stig.profile b/products/rhel8/profiles/stig.profile
|
|
|
07cb6b |
index d92bc72971c..98cabee38dd 100644
|
|
|
07cb6b |
--- a/products/rhel8/profiles/stig.profile
|
|
|
07cb6b |
+++ b/products/rhel8/profiles/stig.profile
|
|
|
07cb6b |
@@ -51,7 +51,7 @@ selections:
|
|
|
07cb6b |
- var_password_pam_lcredit=1
|
|
|
07cb6b |
- var_password_pam_retry=3
|
|
|
07cb6b |
- var_password_pam_minlen=15
|
|
|
07cb6b |
- - var_sshd_set_keepalive=0
|
|
|
07cb6b |
+ # - var_sshd_set_keepalive=0
|
|
|
07cb6b |
- sshd_approved_macs=stig
|
|
|
07cb6b |
- sshd_approved_ciphers=stig
|
|
|
07cb6b |
- sshd_idle_timeout_value=10_minutes
|
|
|
07cb6b |
@@ -170,11 +170,13 @@ selections:
|
|
|
07cb6b |
# RHEL-08-010190
|
|
|
07cb6b |
- dir_perms_world_writable_sticky_bits
|
|
|
07cb6b |
|
|
|
07cb6b |
- # RHEL-08-010200
|
|
|
07cb6b |
- - sshd_set_keepalive_0
|
|
|
07cb6b |
-
|
|
|
07cb6b |
- # RHEL-08-010201
|
|
|
07cb6b |
- - sshd_set_idle_timeout
|
|
|
07cb6b |
+ # These two items don't behave as they used to in RHEL8.6 and RHEL9
|
|
|
07cb6b |
+ # anymore. They will be disabled for now until an alternative
|
|
|
07cb6b |
+ # solution is found.
|
|
|
07cb6b |
+ # # RHEL-08-010200
|
|
|
07cb6b |
+ # - sshd_set_keepalive_0
|
|
|
07cb6b |
+ # # RHEL-08-010201
|
|
|
07cb6b |
+ # - sshd_set_idle_timeout
|
|
|
07cb6b |
|
|
|
07cb6b |
# RHEL-08-010210
|
|
|
07cb6b |
- file_permissions_var_log_messages
|
|
|
07cb6b |
diff --git a/products/rhel9/profiles/stig.profile b/products/rhel9/profiles/stig.profile
|
|
|
07cb6b |
index 42c6d0e9aca..842f17c7021 100644
|
|
|
07cb6b |
--- a/products/rhel9/profiles/stig.profile
|
|
|
07cb6b |
+++ b/products/rhel9/profiles/stig.profile
|
|
|
07cb6b |
@@ -52,7 +52,7 @@ selections:
|
|
|
07cb6b |
- var_password_pam_lcredit=1
|
|
|
07cb6b |
- var_password_pam_retry=3
|
|
|
07cb6b |
- var_password_pam_minlen=15
|
|
|
07cb6b |
- - var_sshd_set_keepalive=0
|
|
|
07cb6b |
+ # - var_sshd_set_keepalive=0
|
|
|
07cb6b |
- sshd_approved_macs=stig
|
|
|
07cb6b |
- sshd_approved_ciphers=stig
|
|
|
07cb6b |
- sshd_idle_timeout_value=10_minutes
|
|
|
07cb6b |
@@ -171,11 +171,13 @@ selections:
|
|
|
07cb6b |
# RHEL-08-010190
|
|
|
07cb6b |
- dir_perms_world_writable_sticky_bits
|
|
|
07cb6b |
|
|
|
07cb6b |
- # RHEL-08-010200
|
|
|
07cb6b |
- - sshd_set_keepalive_0
|
|
|
07cb6b |
-
|
|
|
07cb6b |
- # RHEL-08-010201
|
|
|
07cb6b |
- - sshd_set_idle_timeout
|
|
|
07cb6b |
+ # These two items don't behave as they used to in RHEL8.6 and RHEL9
|
|
|
07cb6b |
+ # anymore. They will be disabled for now until an alternative
|
|
|
07cb6b |
+ # solution is found.
|
|
|
07cb6b |
+ # # RHEL-08-010200
|
|
|
07cb6b |
+ # - sshd_set_keepalive_0
|
|
|
07cb6b |
+ # # RHEL-08-010201
|
|
|
07cb6b |
+ # - sshd_set_idle_timeout
|
|
|
07cb6b |
|
|
|
07cb6b |
# RHEL-08-010210
|
|
|
07cb6b |
- file_permissions_var_log_messages
|
|
|
07cb6b |
diff --git a/tests/data/profile_stability/rhel8/stig.profile b/tests/data/profile_stability/rhel8/stig.profile
|
|
|
07cb6b |
index e4fee44f9f9..e3c8ebfc9a5 100644
|
|
|
07cb6b |
--- a/tests/data/profile_stability/rhel8/stig.profile
|
|
|
07cb6b |
+++ b/tests/data/profile_stability/rhel8/stig.profile
|
|
|
07cb6b |
@@ -353,8 +353,6 @@ selections:
|
|
|
07cb6b |
- sshd_enable_warning_banner
|
|
|
07cb6b |
- sshd_print_last_log
|
|
|
07cb6b |
- sshd_rekey_limit
|
|
|
07cb6b |
-- sshd_set_idle_timeout
|
|
|
07cb6b |
-- sshd_set_keepalive_0
|
|
|
07cb6b |
- sshd_use_strong_rng
|
|
|
07cb6b |
- sshd_x11_use_localhost
|
|
|
07cb6b |
- sssd_certificate_verification
|
|
|
07cb6b |
@@ -423,7 +421,6 @@ selections:
|
|
|
07cb6b |
- var_password_pam_ucredit=1
|
|
|
07cb6b |
- var_password_pam_lcredit=1
|
|
|
07cb6b |
- var_password_pam_retry=3
|
|
|
07cb6b |
-- var_sshd_set_keepalive=0
|
|
|
07cb6b |
- sshd_approved_macs=stig
|
|
|
07cb6b |
- sshd_approved_ciphers=stig
|
|
|
07cb6b |
- sshd_idle_timeout_value=10_minutes
|
|
|
07cb6b |
diff --git a/tests/data/profile_stability/rhel8/stig_gui.profile b/tests/data/profile_stability/rhel8/stig_gui.profile
|
|
|
07cb6b |
index 83d04775e3a..8ef48e0654b 100644
|
|
|
07cb6b |
--- a/tests/data/profile_stability/rhel8/stig_gui.profile
|
|
|
07cb6b |
+++ b/tests/data/profile_stability/rhel8/stig_gui.profile
|
|
|
07cb6b |
@@ -364,8 +364,6 @@ selections:
|
|
|
07cb6b |
- sshd_enable_warning_banner
|
|
|
07cb6b |
- sshd_print_last_log
|
|
|
07cb6b |
- sshd_rekey_limit
|
|
|
07cb6b |
-- sshd_set_idle_timeout
|
|
|
07cb6b |
-- sshd_set_keepalive_0
|
|
|
07cb6b |
- sshd_use_strong_rng
|
|
|
07cb6b |
- sshd_x11_use_localhost
|
|
|
07cb6b |
- sssd_certificate_verification
|
|
|
07cb6b |
@@ -432,7 +430,6 @@ selections:
|
|
|
07cb6b |
- var_password_pam_ucredit=1
|
|
|
07cb6b |
- var_password_pam_lcredit=1
|
|
|
07cb6b |
- var_password_pam_retry=3
|
|
|
07cb6b |
-- var_sshd_set_keepalive=0
|
|
|
07cb6b |
- sshd_approved_macs=stig
|
|
|
07cb6b |
- sshd_approved_ciphers=stig
|
|
|
07cb6b |
- sshd_idle_timeout_value=10_minutes
|