Blame SOURCES/scap-security-guide-0.1.61-update_RHEL_STIG-PR_8130.patch

12e95e
diff --git a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_group_ownership_library_dirs/rule.yml b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_group_ownership_library_dirs/rule.yml
12e95e
index dac47a1c6d1..3a6167a5717 100644
12e95e
--- a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_group_ownership_library_dirs/rule.yml
12e95e
+++ b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_group_ownership_library_dirs/rule.yml
12e95e
@@ -39,7 +39,7 @@ references:
12e95e
     nist: CM-5(6),CM-5(6).1
12e95e
     srg: SRG-OS-000259-GPOS-00100
12e95e
     stigid@ol8: OL08-00-010350
12e95e
-    stigid@rhel8: RHEL-08-010350
12e95e
+    stigid@rhel8: RHEL-08-010351
12e95e
     stigid@sle12: SLES-12-010876
12e95e
     stigid@sle15: SLES-15-010356
12e95e
     stigid@ubuntu2004: UBTU-20-010431
12e95e
diff --git a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_group_ownership_library_dirs/tests/all_dirs_ok.pass.sh b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_group_ownership_library_dirs/tests/all_dirs_ok.pass.sh
12e95e
index 50fdb17bd2e..6a05a2b82ea 100644
12e95e
--- a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_group_ownership_library_dirs/tests/all_dirs_ok.pass.sh
12e95e
+++ b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_group_ownership_library_dirs/tests/all_dirs_ok.pass.sh
12e95e
@@ -1,4 +1,4 @@
12e95e
-# platform = multi_platform_sle,Red Hat Enterprise Linux 8,multi_platform_fedora
12e95e
+# platform = multi_platform_sle,multi_platform_rhel,multi_platform_fedora
12e95e
 
12e95e
 DIRS="/lib /lib64 /usr/lib /usr/lib64"
12e95e
 for dirPath in $DIRS; do
12e95e
diff --git a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_group_ownership_library_dirs/tests/correct_groupowner.pass.sh b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_group_ownership_library_dirs/tests/correct_groupowner.pass.sh
12e95e
new file mode 100644
12e95e
index 00000000000..6a05a2b82ea
12e95e
--- /dev/null
12e95e
+++ b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_group_ownership_library_dirs/tests/correct_groupowner.pass.sh
12e95e
@@ -0,0 +1,6 @@
12e95e
+# platform = multi_platform_sle,multi_platform_rhel,multi_platform_fedora
12e95e
+
12e95e
+DIRS="/lib /lib64 /usr/lib /usr/lib64"
12e95e
+for dirPath in $DIRS; do
12e95e
+	find "$dirPath" -type d -exec chgrp root '{}' \;
12e95e
+done
12e95e
diff --git a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_group_ownership_library_dirs/tests/incorrect_groupowner.fail.sh b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_group_ownership_library_dirs/tests/incorrect_groupowner.fail.sh
12e95e
new file mode 100644
12e95e
index 00000000000..36461f5e5c3
12e95e
--- /dev/null
12e95e
+++ b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_group_ownership_library_dirs/tests/incorrect_groupowner.fail.sh
12e95e
@@ -0,0 +1,6 @@
12e95e
+# platform = multi_platform_sle,multi_platform_rhel,multi_platform_fedora
12e95e
+
12e95e
+DIRS="/lib /lib64 /usr/lib /usr/lib64"
12e95e
+for dirPath in $DIRS; do
12e95e
+	mkdir -p "$dirPath/testme" && chgrp nobody "$dirPath/testme"
12e95e
+done
12e95e
diff --git a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_group_ownership_library_dirs/tests/incorrect_groupowner_2.fail.sh b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_group_ownership_library_dirs/tests/incorrect_groupowner_2.fail.sh
12e95e
new file mode 100644
12e95e
index 00000000000..3f09e3dd018
12e95e
--- /dev/null
12e95e
+++ b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_group_ownership_library_dirs/tests/incorrect_groupowner_2.fail.sh
12e95e
@@ -0,0 +1,6 @@
12e95e
+# platform = multi_platform_sle,multi_platform_rhel,multi_platform_fedora
12e95e
+
12e95e
+DIRS="/lib /lib64 /usr/lib /usr/lib64"
12e95e
+for dirPath in $DIRS; do
12e95e
+	mkdir -p "$dirPath/testme/test2" && chgrp nobody "$dirPath/testme/test2"
12e95e
+done
12e95e
diff --git a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_group_ownership_library_dirs/tests/nobody_group_owned_dir_on_lib.fail.sh b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_group_ownership_library_dirs/tests/nobody_group_owned_dir_on_lib.fail.sh
12e95e
index 043ad6b2dee..36461f5e5c3 100644
12e95e
--- a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_group_ownership_library_dirs/tests/nobody_group_owned_dir_on_lib.fail.sh
12e95e
+++ b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_group_ownership_library_dirs/tests/nobody_group_owned_dir_on_lib.fail.sh
12e95e
@@ -1,4 +1,4 @@
12e95e
-# platform = multi_platform_sle,Red Hat Enterprise Linux 8,multi_platform_fedora
12e95e
+# platform = multi_platform_sle,multi_platform_rhel,multi_platform_fedora
12e95e
 
12e95e
 DIRS="/lib /lib64 /usr/lib /usr/lib64"
12e95e
 for dirPath in $DIRS; do
12e95e
diff --git a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_ownership_binary_dirs/rule.yml b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_ownership_binary_dirs/rule.yml
12e95e
index e2362388678..ba923d8ac55 100644
12e95e
--- a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_ownership_binary_dirs/rule.yml
12e95e
+++ b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_ownership_binary_dirs/rule.yml
12e95e
@@ -27,7 +27,7 @@ references:
12e95e
     srg: SRG-OS-000258-GPOS-00099
12e95e
     stigid@ubuntu2004: UBTU-20-010424
12e95e
 
12e95e
-ocil_clause: 'any system exectables directories are found to not be owned by root'
12e95e
+ocil_clause: 'any system executables directories are found to not be owned by root'
12e95e
 
12e95e
 ocil: |-
12e95e
     System executables are stored in the following directories by default:
12e95e
diff --git a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_ownership_library_dirs/oval/shared.xml b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_ownership_library_dirs/oval/shared.xml
12e95e
deleted file mode 100644
12e95e
index 28e193f827c..00000000000
12e95e
--- a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_ownership_library_dirs/oval/shared.xml
12e95e
+++ /dev/null
12e95e
@@ -1,28 +0,0 @@
12e95e
-<def-group>
12e95e
-  <definition class="compliance" id="dir_ownership_library_dirs" version="1">
12e95e
-    {{{ oval_metadata("
12e95e
-        Checks that /lib, /lib64, /usr/lib, /usr/lib64, /lib/modules, and
12e95e
-        directories therein, are owned by root.
12e95e
-      ") }}}
12e95e
-    <criteria operator="AND">
12e95e
-      <criterion test_ref="test_dir_ownership_lib_dir" />
12e95e
-    </criteria>
12e95e
-  </definition>
12e95e
-
12e95e
-  <unix:file_test  check="all" check_existence="none_exist" comment="library directories uid root" id="test_dir_ownership_lib_dir" version="1">
12e95e
-    <unix:object object_ref="object_dir_ownership_lib_dir" />
12e95e
-  </unix:file_test>
12e95e
-
12e95e
-
12e95e
-  <unix:file_object comment="library directories" id="object_dir_ownership_lib_dir" version="1">
12e95e
-    
12e95e
-    <unix:path operation="pattern match">^\/lib(|64)\/|^\/usr\/lib(|64)\/</unix:path>
12e95e
-    <unix:filename xsi:nil="true" />
12e95e
-    <filter action="include">state_owner_library_dirs_not_root</filter>
12e95e
-  </unix:file_object>
12e95e
-
12e95e
-  <unix:file_state id="state_owner_library_dirs_not_root" version="1">
12e95e
-    <unix:user_id datatype="int" operation="not equal">0</unix:user_id>
12e95e
-  </unix:file_state>
12e95e
-
12e95e
-</def-group>
12e95e
diff --git a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_ownership_library_dirs/rule.yml b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_ownership_library_dirs/rule.yml
12e95e
index d6a0beddf6e..f0781b307b3 100644
12e95e
--- a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_ownership_library_dirs/rule.yml
12e95e
+++ b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_ownership_library_dirs/rule.yml
12e95e
@@ -27,6 +27,8 @@ rationale: |-
12e95e
 severity: medium
12e95e
 
12e95e
 identifiers:
12e95e
+    cce@rhel8: CCE-89021-0
12e95e
+    cce@rhel9: CCE-89022-8
12e95e
     cce@sle12: CCE-83236-0
12e95e
     cce@sle15: CCE-85735-9
12e95e
 
12e95e
@@ -34,6 +36,7 @@ references:
12e95e
     disa: CCI-001499
12e95e
     nist: CM-5(6),CM-5(6).1
12e95e
     srg: SRG-OS-000259-GPOS-00100
12e95e
+    stigid@rhel8: RHEL-08-010341
12e95e
     stigid@sle12: SLES-12-010874
12e95e
     stigid@sle15: SLES-15-010354
12e95e
     stigid@ubuntu2004: UBTU-20-010429
12e95e
@@ -49,3 +52,14 @@ ocil: |-
12e95e
     For each of these directories, run the following command to find files not
12e95e
     owned by root:
12e95e
     
$ sudo find -L $DIR ! -user root -type d -exec chown root {} \;
12e95e
+
12e95e
+template:
12e95e
+    name: file_owner
12e95e
+    vars:
12e95e
+        filepath:
12e95e
+            - /lib/
12e95e
+            - /lib64/
12e95e
+            - /usr/lib/
12e95e
+            - /usr/lib64/
12e95e
+        recursive: 'true'
12e95e
+        fileuid: '0'
12e95e
diff --git a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_ownership_library_dirs/tests/all_dirs_ok.pass.sh b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_ownership_library_dirs/tests/correct_owner.pass.sh
12e95e
similarity index 69%
12e95e
rename from linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_ownership_library_dirs/tests/all_dirs_ok.pass.sh
12e95e
rename to linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_ownership_library_dirs/tests/correct_owner.pass.sh
12e95e
index 01891664f64..a0d4990582e 100644
12e95e
--- a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_ownership_library_dirs/tests/all_dirs_ok.pass.sh
12e95e
+++ b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_ownership_library_dirs/tests/correct_owner.pass.sh
12e95e
@@ -1,4 +1,4 @@
12e95e
-# platform = multi_platform_sle
12e95e
+# platform = multi_platform_sle,multi_platform_rhel
12e95e
 DIRS="/lib /lib64 /usr/lib /usr/lib64"
12e95e
 for dirPath in $DIRS; do
12e95e
 	find "$dirPath" -type d -exec chown root '{}' \;
12e95e
diff --git a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_ownership_library_dirs/tests/nobody_owned_dir_on_lib.fail.sh b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_ownership_library_dirs/tests/incorrect_owner.fail.sh
12e95e
similarity index 63%
12e95e
rename from linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_ownership_library_dirs/tests/nobody_owned_dir_on_lib.fail.sh
12e95e
rename to linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_ownership_library_dirs/tests/incorrect_owner.fail.sh
12e95e
index 59b8a1867eb..f366c2d7922 100644
12e95e
--- a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_ownership_library_dirs/tests/nobody_owned_dir_on_lib.fail.sh
12e95e
+++ b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_ownership_library_dirs/tests/incorrect_owner.fail.sh
12e95e
@@ -1,4 +1,5 @@
12e95e
-# platform = multi_platform_sle
12e95e
+# platform = multi_platform_sle,multi_platform_rhel
12e95e
+groupadd nogroup
12e95e
 DIRS="/lib /lib64"
12e95e
 for dirPath in $DIRS; do
12e95e
 	mkdir -p "$dirPath/testme" && chown nobody:nogroup "$dirPath/testme"
12e95e
diff --git a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_permissions_library_dirs/oval/shared.xml b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_permissions_library_dirs/oval/shared.xml
12e95e
index a0e4e24b4f4..add26b2e778 100644
12e95e
--- a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_permissions_library_dirs/oval/shared.xml
12e95e
+++ b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_permissions_library_dirs/oval/shared.xml
12e95e
@@ -1,8 +1,8 @@
12e95e
 <def-group>
12e95e
   <definition class="compliance" id="dir_permissions_library_dirs" version="1">
12e95e
     {{{ oval_metadata("
12e95e
-        Checks that /lib, /lib64, /usr/lib, /usr/lib64, /lib/modules, and
12e95e
-        objects therein, are not group-writable or world-writable.
12e95e
+        Checks that the directories /lib, /lib64, /usr/lib and /usr/lib64
12e95e
+        are not group-writable or world-writable.
12e95e
       ") }}}
12e95e
     <criteria operator="AND">
12e95e
       <criterion test_ref="dir_test_perms_lib_dir" />
12e95e
@@ -19,7 +19,7 @@
12e95e
     <unix:path operation="pattern match">^\/lib(|64)|^\/usr\/lib(|64)</unix:path>
12e95e
     <unix:filename xsi:nil="true" />
12e95e
     <filter action="include">dir_state_perms_nogroupwrite_noworldwrite</filter>
12e95e
-    <filter action="exclude">dir_perms_state_symlink</filter>
12e95e
+    <filter action="exclude">dir_perms_state_nogroupwrite_noworldwrite_symlink</filter>
12e95e
   </unix:file_object>
12e95e
 
12e95e
   <unix:file_state id="dir_state_perms_nogroupwrite_noworldwrite" version="1" operator="OR">
12e95e
@@ -27,7 +27,7 @@
12e95e
     <unix:owrite datatype="boolean">true</unix:owrite>
12e95e
   </unix:file_state>
12e95e
 
12e95e
-  <unix:file_state id="dir_perms_state_symlink" version="1">
12e95e
+  <unix:file_state id="dir_perms_state_nogroupwrite_noworldwrite_symlink" version="1">
12e95e
     <unix:type operation="equals">symbolic link</unix:type>
12e95e
   </unix:file_state>
12e95e
 
12e95e
diff --git a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_permissions_library_dirs/rule.yml b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_permissions_library_dirs/rule.yml
12e95e
index db89a5e47a1..6e62e8c6bbf 100644
12e95e
--- a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_permissions_library_dirs/rule.yml
12e95e
+++ b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/dir_permissions_library_dirs/rule.yml
12e95e
@@ -60,3 +60,14 @@ ocil: |-
12e95e
     To find shared libraries that are group-writable or world-writable,
12e95e
     run the following command for each directory DIR which contains shared libraries:
12e95e
     
$ sudo find -L DIR -perm /022 -type d
12e95e
+
12e95e
+template:
12e95e
+    name: file_permissions
12e95e
+    vars:
12e95e
+        filepath:
12e95e
+            - /lib/
12e95e
+            - /lib64/
12e95e
+            - /usr/lib/
12e95e
+            - /usr/lib64/
12e95e
+        recursive: 'true'
12e95e
+        filemode: '0755'
12e95e
diff --git a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_groupownership_system_commands_dirs/ansible/shared.yml b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_groupownership_system_commands_dirs/ansible/shared.yml
12e95e
index 6b3a2905068..eec7485f90c 100644
12e95e
--- a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_groupownership_system_commands_dirs/ansible/shared.yml
12e95e
+++ b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_groupownership_system_commands_dirs/ansible/shared.yml
12e95e
@@ -1,4 +1,4 @@
12e95e
-# platform = multi_platform_sle,Oracle Linux 8,Red Hat Enterprise Linux 8,multi_platform_fedora
12e95e
+# platform = multi_platform_sle,Oracle Linux 8,multi_platform_rhel,multi_platform_fedora
12e95e
 # reboot = false
12e95e
 # strategy = restrict
12e95e
 # complexity = medium
12e95e
diff --git a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_groupownership_system_commands_dirs/bash/shared.sh b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_groupownership_system_commands_dirs/bash/shared.sh
12e95e
index a9e8c7d8e25..e352dd34a67 100644
12e95e
--- a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_groupownership_system_commands_dirs/bash/shared.sh
12e95e
+++ b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_groupownership_system_commands_dirs/bash/shared.sh
12e95e
@@ -1,4 +1,4 @@
12e95e
-# platform = multi_platform_sle,Oracle Linux 8,Red Hat Enterprise Linux 8,multi_platform_fedora,multi_platform_ubuntu
12e95e
+# platform = multi_platform_sle,Oracle Linux 8,multi_platform_rhel,multi_platform_fedora,multi_platform_ubuntu
12e95e
 
12e95e
 for SYSCMDFILES in /bin /sbin /usr/bin /usr/sbin /usr/local/bin /usr/local/sbin
12e95e
 do
12e95e
diff --git a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_ownership_library_dirs/ansible/shared.yml b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_ownership_library_dirs/ansible/shared.yml
12e95e
deleted file mode 100644
12e95e
index de81a3703b4..00000000000
12e95e
--- a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_ownership_library_dirs/ansible/shared.yml
12e95e
+++ /dev/null
12e95e
@@ -1,18 +0,0 @@
12e95e
-# platform = Red Hat Virtualization 4,multi_platform_fedora,multi_platform_rhel,multi_platform_ol,multi_platform_sle
12e95e
-# reboot = false
12e95e
-# strategy = restrict
12e95e
-# complexity = medium
12e95e
-# disruption = medium
12e95e
-- name: "Read list libraries without root ownership"
12e95e
-  command: "find -L /usr/lib /usr/lib64 /lib /lib64 \\! -user root"
12e95e
-  register: libraries_not_owned_by_root
12e95e
-  changed_when: False
12e95e
-  failed_when: False
12e95e
-  check_mode: no
12e95e
-
12e95e
-- name: "Set ownership of system libraries to root"
12e95e
-  file:
12e95e
-    path: "{{ item }}"
12e95e
-    owner: "root"
12e95e
-  with_items: "{{ libraries_not_owned_by_root.stdout_lines }}"
12e95e
-  when: libraries_not_owned_by_root | length > 0
12e95e
diff --git a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_ownership_library_dirs/bash/shared.sh b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_ownership_library_dirs/bash/shared.sh
12e95e
deleted file mode 100644
12e95e
index c75167d2fe7..00000000000
12e95e
--- a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_ownership_library_dirs/bash/shared.sh
12e95e
+++ /dev/null
12e95e
@@ -1,8 +0,0 @@
12e95e
-# platform = Red Hat Virtualization 4,multi_platform_fedora,multi_platform_rhel,multi_platform_ol,multi_platform_sle
12e95e
-for LIBDIR in /usr/lib /usr/lib64 /lib /lib64
12e95e
-do
12e95e
-  if [ -d $LIBDIR ]
12e95e
-  then
12e95e
-    find -L $LIBDIR \! -user root -exec chown root {} \; 
12e95e
-  fi
12e95e
-done
12e95e
diff --git a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_ownership_library_dirs/oval/shared.xml b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_ownership_library_dirs/oval/shared.xml
12e95e
deleted file mode 100644
12e95e
index 59ee3d82a21..00000000000
12e95e
--- a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_ownership_library_dirs/oval/shared.xml
12e95e
+++ /dev/null
12e95e
@@ -1,39 +0,0 @@
12e95e
-<def-group>
12e95e
-  <definition class="compliance" id="file_ownership_library_dirs" version="1">
12e95e
-    {{{ oval_metadata("
12e95e
-        Checks that /lib, /lib64, /usr/lib, /usr/lib64, /lib/modules, and
12e95e
-        objects therein, are owned by root.
12e95e
-      ") }}}
12e95e
-    <criteria operator="AND">
12e95e
-      <criterion test_ref="test_ownership_lib_dir" />
12e95e
-      <criterion test_ref="test_ownership_lib_files" />
12e95e
-    </criteria>
12e95e
-  </definition>
12e95e
-
12e95e
-  <unix:file_test  check="all" check_existence="none_exist" comment="library directories uid root" id="test_ownership_lib_dir" version="1">
12e95e
-    <unix:object object_ref="object_file_ownership_lib_dir" />
12e95e
-  </unix:file_test>
12e95e
-
12e95e
-  <unix:file_test  check="all" check_existence="none_exist" comment="library files uid root" id="test_ownership_lib_files" version="1">
12e95e
-    <unix:object object_ref="object_file_ownership_lib_files" />
12e95e
-  </unix:file_test>
12e95e
-
12e95e
-  <unix:file_object comment="library directories" id="object_file_ownership_lib_dir" version="1">
12e95e
-    
12e95e
-    <unix:path operation="pattern match">^\/lib(|64)\/|^\/usr\/lib(|64)\/</unix:path>
12e95e
-    <unix:filename xsi:nil="true" />
12e95e
-    <filter action="include">state_owner_libraries_not_root</filter>
12e95e
-  </unix:file_object>
12e95e
-
12e95e
-  <unix:file_object comment="library files" id="object_file_ownership_lib_files" version="1">
12e95e
-    
12e95e
-    <unix:path operation="pattern match">^\/lib(|64)\/|^\/usr\/lib(|64)\/</unix:path>
12e95e
-    <unix:filename operation="pattern match">^.*$</unix:filename>
12e95e
-   <filter action="include">state_owner_libraries_not_root</filter>
12e95e
-  </unix:file_object>
12e95e
-
12e95e
-  <unix:file_state id="state_owner_libraries_not_root" version="1">
12e95e
-    <unix:user_id datatype="int" operation="not equal">0</unix:user_id>
12e95e
-  </unix:file_state>
12e95e
-
12e95e
-</def-group>
12e95e
diff --git a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_ownership_library_dirs/rule.yml b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_ownership_library_dirs/rule.yml
12e95e
index d80681c1e65..b6bc18e8310 100644
12e95e
--- a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_ownership_library_dirs/rule.yml
12e95e
+++ b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_ownership_library_dirs/rule.yml
12e95e
@@ -60,3 +60,14 @@ ocil: |-
12e95e
     For each of these directories, run the following command to find files not
12e95e
     owned by root:
12e95e
     
$ sudo find -L $DIR ! -user root -exec chown root {} \;
12e95e
+
12e95e
+template:
12e95e
+    name: file_owner
12e95e
+    vars:
12e95e
+        filepath:
12e95e
+            - /lib/
12e95e
+            - /lib64/
12e95e
+            - /usr/lib/
12e95e
+            - /usr/lib64/
12e95e
+        file_regex: ^.*$
12e95e
+        fileuid: '0'
12e95e
diff --git a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_ownership_library_dirs/tests/correct_owner.pass.sh b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_ownership_library_dirs/tests/correct_owner.pass.sh
12e95e
new file mode 100644
12e95e
index 00000000000..92c6a0889d4
12e95e
--- /dev/null
12e95e
+++ b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_ownership_library_dirs/tests/correct_owner.pass.sh
12e95e
@@ -0,0 +1,9 @@
12e95e
+# platform = multi_platform_sle,multi_platform_rhel,multi_platform_fedora,multi_platform_ubuntu
12e95e
+
12e95e
+for SYSLIBDIRS in /lib /lib64 /usr/lib /usr/lib64
12e95e
+do
12e95e
+    if [[ -d $SYSLIBDIRS  ]]
12e95e
+    then
12e95e
+        find $SYSLIBDIRS ! -user root -type f -exec chown root '{}' \;
12e95e
+    fi
12e95e
+done
12e95e
diff --git a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_ownership_library_dirs/tests/incorrect_owner.fail.sh b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_ownership_library_dirs/tests/incorrect_owner.fail.sh
12e95e
new file mode 100644
12e95e
index 00000000000..84da71f45f7
12e95e
--- /dev/null
12e95e
+++ b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_ownership_library_dirs/tests/incorrect_owner.fail.sh
12e95e
@@ -0,0 +1,11 @@
12e95e
+# platform = multi_platform_sle,multi_platform_rhel,multi_platform_fedora,multi_platform_ubuntu
12e95e
+
12e95e
+useradd user_test
12e95e
+for TESTFILE in /lib/test_me /lib64/test_me /usr/lib/test_me /usr/lib64/test_me
12e95e
+do
12e95e
+   if [[ ! -f $TESTFILE ]]
12e95e
+   then
12e95e
+     touch $TESTFILE
12e95e
+   fi
12e95e
+   chown user_test $TESTFILE
12e95e
+done
12e95e
diff --git a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_permissions_library_dirs/ansible/shared.yml b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_permissions_library_dirs/ansible/shared.yml
12e95e
deleted file mode 100644
12e95e
index cf9eebace8b..00000000000
12e95e
--- a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_permissions_library_dirs/ansible/shared.yml
12e95e
+++ /dev/null
12e95e
@@ -1,18 +0,0 @@
12e95e
-# platform = Red Hat Virtualization 4,multi_platform_fedora,multi_platform_rhel,multi_platform_ol,multi_platform_sle
12e95e
-# reboot = false
12e95e
-# strategy = restrict
12e95e
-# complexity = high
12e95e
-# disruption = medium
12e95e
-- name: "Read list of world and group writable files in libraries directories"
12e95e
-  command: "find /lib /lib64 /usr/lib /usr/lib64 -perm /022 -type f"
12e95e
-  register: world_writable_library_files
12e95e
-  changed_when: False
12e95e
-  failed_when: False
12e95e
-  check_mode: no
12e95e
-
12e95e
-- name: "Disable world/group writability to library files"
12e95e
-  file:
12e95e
-    path: "{{ item }}"
12e95e
-    mode: "go-w"
12e95e
-  with_items: "{{ world_writable_library_files.stdout_lines }}"
12e95e
-  when: world_writable_library_files.stdout_lines | length > 0
12e95e
diff --git a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_permissions_library_dirs/bash/shared.sh b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_permissions_library_dirs/bash/shared.sh
12e95e
deleted file mode 100644
12e95e
index af04ad625d3..00000000000
12e95e
--- a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_permissions_library_dirs/bash/shared.sh
12e95e
+++ /dev/null
12e95e
@@ -1,5 +0,0 @@
12e95e
-# platform = multi_platform_all
12e95e
-DIRS="/lib /lib64 /usr/lib /usr/lib64"
12e95e
-for dirPath in $DIRS; do
12e95e
-	find "$dirPath" -perm /022 -type f -exec chmod go-w '{}' \;
12e95e
-done
12e95e
diff --git a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_permissions_library_dirs/oval/shared.xml b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_permissions_library_dirs/oval/shared.xml
12e95e
deleted file mode 100644
12e95e
index f25c52260c4..00000000000
12e95e
--- a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_permissions_library_dirs/oval/shared.xml
12e95e
+++ /dev/null
12e95e
@@ -1,46 +0,0 @@
12e95e
-<def-group>
12e95e
-  <definition class="compliance" id="file_permissions_library_dirs" version="1">
12e95e
-    {{{ oval_metadata("
12e95e
-        Checks that /lib, /lib64, /usr/lib, /usr/lib64, /lib/modules, and
12e95e
-        objects therein, are not group-writable or world-writable.
12e95e
-      ") }}}
12e95e
-    <criteria operator="AND">
12e95e
-      <criterion test_ref="test_perms_lib_dir" />
12e95e
-      <criterion test_ref="test_perms_lib_files" />
12e95e
-    </criteria>
12e95e
-  </definition>
12e95e
-
12e95e
-  <unix:file_test check="all" check_existence="none_exist" comment="library directories go-w" id="test_perms_lib_dir" version="1">
12e95e
-    <unix:object object_ref="object_file_permissions_lib_dir" />
12e95e
-  </unix:file_test>
12e95e
-
12e95e
-  <unix:file_test check="all" check_existence="none_exist" comment="library files go-w" id="test_perms_lib_files" version="1">
12e95e
-    <unix:object object_ref="object_file_permissions_lib_files" />
12e95e
-  </unix:file_test>
12e95e
-
12e95e
-  <unix:file_object comment="library directories" id="object_file_permissions_lib_dir" version="1">
12e95e
-    
12e95e
-    <unix:path operation="pattern match">^\/lib(|64)|^\/usr\/lib(|64)</unix:path>
12e95e
-    <unix:filename xsi:nil="true" />
12e95e
-    <filter action="include">state_perms_nogroupwrite_noworldwrite</filter>
12e95e
-    <filter action="exclude">perms_state_symlink</filter>
12e95e
-  </unix:file_object>
12e95e
-
12e95e
-  <unix:file_object comment="library files" id="object_file_permissions_lib_files" version="1">
12e95e
-    
12e95e
-    <unix:path operation="pattern match">^\/lib(|64)|^\/usr\/lib(|64)</unix:path>
12e95e
-    <unix:filename operation="pattern match">^.*$</unix:filename>
12e95e
-    <filter action="include">state_perms_nogroupwrite_noworldwrite</filter>
12e95e
-    <filter action="exclude">perms_state_symlink</filter>
12e95e
-  </unix:file_object>
12e95e
-
12e95e
-  <unix:file_state id="state_perms_nogroupwrite_noworldwrite" version="1" operator="OR">
12e95e
-    <unix:gwrite datatype="boolean">true</unix:gwrite>
12e95e
-    <unix:owrite datatype="boolean">true</unix:owrite>
12e95e
-  </unix:file_state>
12e95e
-
12e95e
-  <unix:file_state id="perms_state_symlink" version="1">
12e95e
-    <unix:type operation="equals">symbolic link</unix:type>
12e95e
-  </unix:file_state>
12e95e
-
12e95e
-</def-group>
12e95e
diff --git a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_permissions_library_dirs/rule.yml b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_permissions_library_dirs/rule.yml
12e95e
index 9a07e76929e..5a708cf78c3 100644
12e95e
--- a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_permissions_library_dirs/rule.yml
12e95e
+++ b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_permissions_library_dirs/rule.yml
12e95e
@@ -61,3 +61,14 @@ ocil: |-
12e95e
     To find shared libraries that are group-writable or world-writable,
12e95e
     run the following command for each directory DIR which contains shared libraries:
12e95e
     
$ sudo find -L DIR -perm /022 -type f
12e95e
+
12e95e
+template:
12e95e
+    name: file_permissions
12e95e
+    vars:
12e95e
+        filepath:
12e95e
+            - /lib/
12e95e
+            - /lib64/
12e95e
+            - /usr/lib/
12e95e
+            - /usr/lib64/
12e95e
+        file_regex: ^.*$
12e95e
+        filemode: '0755'
12e95e
diff --git a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_permissions_library_dirs/tests/incorrect_permissions.fail.sh b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_permissions_library_dirs/tests/lenient_permissions.fail.sh
12e95e
similarity index 100%
12e95e
rename from linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_permissions_library_dirs/tests/incorrect_permissions.fail.sh
12e95e
rename to linux_os/guide/system/permissions/files/permissions_within_important_dirs/file_permissions_library_dirs/tests/lenient_permissions.fail.sh
12e95e
diff --git a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/root_permissions_syslibrary_files/rule.yml b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/root_permissions_syslibrary_files/rule.yml
12e95e
index eaf04c8d36c..ec135b5279c 100644
12e95e
--- a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/root_permissions_syslibrary_files/rule.yml
12e95e
+++ b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/root_permissions_syslibrary_files/rule.yml
12e95e
@@ -4,7 +4,7 @@ prodtype: fedora,ol8,rhel8,rhel9,sle12,sle15,ubuntu2004
12e95e
 
12e95e
 title: |-
12e95e
     Verify the system-wide library files in directories
12e95e
-    "/lib", "/lib64", "/usr/lib/" and "/usr/lib64" are owned by root.
12e95e
+    "/lib", "/lib64", "/usr/lib/" and "/usr/lib64" are group-owned by root.
12e95e
 
12e95e
 description: |-
12e95e
     System-wide library files are stored in the following directories
12e95e
@@ -15,7 +15,7 @@ description: |-
12e95e
     /usr/lib64
12e95e
     
12e95e
     All system-wide shared library files should be protected from unauthorised
12e95e
-    access. If any of these files is not owned by root, correct its owner with
12e95e
+    access. If any of these files is not group-owned by root, correct its group-owner with
12e95e
     the following command:
12e95e
     
$ sudo chgrp root FILE
12e95e
 
12e95e
@@ -48,7 +48,7 @@ references:
12e95e
     stigid@sle15: SLES-15-010355
12e95e
     stigid@ubuntu2004: UBTU-20-01430
12e95e
 
12e95e
-ocil_clause: 'system wide library files are not group owned by root'
12e95e
+ocil_clause: 'system wide library files are not group-owned by root'
12e95e
 
12e95e
 ocil: |-
12e95e
     System-wide library files are stored in the following directories:
12e95e
diff --git a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/root_permissions_syslibrary_files/tests/correct_groupowner.pass.sh b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/root_permissions_syslibrary_files/tests/correct_groupowner.pass.sh
12e95e
index 0e982c3b8ca..5356d3742d3 100644
12e95e
--- a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/root_permissions_syslibrary_files/tests/correct_groupowner.pass.sh
12e95e
+++ b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/root_permissions_syslibrary_files/tests/correct_groupowner.pass.sh
12e95e
@@ -1,4 +1,4 @@
12e95e
-# platform = multi_platform_sle,Red Hat Enterprise Linux 8,multi_platform_fedora,multi_platform_ubuntu
12e95e
+# platform = multi_platform_sle,multi_platform_rhel,multi_platform_fedora,multi_platform_ubuntu
12e95e
 
12e95e
 for SYSLIBDIRS in /lib /lib64 /usr/lib /usr/lib64
12e95e
 do
12e95e
diff --git a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/root_permissions_syslibrary_files/tests/incorrect_groupowner.fail.sh b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/root_permissions_syslibrary_files/tests/incorrect_groupowner.fail.sh
12e95e
index 23a7703f57d..7352b60aa4b 100644
12e95e
--- a/linux_os/guide/system/permissions/files/permissions_within_important_dirs/root_permissions_syslibrary_files/tests/incorrect_groupowner.fail.sh
12e95e
+++ b/linux_os/guide/system/permissions/files/permissions_within_important_dirs/root_permissions_syslibrary_files/tests/incorrect_groupowner.fail.sh
12e95e
@@ -1,4 +1,4 @@
12e95e
-# platform = multi_platform_sle,Red Hat Enterprise Linux 8,multi_platform_fedora,multi_platform_ubuntu
12e95e
+# platform = multi_platform_sle,multi_platform_rhel,multi_platform_fedora,multi_platform_ubuntu
12e95e
 
12e95e
 groupadd group_test
12e95e
 for TESTFILE in /lib/test_me /lib64/test_me /usr/lib/test_me /usr/lib64/test_me
12e95e
diff --git a/products/rhel8/profiles/stig.profile b/products/rhel8/profiles/stig.profile
12e95e
index ff23f83cfbf..88b3a7e3783 100644
12e95e
--- a/products/rhel8/profiles/stig.profile
12e95e
+++ b/products/rhel8/profiles/stig.profile
12e95e
@@ -235,8 +235,13 @@ selections:
12e95e
     # RHEL-08-010340
12e95e
     - file_ownership_library_dirs
12e95e
 
12e95e
+    # RHEL-08-010341
12e95e
+    - dir_ownership_library_dirs
12e95e
+
12e95e
     # RHEL-08-010350
12e95e
     - root_permissions_syslibrary_files
12e95e
+
12e95e
+    # RHEL-08-010351
12e95e
     - dir_group_ownership_library_dirs
12e95e
 
12e95e
     # RHEL-08-010360
12e95e
diff --git a/products/rhel9/profiles/stig.profile b/products/rhel9/profiles/stig.profile
12e95e
index 8cc6d132591..65465be2c07 100644
12e95e
--- a/products/rhel9/profiles/stig.profile
12e95e
+++ b/products/rhel9/profiles/stig.profile
12e95e
@@ -236,8 +236,13 @@ selections:
12e95e
     # RHEL-08-010340
12e95e
     - file_ownership_library_dirs
12e95e
 
12e95e
+    # RHEL-08-010341
12e95e
+    - dir_ownership_library_dirs
12e95e
+
12e95e
     # RHEL-08-010350
12e95e
     - root_permissions_syslibrary_files
12e95e
+
12e95e
+    # RHEL-08-010351
12e95e
     - dir_group_ownership_library_dirs
12e95e
 
12e95e
     # RHEL-08-010360
12e95e
diff --git a/shared/references/cce-redhat-avail.txt b/shared/references/cce-redhat-avail.txt
12e95e
index 8aad24b20f7..eb3f17f4f3d 100644
12e95e
--- a/shared/references/cce-redhat-avail.txt
12e95e
+++ b/shared/references/cce-redhat-avail.txt
12e95e
@@ -2957,8 +2957,6 @@ CCE-89017-8
12e95e
 CCE-89018-6
12e95e
 CCE-89019-4
12e95e
 CCE-89020-2
12e95e
-CCE-89021-0
12e95e
-CCE-89022-8
12e95e
 CCE-89023-6
12e95e
 CCE-89024-4
12e95e
 CCE-89025-1
12e95e
diff --git a/shared/templates/file_groupowner/ansible.template b/shared/templates/file_groupowner/ansible.template
12e95e
index 68fc2e1e17e..0b4ab594155 100644
12e95e
--- a/shared/templates/file_groupowner/ansible.template
12e95e
+++ b/shared/templates/file_groupowner/ansible.template
12e95e
@@ -12,6 +12,7 @@
12e95e
     paths: "{{{ path }}}"
12e95e
     patterns: {{{ FILE_REGEX[loop.index0] }}}
12e95e
     use_regex: yes
12e95e
+    hidden: yes
12e95e
   register: files_found
12e95e
 
12e95e
 - name: Ensure group owner on {{{ path }}} file(s) matching {{{ FILE_REGEX[loop.index0] }}}
12e95e
diff --git a/shared/templates/file_groupowner/oval.template b/shared/templates/file_groupowner/oval.template
12e95e
index fd2e5db5d93..64a494471a8 100644
12e95e
--- a/shared/templates/file_groupowner/oval.template
12e95e
+++ b/shared/templates/file_groupowner/oval.template
12e95e
@@ -45,6 +45,10 @@
12e95e
     {{%- else %}}
12e95e
       <unix:filepath{{% if FILEPATH_IS_REGEX %}} operation="pattern match"{{% endif %}}>{{{ filepath }}}</unix:filepath>
12e95e
     {{%- endif %}}
12e95e
+    <filter action="exclude">symlink_file_groupowner{{{ FILEID }}}_uid_{{{ FILEGID }}}</filter>
12e95e
   </unix:file_object>
12e95e
   {{% endfor %}}
12e95e
+  <unix:file_state id="symlink_file_groupowner{{{ FILEID }}}_uid_{{{ FILEGID }}}" version="1">
12e95e
+    <unix:type operation="equals">symbolic link</unix:type>
12e95e
+  </unix:file_state>
12e95e
 </def-group>
12e95e
diff --git a/shared/templates/file_owner/ansible.template b/shared/templates/file_owner/ansible.template
12e95e
index 590c9fc6055..dba9e65a277 100644
12e95e
--- a/shared/templates/file_owner/ansible.template
12e95e
+++ b/shared/templates/file_owner/ansible.template
12e95e
@@ -12,6 +12,7 @@
12e95e
     paths: "{{{ path }}}"
12e95e
     patterns: {{{ FILE_REGEX[loop.index0] }}}
12e95e
     use_regex: yes
12e95e
+    hidden: yes
12e95e
   register: files_found
12e95e
 
12e95e
 - name: Ensure group owner on {{{ path }}} file(s) matching {{{ FILE_REGEX[loop.index0] }}}
12e95e
diff --git a/shared/templates/file_owner/oval.template b/shared/templates/file_owner/oval.template
12e95e
index 105e29c81c8..777831d790d 100644
12e95e
--- a/shared/templates/file_owner/oval.template
12e95e
+++ b/shared/templates/file_owner/oval.template
12e95e
@@ -44,6 +44,10 @@
12e95e
     {{%- else %}}
12e95e
       <unix:filepath{{% if FILEPATH_IS_REGEX %}} operation="pattern match"{{% endif %}}>{{{ filepath }}}</unix:filepath>
12e95e
     {{%- endif %}}
12e95e
+    <filter action="exclude">symlink_file_owner{{{ FILEID }}}_uid_{{{ FILEUID }}}</filter>
12e95e
   </unix:file_object>
12e95e
   {{% endfor %}}
12e95e
+  <unix:file_state id="symlink_file_owner{{{ FILEID }}}_uid_{{{ FILEUID }}}" version="1">
12e95e
+    <unix:type operation="equals">symbolic link</unix:type>
12e95e
+  </unix:file_state>
12e95e
 </def-group>
12e95e
diff --git a/shared/templates/file_permissions/ansible.template b/shared/templates/file_permissions/ansible.template
12e95e
index fc211bdc4c3..6d4dedcee51 100644
12e95e
--- a/shared/templates/file_permissions/ansible.template
12e95e
+++ b/shared/templates/file_permissions/ansible.template
12e95e
@@ -12,6 +12,7 @@
12e95e
     paths: "{{{ path }}}"
12e95e
     patterns: {{{ FILE_REGEX[loop.index0] }}}
12e95e
     use_regex: yes
12e95e
+    hidden: yes
12e95e
   register: files_found
12e95e
 
12e95e
 - name: Set permissions for {{{ path }}} file(s)
12e95e
diff --git a/tests/data/profile_stability/rhel8/stig.profile b/tests/data/profile_stability/rhel8/stig.profile
12e95e
index b5621425b96..c5a9b6a32ad 100644
12e95e
--- a/tests/data/profile_stability/rhel8/stig.profile
12e95e
+++ b/tests/data/profile_stability/rhel8/stig.profile
12e95e
@@ -181,6 +181,7 @@ selections:
12e95e
 - dconf_gnome_screensaver_idle_delay
12e95e
 - dconf_gnome_screensaver_lock_enabled
12e95e
 - dir_group_ownership_library_dirs
12e95e
+- dir_ownership_library_dirs
12e95e
 - dir_permissions_library_dirs
12e95e
 - dir_perms_world_writable_root_owned
12e95e
 - dir_perms_world_writable_sticky_bits
12e95e
diff --git a/tests/data/profile_stability/rhel8/stig_gui.profile b/tests/data/profile_stability/rhel8/stig_gui.profile
12e95e
index 31221ed632c..32d195e28aa 100644
12e95e
--- a/tests/data/profile_stability/rhel8/stig_gui.profile
12e95e
+++ b/tests/data/profile_stability/rhel8/stig_gui.profile
12e95e
@@ -192,6 +192,7 @@ selections:
12e95e
 - dconf_gnome_screensaver_idle_delay
12e95e
 - dconf_gnome_screensaver_lock_enabled
12e95e
 - dir_group_ownership_library_dirs
12e95e
+- dir_ownership_library_dirs
12e95e
 - dir_permissions_library_dirs
12e95e
 - dir_perms_world_writable_root_owned
12e95e
 - dir_perms_world_writable_sticky_bits