Blame SOURCES/scap-security-guide-0.1.66-map_stig_rhel_08_040400-PR_9878.patch

f6303c
From fae75e8f00cf5de18c4c1813d94987e848f14233 Mon Sep 17 00:00:00 2001
f6303c
From: Watson Sato <wsato@redhat.com>
f6303c
Date: Thu, 24 Nov 2022 14:40:15 +0100
f6303c
Subject: [PATCH] Map selinux_user_login_roles to RHEL-08-040400
f6303c
f6303c
This STIG ID is a new addition in DISA RHEL8 STIG V1R8
f6303c
---
f6303c
 .../guide/system/selinux/selinux_user_login_roles/rule.yml     | 2 ++
f6303c
 products/rhel8/profiles/stig.profile                           | 3 +++
f6303c
 shared/references/cce-redhat-avail.txt                         | 1 -
f6303c
 tests/data/profile_stability/rhel8/stig.profile                | 1 +
f6303c
 tests/data/profile_stability/rhel8/stig_gui.profile            | 1 +
f6303c
 5 files changed, 7 insertions(+), 1 deletion(-)
f6303c
f6303c
diff --git a/linux_os/guide/system/selinux/selinux_user_login_roles/rule.yml b/linux_os/guide/system/selinux/selinux_user_login_roles/rule.yml
f6303c
index 053d4341bbd..d4c211c1062 100644
f6303c
--- a/linux_os/guide/system/selinux/selinux_user_login_roles/rule.yml
f6303c
+++ b/linux_os/guide/system/selinux/selinux_user_login_roles/rule.yml
f6303c
@@ -34,6 +34,7 @@ severity: medium
f6303c
 
f6303c
 identifiers:
f6303c
     cce@rhel7: CCE-80543-2
f6303c
+    cce@rhel8: CCE-86353-0
f6303c
 
f6303c
 references:
f6303c
     disa: CCI-002165,CCI-002235
f6303c
@@ -41,6 +42,7 @@ references:
f6303c
     stigid@ol7: OL07-00-020020
f6303c
     stigid@ol8: OL08-00-040400
f6303c
     stigid@rhel7: RHEL-07-020020
f6303c
+    stigid@rhel8: RHEL-08-040400
f6303c
 
f6303c
 ocil_clause: 'non-admin users are not confined correctly'
f6303c
 
f6303c
diff --git a/products/rhel8/profiles/stig.profile b/products/rhel8/profiles/stig.profile
f6303c
index d184957f28c..fe699f34beb 100644
f6303c
--- a/products/rhel8/profiles/stig.profile
f6303c
+++ b/products/rhel8/profiles/stig.profile
f6303c
@@ -1207,5 +1207,8 @@ selections:
f6303c
     # RHEL-08-040390
f6303c
     - package_tuned_removed
f6303c
 
f6303c
+    # RHEL-08-040400
f6303c
+    - selinux_user_login_roles
f6303c
+
f6303c
     # RHEL-08-010163
f6303c
     - package_krb5-server_removed
f6303c
diff --git a/shared/references/cce-redhat-avail.txt b/shared/references/cce-redhat-avail.txt
f6303c
index d2fcd6421e1..9575ecac8c9 100644
f6303c
--- a/shared/references/cce-redhat-avail.txt
f6303c
+++ b/shared/references/cce-redhat-avail.txt
f6303c
@@ -210,7 +210,6 @@ CCE-86343-1
f6303c
 CCE-86347-2
f6303c
 CCE-86351-4
f6303c
 CCE-86352-2
f6303c
-CCE-86353-0
f6303c
 CCE-86355-5
f6303c
 CCE-86357-1
f6303c
 CCE-86358-9
f6303c
diff --git a/tests/data/profile_stability/rhel8/stig.profile b/tests/data/profile_stability/rhel8/stig.profile
f6303c
index 51971451996..6ddf29e7bfe 100644
f6303c
--- a/tests/data/profile_stability/rhel8/stig.profile
f6303c
+++ b/tests/data/profile_stability/rhel8/stig.profile
f6303c
@@ -343,6 +343,7 @@ selections:
f6303c
 - security_patches_up_to_date
f6303c
 - selinux_policytype
f6303c
 - selinux_state
f6303c
+- selinux_user_login_roles
f6303c
 - service_auditd_enabled
f6303c
 - service_autofs_disabled
f6303c
 - service_debug-shell_disabled
f6303c
diff --git a/tests/data/profile_stability/rhel8/stig_gui.profile b/tests/data/profile_stability/rhel8/stig_gui.profile
f6303c
index fd150744167..fb8f5602dac 100644
f6303c
--- a/tests/data/profile_stability/rhel8/stig_gui.profile
f6303c
+++ b/tests/data/profile_stability/rhel8/stig_gui.profile
f6303c
@@ -353,6 +353,7 @@ selections:
f6303c
 - security_patches_up_to_date
f6303c
 - selinux_policytype
f6303c
 - selinux_state
f6303c
+- selinux_user_login_roles
f6303c
 - service_auditd_enabled
f6303c
 - service_autofs_disabled
f6303c
 - service_debug-shell_disabled