[Apollo] Advisories Statistics light light Login

RLBA-2023:0829

Bug Fix Mirrored from RHBA-2023:0829
Issued at: 2023-02-22
Updated at: 2023-02-22

Synopsis

scap-security-guide bug fix and enhancement update



Description

The scap-security-guide project provides a guide for configuration of the system from the final system's security point of view. The guidance is specified in the

Security Content Automation Protocol (SCAP) format and constitutes a catalog of practical hardening advice, linked to government requirements where applicable.

The project bridges the gap between generalized policy requirements and specific implementation guidelines.

Bug Fix(es) and Enhancement(s):

* [SCAP] PCI-DSS Rsyslog log files related rules fails for Rsyslog 8 RainerScript syntax (BZ#2168050)

* DISA STIG: SCAP kerberos related findings after realm join (BZ#2168054)

* file_permissions_sshd_private_key is not aligned with DISA STIG benchmark (BZ#2168057)

* audit_rules_usergroup_modification_shadow don't remediate existing audit rule (BZ#2168060)

* Rules concerning audit check for content of specific files, and not /etc/audit/audit.rules ( ex xccdf_org.ssgproject.content_rule_audit_immutable_login_uids) (BZ#2168063)

* The stig rule xccdf_org.ssgproject.content_rule_sudo_require_reauthentication fails due to space in in the "timestamp_timeout" value (BZ#2168066)

* Some rules have proper STIG references but they are not part of STIG profile (BZ#2168069)

* Two CIS Level 2 Benchmarks are listed in scap-security-guide under CIS Level 1 Profile (BZ#2168072)

* Update Rocky Linux8 DISA STIG profile to V1R9 (BZ#2168075)

* Rebase SSG to the latest upstream version in Rocky Linux 8.8 (BZ#2168079)



Affected products

Rocky Linux 8 aarch64 Rocky Linux 8 x86_64

Fixes

2168050 2168054 2168057 2168060 2168063 2168066 2168069 2168072 2168075 2168079

CVEs

Affected packages

Rocky Linux 8 x86_64 - AppStream

scap-security-guide-0:0.1.66-2.el8_7.rocky.0.1.noarch.rpm scap-security-guide-0:0.1.66-2.el8_7.rocky.0.1.src.rpm scap-security-guide-doc-0:0.1.66-2.el8_7.rocky.0.1.noarch.rpm

Rocky Linux 8 aarch64 - AppStream

scap-security-guide-0:0.1.66-2.el8_7.rocky.0.1.noarch.rpm scap-security-guide-0:0.1.66-2.el8_7.rocky.0.1.src.rpm scap-security-guide-doc-0:0.1.66-2.el8_7.rocky.0.1.noarch.rpm