diff --git a/tests/data/product_stability/al2023.yml b/tests/data/product_stability/al2023.yml new file mode 100644 index 000000000000..6075a24a1583 --- /dev/null +++ b/tests/data/product_stability/al2023.yml @@ -0,0 +1,83 @@ +aide_also_checks_audispd: 'yes' +aide_also_checks_rsyslog: 'no' +aide_bin_path: /usr/sbin/aide +aide_conf_path: /etc/aide.conf +audisp_conf_path: /etc/audit +auid: 1000 +basic_properties_derived: true +benchmark_id: AL-2023 +benchmark_root: ../../linux_os/guide +chrony_conf_path: /etc/chrony.conf +chrony_d_path: /etc/chrony.d/ +components_root: ../../components +cpes: +- al2023: + check_id: installed_OS_is_al2023 + name: cpe:/o:amazon:amazon_linux:2023 + title: Amazon Linux 2023 +cpes_root: ../../shared/applicability +dconf_gdm_dir: gdm.d +faillock_path: /var/log/faillock +full_name: Amazon Linux 2023 +gid_min: 1000 +groups: + dedicated_ssh_keyowner: + name: ssh_keys +grub2_boot_path: /boot/grub2 +grub2_uefi_boot_path: /boot/grub2 +grub_helper_executable: grubby +init_system: systemd +journald_conf_dir_path: /etc/systemd/journald.conf.d +nobody_gid: 65534 +nobody_uid: 65534 +pkg_manager: dnf +pkg_manager_config_file: /etc/dnf/dnf.conf +pkg_system: rpm +platform_package_overrides: + aarch64_arch: null + grub2: grub2-common + login_defs: shadow-utils + no_ovirt: null + non-uefi: null + not_aarch64_arch: null + not_s390x_arch: null + ovirt: null + s390x_arch: null + sssd: sssd-common + sssd-ldap: null + uefi: null + zipl: s390utils-base +product: al2023 +profiles_root: ./profiles +reference_uris: + anssi: https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf + app-srg: https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=application-servers + app-srg-ctr: https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=container-platform + bsi: https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Grundschutz/International/bsi_it_gs_comp_2022.pdf + cis: https://www.cisecurity.org/benchmark/amazon_linux/ + cis-csc: https://www.cisecurity.org/controls/ + cjis: https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf + cobit5: https://www.isaca.org/resources/cobit + cui: http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf + dcid: not_officially_available + disa: https://public.cyber.mil/stigs/cci/ + hipaa: https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf + isa-62443-2009: https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat + isa-62443-2013: https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu + ism: https://www.cyber.gov.au/acsc/view-all-content/ism + iso27001-2013: https://www.iso.org/contents/data/standard/05/45/54534.html + nerc-cip: https://www.nerc.com/pa/Stand/Standard%20Purpose%20Statement%20DL/US_Standard_One-Stop-Shop.xlsx + nist: http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf + nist-csf: https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf + os-srg: https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os + ospp: https://www.niap-ccevs.org/Profile/PP.cfm + pcidss: https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf + pcidss4: https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf + stigid: https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux + stigref: https://public.cyber.mil/stigs/srg-stig-tools/ +release_key_fingerprint: B21C50FA44A99720EAA72F7FE951904AD832C631 +sshd_distributed_config: 'true' +sysctl_remediate_drop_in_file: 'false' +type: platform +uid_max: 60000 +uid_min: 1000 diff --git a/tests/data/product_stability/alinux2.yml b/tests/data/product_stability/alinux2.yml index 39d49e6b72f9..fac612e6d87b 100644 --- a/tests/data/product_stability/alinux2.yml +++ b/tests/data/product_stability/alinux2.yml @@ -73,4 +73,5 @@ reference_uris: sshd_distributed_config: 'false' sysctl_remediate_drop_in_file: 'false' type: platform +uid_max: 60000 uid_min: 1000 diff --git a/tests/data/product_stability/alinux3.yml b/tests/data/product_stability/alinux3.yml index cde45fb3c1ab..a15170b6fbe0 100644 --- a/tests/data/product_stability/alinux3.yml +++ b/tests/data/product_stability/alinux3.yml @@ -73,4 +73,5 @@ reference_uris: sshd_distributed_config: 'false' sysctl_remediate_drop_in_file: 'false' type: platform +uid_max: 60000 uid_min: 1000 diff --git a/tests/data/product_stability/anolis23.yml b/tests/data/product_stability/anolis23.yml index 01edaa2bfc12..095c2560a2c5 100644 --- a/tests/data/product_stability/anolis23.yml +++ b/tests/data/product_stability/anolis23.yml @@ -73,4 +73,5 @@ reference_uris: sshd_distributed_config: 'false' sysctl_remediate_drop_in_file: 'false' type: platform +uid_max: 60000 uid_min: 1000 diff --git a/tests/data/product_stability/anolis8.yml b/tests/data/product_stability/anolis8.yml index dd0abda59d40..e2e86819775a 100644 --- a/tests/data/product_stability/anolis8.yml +++ b/tests/data/product_stability/anolis8.yml @@ -73,4 +73,5 @@ reference_uris: sshd_distributed_config: 'false' sysctl_remediate_drop_in_file: 'false' type: platform +uid_max: 60000 uid_min: 1000 diff --git a/tests/data/product_stability/chromium.yml b/tests/data/product_stability/chromium.yml index 259552fbfe2b..31f77c3185c4 100644 --- a/tests/data/product_stability/chromium.yml +++ b/tests/data/product_stability/chromium.yml @@ -69,4 +69,5 @@ reference_uris: sshd_distributed_config: 'false' sysctl_remediate_drop_in_file: 'false' type: product +uid_max: 60000 uid_min: 1000 diff --git a/tests/data/product_stability/debian11.yml b/tests/data/product_stability/debian11.yml index 4c8d64ee5766..8fe3c7626ccb 100644 --- a/tests/data/product_stability/debian11.yml +++ b/tests/data/product_stability/debian11.yml @@ -82,4 +82,5 @@ reference_uris: sshd_distributed_config: 'false' sysctl_remediate_drop_in_file: 'false' type: platform +uid_max: 60000 uid_min: 1000 diff --git a/tests/data/product_stability/debian12.yml b/tests/data/product_stability/debian12.yml index 102330d6e2b6..22e83d45d43f 100644 --- a/tests/data/product_stability/debian12.yml +++ b/tests/data/product_stability/debian12.yml @@ -82,4 +82,5 @@ reference_uris: sshd_distributed_config: 'false' sysctl_remediate_drop_in_file: 'false' type: platform +uid_max: 60000 uid_min: 1000 diff --git a/tests/data/product_stability/eks.yml b/tests/data/product_stability/eks.yml index 135023ebf436..815cabc5b0ba 100644 --- a/tests/data/product_stability/eks.yml +++ b/tests/data/product_stability/eks.yml @@ -80,4 +80,5 @@ reference_uris: sshd_distributed_config: 'false' sysctl_remediate_drop_in_file: 'false' type: platform +uid_max: 60000 uid_min: 1000 diff --git a/tests/data/product_stability/example.yml b/tests/data/product_stability/example.yml index f20e554e6dec..79cb79985ab7 100644 --- a/tests/data/product_stability/example.yml +++ b/tests/data/product_stability/example.yml @@ -74,4 +74,5 @@ reference_uris: sshd_distributed_config: 'false' sysctl_remediate_drop_in_file: 'false' type: platform +uid_max: 60000 uid_min: 1000 diff --git a/tests/data/product_stability/fedora.yml b/tests/data/product_stability/fedora.yml index 214cf9a8abf8..627f8d147b39 100644 --- a/tests/data/product_stability/fedora.yml +++ b/tests/data/product_stability/fedora.yml @@ -117,4 +117,5 @@ reference_uris: sshd_distributed_config: 'true' sysctl_remediate_drop_in_file: 'false' type: platform +uid_max: 60000 uid_min: 1000 diff --git a/tests/data/product_stability/firefox.yml b/tests/data/product_stability/firefox.yml index 562f3c85a880..4cf157dc457d 100644 --- a/tests/data/product_stability/firefox.yml +++ b/tests/data/product_stability/firefox.yml @@ -69,4 +69,5 @@ reference_uris: sshd_distributed_config: 'false' sysctl_remediate_drop_in_file: 'false' type: product +uid_max: 60000 uid_min: 1000 diff --git a/tests/data/product_stability/kylinserver10.yml b/tests/data/product_stability/kylinserver10.yml new file mode 100644 index 000000000000..899ca6513f3e --- /dev/null +++ b/tests/data/product_stability/kylinserver10.yml @@ -0,0 +1,85 @@ +aide_also_checks_audispd: 'yes' +aide_also_checks_rsyslog: 'no' +aide_bin_path: /usr/sbin/aide +aide_conf_path: /etc/aide.conf +audisp_conf_path: /etc/audit +auid: 1000 +basic_properties_derived: true +benchmark_id: KYLINSERVER10 +benchmark_root: ../../linux_os/guide +chrony_conf_path: /etc/chrony.conf +chrony_d_path: /etc/chrony.d/ +cpes: +- kylin-sp1: + check_id: installed_OS_is_kylinserver10 + name: cpe:/o:Kylin:Kylin:V10_SP1:ga:server + title: Kylin V10 SP1 +- kylin-sp2: + check_id: installed_OS_is_kylinserver10 + name: cpe:/o:Kylin:Kylin:V10_SP2:ga:server + title: Kylin V10 SP2 +- kylin-sp3: + check_id: installed_OS_is_kylinserver10 + name: cpe:/o:Kylin:Kylin:V10_SP3:ga:server + title: Kylin V10 SP3 +cpes_root: ../../shared/applicability +dconf_gdm_dir: gdm.d +faillock_path: /var/run/faillock +full_name: Kylin Server 10 +gid_min: 1000 +groups: {} +grub2_boot_path: /boot/grub2 +grub2_uefi_boot_path: /boot/grub2 +grub_helper_executable: grubby +init_system: systemd +nobody_gid: 65534 +nobody_uid: 65534 +pkg_manager: dnf +pkg_manager_config_file: /etc/yum.conf +pkg_system: rpm +platform_package_overrides: + aarch64_arch: null + grub2: grub2-common + login_defs: login + no_ovirt: null + non-uefi: null + not_aarch64_arch: null + not_s390x_arch: null + ovirt: null + s390x_arch: null + sssd: sssd-common + sssd-ldap: null + uefi: null + zipl: s390utils-base +product: kylinserver10 +profiles_root: ./profiles +reference_uris: + anssi: https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf + app-srg: https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=application-servers + app-srg-ctr: https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=container-platform + bsi: https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Grundschutz/International/bsi_it_gs_comp_2022.pdf + cis-csc: https://www.cisecurity.org/controls/ + cjis: https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf + cobit5: https://www.isaca.org/resources/cobit + cui: http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf + dcid: not_officially_available + disa: https://public.cyber.mil/stigs/cci/ + hipaa: https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf + isa-62443-2009: https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat + isa-62443-2013: https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu + ism: https://www.cyber.gov.au/acsc/view-all-content/ism + iso27001-2013: https://www.iso.org/contents/data/standard/05/45/54534.html + nerc-cip: https://www.nerc.com/pa/Stand/Standard%20Purpose%20Statement%20DL/US_Standard_One-Stop-Shop.xlsx + nist: http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf + nist-csf: https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf + os-srg: https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os + ospp: https://www.niap-ccevs.org/Profile/PP.cfm + pcidss: https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf + pcidss4: https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf + stigid: https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux + stigref: https://public.cyber.mil/stigs/srg-stig-tools/ +sshd_distributed_config: 'false' +sysctl_remediate_drop_in_file: 'false' +type: platform +uid_max: 60000 +uid_min: 1000 diff --git a/tests/data/product_stability/macos1015.yml b/tests/data/product_stability/macos1015.yml index 0124fed6df5e..7e966955128f 100644 --- a/tests/data/product_stability/macos1015.yml +++ b/tests/data/product_stability/macos1015.yml @@ -69,4 +69,5 @@ reference_uris: sshd_distributed_config: 'false' sysctl_remediate_drop_in_file: 'false' type: platform +uid_max: 60000 uid_min: 1000 diff --git a/tests/data/product_stability/ocp4.yml b/tests/data/product_stability/ocp4.yml index 75c8888648a1..fb57c0e0ee5d 100644 --- a/tests/data/product_stability/ocp4.yml +++ b/tests/data/product_stability/ocp4.yml @@ -156,4 +156,5 @@ reference_uris: sshd_distributed_config: 'false' sysctl_remediate_drop_in_file: 'false' type: platform +uid_max: 60000 uid_min: 1000 diff --git a/tests/data/product_stability/ol10.yml b/tests/data/product_stability/ol10.yml new file mode 100644 index 000000000000..eac6894b90d5 --- /dev/null +++ b/tests/data/product_stability/ol10.yml @@ -0,0 +1,89 @@ +aide_also_checks_audispd: 'yes' +aide_also_checks_rsyslog: 'no' +aide_bin_path: /usr/sbin/aide +aide_conf_path: /etc/aide.conf +audisp_conf_path: /etc/audit +auid: 1000 +aux_pkg_release: '' +aux_pkg_version: '' +auxiliary_key_fingerprint: '' +basic_properties_derived: true +benchmark_id: OL-10 +benchmark_root: ../../linux_os/guide +chrony_conf_path: /etc/chrony.conf +chrony_d_path: /etc/chrony.d/ +cpes: +- ol10: + check_id: installed_OS_is_ol10 + name: cpe:/o:oracle:linux:10 + title: Oracle Linux 10 +cpes_root: ../../shared/applicability +dconf_gdm_dir: local.d +faillock_path: /var/log/faillock +families: +- ol +full_name: Oracle Linux 10 +gid_min: 1000 +groups: + dedicated_ssh_keyowner: + name: ssh_keys +grub2_boot_path: /boot/grub2 +grub2_uefi_boot_path: /boot/grub2 +grub_helper_executable: grubby +init_system: systemd +major_version_ordinal: 10 +nobody_gid: 65534 +nobody_uid: 65534 +pkg_manager: dnf +pkg_manager_config_file: /etc/dnf/dnf.conf +pkg_release: '' +pkg_system: rpm +pkg_version: '' +platform_package_overrides: + aarch64_arch: null + grub2: grub2-common + login_defs: shadow-utils + no_ovirt: null + non-uefi: null + not_aarch64_arch: null + not_s390x_arch: null + ovirt: null + s390x_arch: null + sssd: sssd-common + sssd-ldap: null + uefi: null + zipl: s390utils-base +product: ol10 +profiles_root: ./profiles +reference_uris: + anssi: https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf + app-srg: https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=application-servers + app-srg-ctr: https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=container-platform + bsi: https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Grundschutz/International/bsi_it_gs_comp_2022.pdf + cis: '' + cis-csc: https://www.cisecurity.org/controls/ + cjis: https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf + cobit5: https://www.isaca.org/resources/cobit + cui: http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf + dcid: not_officially_available + disa: https://public.cyber.mil/stigs/cci/ + hipaa: https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf + isa-62443-2009: https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat + isa-62443-2013: https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu + ism: https://www.cyber.gov.au/acsc/view-all-content/ism + iso27001-2013: https://www.iso.org/contents/data/standard/05/45/54534.html + nerc-cip: https://www.nerc.com/pa/Stand/Standard%20Purpose%20Statement%20DL/US_Standard_One-Stop-Shop.xlsx + nist: http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf + nist-csf: https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf + os-srg: https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os + ospp: https://www.niap-ccevs.org/Profile/PP.cfm + pcidss: https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf + pcidss4: https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf + stigid: https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux + stigref: https://public.cyber.mil/stigs/srg-stig-tools/ +release_key_fingerprint: '' +sshd_distributed_config: 'false' +sysctl_remediate_drop_in_file: 'false' +type: platform +uid_max: 60000 +uid_min: 1000 diff --git a/tests/data/product_stability/ol7.yml b/tests/data/product_stability/ol7.yml index 617a8f908ccc..7eb418c5aa12 100644 --- a/tests/data/product_stability/ol7.yml +++ b/tests/data/product_stability/ol7.yml @@ -85,4 +85,5 @@ release_key_fingerprint: 42144123FECFC55B9086313D72F97B74EC551F03 sshd_distributed_config: 'false' sysctl_remediate_drop_in_file: 'false' type: platform +uid_max: 60000 uid_min: 1000 diff --git a/tests/data/product_stability/ol8.yml b/tests/data/product_stability/ol8.yml index 955a324cc735..27a41c298999 100644 --- a/tests/data/product_stability/ol8.yml +++ b/tests/data/product_stability/ol8.yml @@ -84,4 +84,5 @@ release_key_fingerprint: 76FD3DB13AB67410B89DB10E82562EA9AD986DA3 sshd_distributed_config: 'false' sysctl_remediate_drop_in_file: 'false' type: platform +uid_max: 60000 uid_min: 1000 diff --git a/tests/data/product_stability/ol9.yml b/tests/data/product_stability/ol9.yml index 34985b56c43e..b8b979b5ab82 100644 --- a/tests/data/product_stability/ol9.yml +++ b/tests/data/product_stability/ol9.yml @@ -87,4 +87,5 @@ release_key_fingerprint: 3E6D826D3FBAB389C2F38E34BC4D06A08D8B756F sshd_distributed_config: 'false' sysctl_remediate_drop_in_file: 'false' type: platform +uid_max: 60000 uid_min: 1000 diff --git a/tests/data/product_stability/openembedded.yml b/tests/data/product_stability/openembedded.yml index 72e643c41ede..6e895ad4e2e1 100644 --- a/tests/data/product_stability/openembedded.yml +++ b/tests/data/product_stability/openembedded.yml @@ -85,4 +85,5 @@ reference_uris: sshd_distributed_config: 'false' sysctl_remediate_drop_in_file: 'false' type: platform +uid_max: 60000 uid_min: 1000 diff --git a/tests/data/product_stability/openeuler2203.yml b/tests/data/product_stability/openeuler2203.yml new file mode 100644 index 000000000000..c9bed2beee7e --- /dev/null +++ b/tests/data/product_stability/openeuler2203.yml @@ -0,0 +1,85 @@ +aide_also_checks_audispd: 'yes' +aide_also_checks_rsyslog: 'no' +aide_bin_path: /usr/sbin/aide +aide_conf_path: /etc/aide.conf +audisp_conf_path: /etc/audit +auid: 1000 +basic_properties_derived: true +benchmark_id: OPENEULER2203 +benchmark_root: ../../linux_os/guide +chrony_conf_path: /etc/chrony.conf +chrony_d_path: /etc/chrony.d/ +cpes: +- openeuler2203lts: + check_id: installed_OS_is_openeuler2203 + name: cpe:/o:openEuler:openEuler:22.03LTS:ga:server + title: openEuler 22.03 LTS +- openeuler2203lts-sp1: + check_id: installed_OS_is_openeuler2203 + name: cpe:/o:openEuler:openEuler:22.03LTS_SP1:ga:server + title: openEuler 22.03 LTS SP1 +- openeuler2203lts-sp2: + check_id: installed_OS_is_openeuler2203 + name: cpe:/o:openEuler:openEuler:22.03LTS_SP2:ga:server + title: openEuler 22.03 LTS SP2 +cpes_root: ../../shared/applicability +dconf_gdm_dir: gdm.d +faillock_path: /var/run/faillock +full_name: openEuler 2203 +gid_min: 1000 +groups: {} +grub2_boot_path: /boot/grub2 +grub2_uefi_boot_path: /boot/grub2 +grub_helper_executable: grubby +init_system: systemd +nobody_gid: 65534 +nobody_uid: 65534 +pkg_manager: dnf +pkg_manager_config_file: /etc/yum.conf +pkg_system: rpm +platform_package_overrides: + aarch64_arch: null + grub2: grub2-common + login_defs: login + no_ovirt: null + non-uefi: null + not_aarch64_arch: null + not_s390x_arch: null + ovirt: null + s390x_arch: null + sssd: sssd-common + sssd-ldap: null + uefi: null + zipl: s390utils-base +product: openeuler2203 +profiles_root: ./profiles +reference_uris: + anssi: https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf + app-srg: https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=application-servers + app-srg-ctr: https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=container-platform + bsi: https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Grundschutz/International/bsi_it_gs_comp_2022.pdf + cis-csc: https://www.cisecurity.org/controls/ + cjis: https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf + cobit5: https://www.isaca.org/resources/cobit + cui: http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf + dcid: not_officially_available + disa: https://public.cyber.mil/stigs/cci/ + hipaa: https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf + isa-62443-2009: https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat + isa-62443-2013: https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu + ism: https://www.cyber.gov.au/acsc/view-all-content/ism + iso27001-2013: https://www.iso.org/contents/data/standard/05/45/54534.html + nerc-cip: https://www.nerc.com/pa/Stand/Standard%20Purpose%20Statement%20DL/US_Standard_One-Stop-Shop.xlsx + nist: http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf + nist-csf: https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf + os-srg: https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os + ospp: https://www.niap-ccevs.org/Profile/PP.cfm + pcidss: https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf + pcidss4: https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf + stigid: https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux + stigref: https://public.cyber.mil/stigs/srg-stig-tools/ +sshd_distributed_config: 'false' +sysctl_remediate_drop_in_file: 'false' +type: platform +uid_max: 60000 +uid_min: 1000 diff --git a/tests/data/product_stability/opensuse.yml b/tests/data/product_stability/opensuse.yml index c7214c7d51a2..981912c9c8a7 100644 --- a/tests/data/product_stability/opensuse.yml +++ b/tests/data/product_stability/opensuse.yml @@ -85,4 +85,5 @@ reference_uris: sshd_distributed_config: 'false' sysctl_remediate_drop_in_file: 'false' type: platform +uid_max: 60000 uid_min: 1000 diff --git a/tests/data/product_stability/rhcos4.yml b/tests/data/product_stability/rhcos4.yml index 4f242c6f2f88..ea2c277109ef 100644 --- a/tests/data/product_stability/rhcos4.yml +++ b/tests/data/product_stability/rhcos4.yml @@ -78,4 +78,5 @@ release_key_fingerprint: 567E347AD0044ADE55BA8A5F199E2F91FD431D51 sshd_distributed_config: 'false' sysctl_remediate_drop_in_file: 'false' type: platform +uid_max: 60000 uid_min: 1000 diff --git a/tests/data/product_stability/rhel10.yml b/tests/data/product_stability/rhel10.yml new file mode 100644 index 000000000000..dcd0d50ab662 --- /dev/null +++ b/tests/data/product_stability/rhel10.yml @@ -0,0 +1,90 @@ +aide_also_checks_audispd: 'no' +aide_also_checks_rsyslog: 'yes' +aide_bin_path: /usr/sbin/aide +aide_conf_path: /etc/aide.conf +audisp_conf_path: /etc/audit +auid: 1000 +aux_pkg_release: '' +aux_pkg_version: '' +auxiliary_key_fingerprint: '' +basic_properties_derived: true +benchmark_id: RHEL-10 +benchmark_root: ../../linux_os/guide +chrony_conf_path: /etc/chrony.conf +chrony_d_path: /etc/chrony.d/ +components_root: ../../components +cpes: +- rhel10: + check_id: installed_OS_is_rhel10 + name: cpe:/o:redhat:enterprise_linux:10 + title: Red Hat Enterprise Linux 10 +cpes_root: ../../shared/applicability +dconf_gdm_dir: distro.d +faillock_path: /var/log/faillock +families: +- rhel +- rhel-like +full_name: Red Hat Enterprise Linux 10 +gid_min: 1000 +groups: {} +grub2_boot_path: /boot/grub2 +grub2_uefi_boot_path: /boot/grub2 +grub_helper_executable: grubby +init_system: systemd +journald_conf_dir_path: /etc/systemd/journald.conf.d +major_version_ordinal: 10 +nobody_gid: 65534 +nobody_uid: 65534 +pkg_manager: dnf +pkg_manager_config_file: /etc/dnf/dnf.conf +pkg_release: '' +pkg_system: rpm +pkg_version: '' +platform_package_overrides: + aarch64_arch: null + grub2: grub2-common + login_defs: shadow-utils + no_ovirt: null + non-uefi: null + not_aarch64_arch: null + not_s390x_arch: null + ovirt: null + s390x_arch: null + sssd: sssd-common + sssd-ldap: null + uefi: null + zipl: s390utils-base +product: rhel10 +profiles_root: ./profiles +reference_uris: + anssi: https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf + app-srg: https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=application-servers + app-srg-ctr: https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=container-platform + bsi: https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Grundschutz/International/bsi_it_gs_comp_2022.pdf + cis: https://www.cisecurity.org/benchmark/red_hat_linux/ + cis-csc: https://www.cisecurity.org/controls/ + cjis: https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf + cobit5: https://www.isaca.org/resources/cobit + cui: http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf + dcid: not_officially_available + disa: https://public.cyber.mil/stigs/cci/ + hipaa: https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf + isa-62443-2009: https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat + isa-62443-2013: https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu + ism: https://www.cyber.gov.au/acsc/view-all-content/ism + iso27001-2013: https://www.iso.org/contents/data/standard/05/45/54534.html + nerc-cip: https://www.nerc.com/pa/Stand/Standard%20Purpose%20Statement%20DL/US_Standard_One-Stop-Shop.xlsx + nist: http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf + nist-csf: https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf + os-srg: https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os + ospp: https://www.niap-ccevs.org/Profile/PP.cfm + pcidss: https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf + pcidss4: https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf + stigid: https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux + stigref: https://public.cyber.mil/stigs/srg-stig-tools/ +release_key_fingerprint: '' +sshd_distributed_config: 'true' +sysctl_remediate_drop_in_file: 'false' +type: platform +uid_max: 60000 +uid_min: 1000 diff --git a/tests/data/product_stability/rhel8.yml b/tests/data/product_stability/rhel8.yml index a3647a9df47d..c459a6629f99 100644 --- a/tests/data/product_stability/rhel8.yml +++ b/tests/data/product_stability/rhel8.yml @@ -135,4 +135,5 @@ release_key_fingerprint: 567E347AD0044ADE55BA8A5F199E2F91FD431D51 sshd_distributed_config: 'false' sysctl_remediate_drop_in_file: 'false' type: platform +uid_max: 60000 uid_min: 1000 diff --git a/tests/data/product_stability/rhel9.yml b/tests/data/product_stability/rhel9.yml index e9e0fe03b582..fd3573d94d27 100644 --- a/tests/data/product_stability/rhel9.yml +++ b/tests/data/product_stability/rhel9.yml @@ -92,4 +92,5 @@ release_key_fingerprint: 567E347AD0044ADE55BA8A5F199E2F91FD431D51 sshd_distributed_config: 'true' sysctl_remediate_drop_in_file: 'false' type: platform +uid_max: 60000 uid_min: 1000 diff --git a/tests/data/product_stability/rhv4.yml b/tests/data/product_stability/rhv4.yml index 59f81d865f75..1a8bd9499e12 100644 --- a/tests/data/product_stability/rhv4.yml +++ b/tests/data/product_stability/rhv4.yml @@ -83,4 +83,5 @@ release_key_fingerprint: 567E347AD0044ADE55BA8A5F199E2F91FD431D51 sshd_distributed_config: 'false' sysctl_remediate_drop_in_file: 'false' type: platform +uid_max: 60000 uid_min: 1000 diff --git a/tests/data/product_stability/sle12.yml b/tests/data/product_stability/sle12.yml index db5526ea7b12..743722b5d365 100644 --- a/tests/data/product_stability/sle12.yml +++ b/tests/data/product_stability/sle12.yml @@ -83,4 +83,5 @@ reference_uris: sshd_distributed_config: 'false' sysctl_remediate_drop_in_file: 'true' type: platform +uid_max: 60000 uid_min: 1000 diff --git a/tests/data/product_stability/sle15.yml b/tests/data/product_stability/sle15.yml index 7a82d1a09b5c..5759be6007e7 100644 --- a/tests/data/product_stability/sle15.yml +++ b/tests/data/product_stability/sle15.yml @@ -88,4 +88,5 @@ release_key_fingerprint: FEAB502539D846DB2C0961CA70AF9E8139DB7C82 sshd_distributed_config: 'false' sysctl_remediate_drop_in_file: 'true' type: platform +uid_max: 60000 uid_min: 1000 diff --git a/tests/data/product_stability/slmicro5.yml b/tests/data/product_stability/slmicro5.yml new file mode 100644 index 000000000000..e800c0af6db6 --- /dev/null +++ b/tests/data/product_stability/slmicro5.yml @@ -0,0 +1,93 @@ +aide_also_checks_audispd: 'yes' +aide_also_checks_rsyslog: 'no' +aide_bin_path: /usr/bin/aide +aide_conf_path: /etc/aide.conf +audisp_conf_path: /etc/audit +auid: 1000 +basic_properties_derived: true +benchmark_id: SLMICRO5 +benchmark_root: ../../linux_os/guide +chrony_conf_path: /etc/chrony.conf +chrony_d_path: /etc/chrony.d/ +cpes: +- slmicro-5.2: + check_id: installed_OS_is_slmicro5 + name: cpe:/o:suse:sle-microos:5.2 + title: SLE MicroOS 5.2 +- slmicro-5.3: + check_id: installed_OS_is_slmicro5 + name: cpe:/o:suse:sle-micro:5.3 + title: SLE Micro 5.3 +- slmicro-5.4: + check_id: installed_OS_is_slmicro5 + name: cpe:/o:suse:sle-micro:5.4 + title: SLE Micro 5.4 +- slmicro-5.5: + check_id: installed_OS_is_slmicro5 + name: cpe:/o:suse:sle-micro:5.5 + title: SLE Micro 5.5 +cpes_root: ../../shared/applicability +dconf_gdm_dir: gdm.d +faillock_path: /var/run/faillock +full_name: SUSE Linux Enterprise Micro 5 +gid_min: 1000 +groups: {} +grub2_boot_path: /boot/grub2 +grub2_uefi_boot_path: /boot/grub2 +grub_helper_executable: grubby +init_system: systemd +journald_conf_dir_path: /etc/systemd/journal.conf.d +major_version_ordinal: 5 +nobody_gid: 65534 +nobody_uid: 65534 +oval_feed_url: https://ftp.suse.com/pub/projects/security/oval/suse.linux.enterprise.micro.5-patch.xml.bz2 +pkg_manager: zypper +pkg_manager_config_file: /etc/zypp/zypp.conf +pkg_system: rpm +platform_package_overrides: + aarch64_arch: null + grub2: grub2 + login_defs: shadow + no_ovirt: null + non-uefi: null + not_aarch64_arch: null + not_s390x_arch: null + ovirt: null + passwd: shadow + s390x_arch: null + sssd: sssd + sssd-ldap: null + uefi: null + zipl: s390utils-base +product: slmicro5 +profiles_root: ./profiles +reference_uris: + anssi: https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf + app-srg: https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=application-servers + app-srg-ctr: https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=container-platform + bsi: https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Grundschutz/International/bsi_it_gs_comp_2022.pdf + cis-csc: https://www.cisecurity.org/controls/ + cjis: https://www.fbi.gov/file-repository/cjis-security-policy-v5_5_20160601-2-1.pdf + cobit5: https://www.isaca.org/resources/cobit + cui: http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171.pdf + dcid: not_officially_available + disa: https://public.cyber.mil/stigs/cci/ + hipaa: https://www.gpo.gov/fdsys/pkg/CFR-2007-title45-vol1/pdf/CFR-2007-title45-vol1-chapA-subchapC.pdf + isa-62443-2009: https://www.isa.org/products/isa-62443-2-1-2009-security-for-industrial-automat + isa-62443-2013: https://www.isa.org/products/ansi-isa-62443-3-3-99-03-03-2013-security-for-indu + ism: https://www.cyber.gov.au/acsc/view-all-content/ism + iso27001-2013: https://www.iso.org/contents/data/standard/05/45/54534.html + nerc-cip: https://www.nerc.com/pa/Stand/Standard%20Purpose%20Statement%20DL/US_Standard_One-Stop-Shop.xlsx + nist: http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf + nist-csf: https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf + os-srg: https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os + ospp: https://www.niap-ccevs.org/Profile/PP.cfm + pcidss: https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf + pcidss4: https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf + stigid: https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux + stigref: https://public.cyber.mil/stigs/srg-stig-tools/ +sshd_distributed_config: 'false' +sysctl_remediate_drop_in_file: 'true' +type: platform +uid_max: 60000 +uid_min: 1000 diff --git a/tests/data/product_stability/ubuntu1604.yml b/tests/data/product_stability/ubuntu1604.yml index 954a108c7c1f..e526e4d97a90 100644 --- a/tests/data/product_stability/ubuntu1604.yml +++ b/tests/data/product_stability/ubuntu1604.yml @@ -86,4 +86,5 @@ reference_uris: sshd_distributed_config: 'false' sysctl_remediate_drop_in_file: 'false' type: platform +uid_max: 60000 uid_min: 1000 diff --git a/tests/data/product_stability/ubuntu1804.yml b/tests/data/product_stability/ubuntu1804.yml index f5159a1cb5c1..0c4eb08b1cf1 100644 --- a/tests/data/product_stability/ubuntu1804.yml +++ b/tests/data/product_stability/ubuntu1804.yml @@ -85,4 +85,5 @@ reference_uris: sshd_distributed_config: 'false' sysctl_remediate_drop_in_file: 'false' type: platform +uid_max: 60000 uid_min: 1000 diff --git a/tests/data/product_stability/ubuntu2004.yml b/tests/data/product_stability/ubuntu2004.yml index 088f9c35b03e..edc0a04d1368 100644 --- a/tests/data/product_stability/ubuntu2004.yml +++ b/tests/data/product_stability/ubuntu2004.yml @@ -89,4 +89,5 @@ reference_uris: sshd_distributed_config: 'true' sysctl_remediate_drop_in_file: 'false' type: platform +uid_max: 60000 uid_min: 1000 diff --git a/tests/data/product_stability/ubuntu2204.yml b/tests/data/product_stability/ubuntu2204.yml index f4a4c1e80005..f88fe95043a4 100644 --- a/tests/data/product_stability/ubuntu2204.yml +++ b/tests/data/product_stability/ubuntu2204.yml @@ -90,4 +90,5 @@ reference_uris: sshd_distributed_config: 'true' sysctl_remediate_drop_in_file: 'false' type: platform +uid_max: 60000 uid_min: 1000