Skip to content

Update OL8 STIG profile to DISA STIG V2R8#14738

Open
mrkanon wants to merge 4 commits into
ComplianceAsCode:masterfrom
mrkanon:OL8-v2r8
Open

Update OL8 STIG profile to DISA STIG V2R8#14738
mrkanon wants to merge 4 commits into
ComplianceAsCode:masterfrom
mrkanon:OL8-v2r8

Conversation

@mrkanon
Copy link
Copy Markdown
Contributor

@mrkanon mrkanon commented May 26, 2026

Description:

Update the OL8 STIG profile to be compliant with DISA STIG V2R8

Rationale:

Be aligned with OL8 DISA STIG V2R8

mrkanon added 3 commits May 26, 2026 16:15
Signed-off-by: Armando Acosta <armando.acosta@oracle.com>
Signed-off-by: Armando Acosta <armando.acosta@oracle.com>
OL08-00-010180
OL08-00-010181

Signed-off-by: Armando Acosta <armando.acosta@oracle.com>
@mrkanon mrkanon added this to the 0.1.82 milestone May 26, 2026
@mrkanon mrkanon requested a review from a team as a code owner May 26, 2026 22:19
@mrkanon mrkanon added Oracle Linux Oracle Linux product related. STIG STIG Benchmark related. labels May 26, 2026
@mrkanon
Copy link
Copy Markdown
Contributor Author

mrkanon commented May 27, 2026

/retest

@Mab879 Mab879 self-assigned this May 28, 2026
Copy link
Copy Markdown
Member

@Mab879 Mab879 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please take look at these findings.

  1. ensure_epel_repos_disabled is missing its STIG ID reference

The profile maps OL08-00-040010 to this rule (stig.profile:970-971), but ensure_epel_repos_disabled/rule.yml has no stigid@ol8. Without it, the OL8 data stream won't associate this rule with its V2R8 STIG ID.

  1. ensure_epel_repos_disabled is missing a severity override

The V2R8 reference XML assigns severity="high" to OL08-00-040010. The rule defaults to severity: medium. Other newly-added rules in this PR received overrides (e.g., package_crypto-policies_installed.severity=high); this one was missed.

  1. Stale stigid@ol8 on package_rsh-server_removed

OL08-00-040010 was reassigned in V2R8 from rsh-server removal to the EPEL check. The rule is no longer in the profile, and its stigid should be removed. The PR cleaned up four other removed rules but missed this one.

  1. Stale stigid@ol8 on sshd_use_approved_kex_ordered_stig

OL08-00-040342 does not exist in the V2R8 reference XML. The rule was correctly removed from the profile, but the stigid reference in rule.yml was not cleaned up.

This review was created in part with Claude code.

Signed-off-by: Armando Acosta <armando.acosta@oracle.com>
@openshift-ci
Copy link
Copy Markdown

openshift-ci Bot commented May 28, 2026

@mrkanon: The following test failed, say /retest to rerun all failed tests or /retest-required to rerun all mandatory failed tests:

Test name Commit Details Required Rerun command
ci/prow/e2e-aws-openshift-platform-compliance c827a59 link true /test e2e-aws-openshift-platform-compliance

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Oracle Linux Oracle Linux product related. STIG STIG Benchmark related.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants