Commit Graph

65 Commits

Author SHA256 Message Date
1da4c878e8 - updated to 0.1.66 (jsc#ECO-3319)
- Ubuntu 22.04 CIS
  - OL7 stig v2r9 update
  - Bump OL8 STIG version to V1R4
  - Update RHEL7 STIG to V3R10
  - Update RHEL8 STIG to V1R9
  - Introduce CIS RHEL9 profiles
- also various SUSE profile fixes were done

OBS-URL: https://build.opensuse.org/package/show/security/scap-security-guide?expand=0&rev=83
2023-02-06 15:04:42 +00:00
dce8ee0fe9 Accepting request 1040265 from home:msmeissn:branches:security
- updated to 0.1.65 (jsc#ECO-3319)
   - Introduce cui profile for OL9
   - Remove Support for OVAL 5.10
   - Rename account_passwords_pam_faillock_audit
   - CI ansible hardening and rename of existing Bash hardening
   - Update contributors list for v0.1.65 release
   - various SUSE profile specific fixes

OBS-URL: https://build.opensuse.org/request/show/1040265
OBS-URL: https://build.opensuse.org/package/show/security/scap-security-guide?expand=0&rev=81
2022-12-05 12:44:01 +00:00
aa97eceaa7 - require sudo, as remediations touch sudo config or use sudo.
OBS-URL: https://build.opensuse.org/package/show/security/scap-security-guide?expand=0&rev=79
2022-11-25 13:16:57 +00:00
8f4f076e71 - enable ubuntu 2204 build
OBS-URL: https://build.opensuse.org/package/show/security/scap-security-guide?expand=0&rev=77
2022-10-05 09:22:16 +00:00
b7a0ce2ed7 - updated to 0.1.64 (jsc#ECO-3319)
- Introduce ol9 stig profile
   - Introduce Ol9 anssi profiles
   - Update RHEL8 STIG to V1R7
   - Introduce e8 profile for OL9
   - Update RHEL7 STIG to V3R8
   - some SUSE profile fixes

OBS-URL: https://build.opensuse.org/package/show/security/scap-security-guide?expand=0&rev=75
2022-10-01 09:00:13 +00:00
779881f7d7 - Added several RPM requires that are needed by the SUSE remediation
scripts. (e.g. awk is not necessary installed)

OBS-URL: https://build.opensuse.org/package/show/security/scap-security-guide?expand=0&rev=73
2022-09-21 08:25:12 +00:00
7493083014 OBS-URL: https://build.opensuse.org/package/show/security/scap-security-guide?expand=0&rev=71 2022-08-02 12:46:34 +00:00
9d790ae2f3 OBS-URL: https://build.opensuse.org/package/show/security/scap-security-guide?expand=0&rev=70 2022-08-02 11:56:04 +00:00
14e6352898 disable alibaba linux for now
OBS-URL: https://build.opensuse.org/package/show/security/scap-security-guide?expand=0&rev=69
2022-08-02 10:50:33 +00:00
316cd1586b - Fixed: stig: /etc/shadow group owner should not be root but shadow (bsc#1200149)
- Fixed: sles15_script-stig.sh: remediation_functions: No such file or directory (bsc#1200163)
- Fixed: SLES-15-010130 - The SUSE operating system must initiate a session lock after a 15-minute period of inactivity (bsc#1200122)

OBS-URL: https://build.opensuse.org/package/show/security/scap-security-guide?expand=0&rev=68
2022-07-30 14:07:22 +00:00
c851cbd50a OBS-URL: https://build.opensuse.org/package/show/security/scap-security-guide?expand=0&rev=67 2022-07-30 14:02:13 +00:00
2f7037c731 OBS-URL: https://build.opensuse.org/package/show/security/scap-security-guide?expand=0&rev=66 2022-07-30 14:01:53 +00:00
2eb737837b - updated to 0.1.63 (jsc#ECO-3319)
- multiple bugfixes in SUSE profiles
   - Expand project guidelines 
   - Add Draft OCP4 STIG profile 
   - Add anssi_bp28_intermediary profile 
   - add products/uos20 to support UnionTech OS Server 20
   - products/alinux3: Add CIS Alibaba Cloud Linux 3 profiles
   - Remove WRLinux Products
   - Update CIS RHEL8 Benchmark for v2.0.0

OBS-URL: https://build.opensuse.org/package/show/security/scap-security-guide?expand=0&rev=65
2022-07-30 14:01:30 +00:00
e9069206a8 Accepting request 989423 from home:juliogonzalezgil:branches:security
- Fix the build for RHEL 7 and clones (python-setuptools is used)

OBS-URL: https://build.opensuse.org/request/show/989423
OBS-URL: https://build.opensuse.org/package/show/security/scap-security-guide?expand=0&rev=63
2022-07-15 12:04:55 +00:00
72a0614358 Accepting request 987134 from home:juliogonzalezgil:branches:security
- Fix the build for RHEL 9 and clones

OBS-URL: https://build.opensuse.org/request/show/987134
OBS-URL: https://build.opensuse.org/package/show/security/scap-security-guide?expand=0&rev=61
2022-07-06 10:27:19 +00:00
bed5d29c1e OBS-URL: https://build.opensuse.org/package/show/security/scap-security-guide?expand=0&rev=59 2022-06-28 08:21:15 +00:00
d2594301b5 - fix-bash-template.patch: convert one bash emitter to new jinja method.
(bsc#1200163)

OBS-URL: https://build.opensuse.org/package/show/security/scap-security-guide?expand=0&rev=58
2022-06-27 13:00:45 +00:00
7bea99af49 - add python3-setuptools for all builds (so it is also used on debian
and centos flavors)

OBS-URL: https://build.opensuse.org/package/show/security/scap-security-guide?expand=0&rev=56
2022-06-09 15:38:39 +00:00
41770cd841 OBS-URL: https://build.opensuse.org/package/show/security/scap-security-guide?expand=0&rev=55 2022-06-09 15:32:55 +00:00
cc2a240412 - add python3-setuptools for debian builds
OBS-URL: https://build.opensuse.org/package/show/security/scap-security-guide?expand=0&rev=54
2022-06-09 15:32:00 +00:00
7d80347bc9 OBS-URL: https://build.opensuse.org/package/show/security/scap-security-guide?expand=0&rev=52 2022-05-30 13:46:43 +00:00
aac6818829 - updated to 0.1.62 (jsc#ECO-3319)
- Update rhel8 stig to v1r6
  - OL7 STIG v2r7 update
  - Initial definition of ANSSI BP28 minmal profile for SLE

OBS-URL: https://build.opensuse.org/package/show/security/scap-security-guide?expand=0&rev=51
2022-05-30 12:50:00 +00:00
b8d0261f0a OBS-URL: https://build.opensuse.org/package/show/security/scap-security-guide?expand=0&rev=50 2022-05-04 07:17:02 +00:00
ae3c689fbf OBS-URL: https://build.opensuse.org/package/show/security/scap-security-guide?expand=0&rev=49 2022-04-27 06:57:13 +00:00
afaf6269b8 OBS-URL: https://build.opensuse.org/package/show/security/scap-security-guide?expand=0&rev=48 2022-04-12 13:18:33 +00:00
8412ab4411 OBS-URL: https://build.opensuse.org/package/show/security/scap-security-guide?expand=0&rev=46 2022-04-04 09:03:43 +00:00
d29da4888b - updated to 0.1.61 (jsc#ECO-3319)
- Stop building PCI-DSS-centric XCCDF benchmark for RHEL 7
  - Introduce OL9 product
  - Implement handling of logical expressions in platform definitions

OBS-URL: https://build.opensuse.org/package/show/security/scap-security-guide?expand=0&rev=45
2022-04-04 08:41:19 +00:00
1e35edc382 - bump disk size constraints to 7gb to avoid occasional disk fulls failures.
OBS-URL: https://build.opensuse.org/package/show/security/scap-security-guide?expand=0&rev=44
2022-02-22 15:20:05 +00:00
c8e5a26671 Accepting request 949738 from home:msmeissn:branches:security
- updated to 0.1.60 (jsc#ECO-3319)
  - New draft stig profile v1r1 for OL8
  - New product Amazon EKS platform and initial CIS profiles
  - New product CentOS Stream 9, as a derivative from RHEL9 product

OBS-URL: https://build.opensuse.org/request/show/949738
OBS-URL: https://build.opensuse.org/package/show/security/scap-security-guide?expand=0&rev=43
2022-01-28 16:28:07 +00:00
a79dc49061 OBS-URL: https://build.opensuse.org/package/show/security/scap-security-guide?expand=0&rev=42 2021-11-29 12:16:34 +00:00
e166bbe082 - updated to 0.1.59 release (jsc#ECO-3319)
- Support for Debian 11
  - NERC CIP profiles for OCP4 and RHCOS
  - HIPAA profile for SLE15
  - Delta Tailoring Files for STIG profiles

OBS-URL: https://build.opensuse.org/package/show/security/scap-security-guide?expand=0&rev=41
2021-11-27 15:41:29 +00:00
f0bb083c48 OBS-URL: https://build.opensuse.org/package/show/security/scap-security-guide?expand=0&rev=40 2021-10-07 15:04:19 +00:00
3910b93b4a OBS-URL: https://build.opensuse.org/package/show/security/scap-security-guide?expand=0&rev=39 2021-10-07 14:59:44 +00:00
56cdaf93b5 OBS-URL: https://build.opensuse.org/package/show/security/scap-security-guide?expand=0&rev=38 2021-10-07 14:44:53 +00:00
b00565ed59 - Fix SLE-12 build issue caused by '\xb0' character (bsc#1191431).
- Add scap-security-guide-UnicodeEncodeError-character-fix.patch

OBS-URL: https://build.opensuse.org/package/show/security/scap-security-guide?expand=0&rev=37
2021-10-07 14:44:29 +00:00
faf1cfcbbd - Support for Script Checking Engine (SCE)
- Split RHEL 8 CIS profile using new controls file format
- CIS Profiles for SLE12
- Initial Ubuntu 20.04 STIG Profiles
- Addition of an automated CCE adder

OBS-URL: https://build.opensuse.org/package/show/security/scap-security-guide?expand=0&rev=36
2021-09-24 15:17:05 +00:00
f4d232af87 - updated to 0.1.58 release (jsc#ECO-3319)
- Support for Script Checking Engine (SCE)                                                                                                                                                   
- Split RHEL 8 CIS profile using new controls file format                                                                                                                                    
- CIS Profiles for SLE12                                                                                                                                                                     
- Initial Ubuntu 20.04 STIG Profiles                                                                                                                                                         
- Addition of an automated CCE adder

OBS-URL: https://build.opensuse.org/package/show/security/scap-security-guide?expand=0&rev=35
2021-09-24 15:16:52 +00:00
0ae36b0705 OBS-URL: https://build.opensuse.org/package/show/security/scap-security-guide?expand=0&rev=34 2021-08-01 14:35:42 +00:00
dfb55a9ac3 - CIS profile for RHEL 7 is updated
- initial CIS profiles for Ubuntu 20.04                                                                                                                                                    
  - Major improvement of RHEL 9 content                                                                                                                                                      
  - new release process implemented using Github actions

OBS-URL: https://build.opensuse.org/package/show/security/scap-security-guide?expand=0&rev=33
2021-08-01 14:28:53 +00:00
5c3ffcf335 Accepting request 907719 from home:juliogonzalezgil:branches:security
Building the package for Debian requires almost 5GB of free disk space

OBS-URL: https://build.opensuse.org/request/show/907719
OBS-URL: https://build.opensuse.org/package/show/security/scap-security-guide?expand=0&rev=32
2021-07-22 11:38:19 +00:00
d700fb0ef5 Accepting request 907715 from home:juliogonzalezgil:branches:security
Building the package for Debian requires almost 5GB of free disk space

OBS-URL: https://build.opensuse.org/request/show/907715
OBS-URL: https://build.opensuse.org/package/show/security/scap-security-guide?expand=0&rev=31
2021-07-22 11:30:51 +00:00
ac2115898a OBS-URL: https://build.opensuse.org/package/show/security/scap-security-guide?expand=0&rev=30 2021-07-21 15:28:07 +00:00
73fb95947f - updated to 0.1.57 release (jsc#ECO-3319)
- no upstream changelog.

OBS-URL: https://build.opensuse.org/package/show/security/scap-security-guide?expand=0&rev=29
2021-07-21 15:27:40 +00:00
4bead61ee7 Accepting request 896944 from home:juliogonzalezgil:branches:security
- Specify the maintainer, for deb packages.

Now dpkg does not show warnings:

root@f0531c84f41d:/# dpkg -i scap-security-guide-debian_0.1.56-30.1_all.deb scap-security-guide-ubuntu_0.1.56-30.1_all.deb scap-security-guide-redhat_0.1.56-30.1_all.deb scap-security-guide_0.1.56-30.1_all.deb 
Selecting previously unselected package scap-security-guide-debian.
(Reading database ... 7079 files and directories currently installed.)
Preparing to unpack scap-security-guide-debian_0.1.56-30.1_all.deb ...
Unpacking scap-security-guide-debian (0.1.56-30.1) ...
Selecting previously unselected package scap-security-guide-ubuntu.
Preparing to unpack scap-security-guide-ubuntu_0.1.56-30.1_all.deb ...
Unpacking scap-security-guide-ubuntu (0.1.56-30.1) ...
Selecting previously unselected package scap-security-guide-redhat.
Preparing to unpack scap-security-guide-redhat_0.1.56-30.1_all.deb ...
Unpacking scap-security-guide-redhat (0.1.56-30.1) ...
Selecting previously unselected package scap-security-guide.
Preparing to unpack scap-security-guide_0.1.56-30.1_all.deb ...
Unpacking scap-security-guide (0.1.56-30.1) ...
Setting up scap-security-guide-debian (0.1.56-30.1) ...
Setting up scap-security-guide-ubuntu (0.1.56-30.1) ...
Setting up scap-security-guide-redhat (0.1.56-30.1) ...
Setting up scap-security-guide (0.1.56-30.1) ...

OBS-URL: https://build.opensuse.org/request/show/896944
OBS-URL: https://build.opensuse.org/package/show/security/scap-security-guide?expand=0&rev=27
2021-06-03 16:00:24 +00:00
4d11fa289c OBS-URL: https://build.opensuse.org/package/show/security/scap-security-guide?expand=0&rev=25 2021-05-28 07:27:09 +00:00
88d1463719 Accepting request 895669 from home:msmeissn:branches:security
- updated to 0.1.56 release (jsc#ECO-3319)
  - Align ism_o profile with latest ISM SSP (#6878)
  - Align RHEL 7 STIG profile with DISA STIG V3R3
  - Creating new RHEL 7 STIG GUI profile (#6863)
  - Creating new RHEL 8 STIG GUI profile (#6862)
  - Add the RHEL9 product (#6801)
  - Initial support for SUSE SLE-15 (#6666)
  - add support for osbuild blueprint remediations (#6970)

OBS-URL: https://build.opensuse.org/request/show/895669
OBS-URL: https://build.opensuse.org/package/show/security/scap-security-guide?expand=0&rev=24
2021-05-27 07:39:56 +00:00
8bdb9329ef Accepting request 881076 from home:msmeissn:branches:security
- updated to a intermediate GIT snapshot of 20210323 (jsc#ECO-3319)
  - initial SLES15 STIG added
  - more SLES 12 STIG work
  - correct tables and cross references for SLES 12 and 15 STIG

- avoid some non sles12 sp2 available macros.

OBS-URL: https://build.opensuse.org/request/show/881076
OBS-URL: https://build.opensuse.org/package/show/security/scap-security-guide?expand=0&rev=22
2021-03-24 16:18:16 +00:00
aee34c6659 Accepting request 880137 from home:msmeissn:branches:security
- updated to 0.1.55 release (jsc#ECO-3319)
  - big update of rules used in SLES-12 STIG profile
  - Render policy to HTML (#6532)
  - Add variable support to yamlfile_value template (#6563)
  - Introduce new template for dconf configuration files (#6118)

OBS-URL: https://build.opensuse.org/request/show/880137
OBS-URL: https://build.opensuse.org/package/show/security/scap-security-guide?expand=0&rev=20
2021-03-19 15:31:45 +00:00
8fbf87fad4 Accepting request 878585 from home:juliogonzalezgil:branches:openSUSE:Factory
- Add the redhat conflict for packages built on redhat clones
  or Fedora

OBS-URL: https://build.opensuse.org/request/show/878585
OBS-URL: https://build.opensuse.org/package/show/security/scap-security-guide?expand=0&rev=18
2021-03-12 15:09:45 +00:00
7128c36f02 OBS-URL: https://build.opensuse.org/package/show/security/scap-security-guide?expand=0&rev=16 2021-02-26 09:51:11 +00:00