-
Notifications
You must be signed in to change notification settings - Fork 710
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Add package_ftp_removed rule #10294
Add package_ftp_removed rule #10294
Conversation
cf5244e
to
70298c1
Compare
linux_os/guide/services/ftp/package_ftp-client_removed/rule.yml
Outdated
Show resolved
Hide resolved
linux_os/guide/services/ftp/package_ftp-client_removed/rule.yml
Outdated
Show resolved
Hide resolved
linux_os/guide/services/ftp/package_ftp-client_removed/rule.yml
Outdated
Show resolved
Hide resolved
It appears that the |
Correct. The package name for the FTP client in RHEL9 is |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks for the rule @cortesana . There is a small issue related to the package name. Thanks @Mab879 for catching this.
linux_os/guide/services/ftp/package_ftp-client_removed/rule.yml
Outdated
Show resolved
Hide resolved
linux_os/guide/services/ftp/package_ftp-client_removed/rule.yml
Outdated
Show resolved
Hide resolved
linux_os/guide/services/ftp/package_ftp-client_removed/rule.yml
Outdated
Show resolved
Hide resolved
linux_os/guide/services/ftp/package_ftp-client_removed/rule.yml
Outdated
Show resolved
Hide resolved
70298c1
to
5593986
Compare
5286950
to
85dc15e
Compare
The Automatus CS8 failure is expected since the rule is restricted to |
/retest |
Hello @jhrozek - one of the RHCOS tests is failing. Could you take a look at the |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Just one minor nitpick.
The new package_ftp_removed rule is created in order to meet the following CIS requirement for RHEL9: - 2.3.4 - Ensure FTP client is not installed. (Automated)
85dc15e
to
f0c929a
Compare
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks for this new rule. LGTM!
I will only wait the CI tests to finish. |
Code Climate has analyzed commit f0c929a and detected 0 issues on this pull request. The test coverage on the diff in this pull request is 100.0% (50% is the threshold). This pull request will bring the total coverage in the repository to 51.7% (0.0% change). View more on Code Climate. |
Description:
The new package_ftp-client_removed rule is created in order to meet the following CIS requirement for RHEL9:
Rationale:
FTP does not protect the confidentiality of data or authentication credentials. Unless the system needs to run as a FTP server, the package should be removed to reduce the potential attack surface.