Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

mount_option_nodev_nonroot_local_partitions reported as failing after scan of IB created image #11996

Open
vojtapolasek opened this issue May 15, 2024 · 1 comment
Assignees
Labels
productization-issue Issue found in upstream stabilization process.
Milestone

Comments

@vojtapolasek
Copy link
Collaborator

Description of problem:

When provisioning system with Imagebuilder and hardening with CUI profile, the rule mount_option_nodev_nonroot_local_partitions is reported as fail in the final scan.

SCAP Security Guide Version:

master as of 7425c4e

Operating System Version:

RHEL 8

Steps to Reproduce:

Perform hardening of the system with Imagebuilder.
Some steps might be here: https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/composing_a_customized_rhel_system_image/assembly_creating-pre-hardened-images-with-image-builder-openscap-integration_composing-a-customized-rhel-system-image

Actual Results:

The rule is marked as "pass" during initial scan. But then the remediation seems to be applied. And in the final scan the rule is reported as "fail". The mount point which causes the fail is /boot/efi.

Expected Results:

The rule is marked as "pass".

Additional Information/Debugging Steps:

Due to the problem being /boot/efi, it might be caused by Imagebuilder when composing the image.int

@mildas
Copy link
Contributor

mildas commented May 23, 2024

@evgenyz Any updates?
If you have done some investigation and reported downstream issue on IB side, it's enough. In such case, send me link to the issue, I will update waivers and then we can label this issue as blocked.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
productization-issue Issue found in upstream stabilization process.
Projects
None yet
Development

No branches or pull requests

3 participants