-
Notifications
You must be signed in to change notification settings - Fork 764
Add Amazon Linux 2023 DISA STIG Profile #14246
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: master
Are you sure you want to change the base?
Add Amazon Linux 2023 DISA STIG Profile #14246
Conversation
|
Hi @Eric-Domeier. Thanks for your PR. I'm waiting for a github.com member to verify that this patch is reasonable to test. If it is, they should reply with Once the patch is verified, the new status will be reflected by the I understand the commands that are listed here. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Needs further review, copy-pasted from RHEL8
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I tried to get this working for a bit but gave up and went with a VM. Al2023 image is minimal and doesn't have all packages needed.
| ssg_build_html_srgmap_tables(${PRODUCT}) | ||
|
|
||
| ssg_build_html_stig_tables(${PRODUCT}) | ||
| ssg_build_html_stig_tables_per_profile(${PRODUCT} "stig") |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Missing new line at the end of the file.
|
|
||
| ssg_build_html_cce_table(${PRODUCT}) | ||
|
|
||
| ssg_build_html_ref_tables("${PRODUCT}" "table-${PRODUCT}-{ref_id}refs" "anssi;cis;cui;nist;pcidss") |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
AL2023 currently doesn't have ANSSI, CUI and PCI-DSS profiles.
| all of these checks should pass. | ||
|
|
||
| selections: | ||
| - accounts_password_minlen_login_defs |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Why do you introduce an almost empty profile?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I was following along the creation docs - I will delete this if its unnecessary.
https://complianceascode.readthedocs.io/en/latest/manual/developer/03_creating_content.html
| documentation_complete: true | ||
|
|
||
| metadata: | ||
| version: 1.0.0 |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I assume the version should be V1R1
Co-authored-by: Jan Černý <[email protected]>
ATEX Test ResultsTest artifacts have been submitted to Testing Farm. Results: View Test Results This comment was automatically generated by the ATEX workflow. |
Description:
Rationale:
Amazon linux 2023 stig profile is useful for federal agencies, cmmc, fedramp etc.
Amazon Linux 2023 Department of War (Previously Department of Defense) STIG #13885
Review Hints:
This builds off of @jesseborden branch, attempts to get the --stig-viewer flag working properly.
products/al2023/overlays/srg_support.xml is just a copy paste from products/rhel8/overlays/srg_support.xml with name replaced, the content hasn't actually been checked yet.
I haven't verified the content in controls/stig_al2023.yml yet
modifies applicability templates to ensure checks are applicable for al2023
To-do