Skip to content

Updated the e8 profile for RHEL8.#5024

Merged
redhatrises merged 2 commits intoComplianceAsCode:masterfrom
matejak:e8_rhel8
Nov 25, 2019
Merged

Updated the e8 profile for RHEL8.#5024
redhatrises merged 2 commits intoComplianceAsCode:masterfrom
matejak:e8_rhel8

Conversation

@matejak
Copy link
Copy Markdown
Member

@matejak matejak commented Nov 21, 2019

  • removed obsolete sshd settings.
  • added rules for crypto policies to set up strong ciphers + MACs for sshd.

- removed obsolete SSHD settings.
- added rules for crypto policies.
@matejak matejak added this to the 0.1.48 milestone Nov 21, 2019
Comment thread rhel8/profiles/e8.profile Outdated
@matejak matejak marked this pull request as ready for review November 25, 2019 15:43
@matejak
Copy link
Copy Markdown
Member Author

matejak commented Nov 25, 2019

I have reflected those suggestions in an inline comment. As of now, the FUTURE policy is the best fit, but a better policy may become available later.

@redhatrises redhatrises added the bugfix Fixes to reported bugs. label Nov 25, 2019
@redhatrises
Copy link
Copy Markdown
Contributor

@shaneboulden do we need to add more cyrpto-policy checks for bind, krb, java, etc? Or is ssh just good enough.

@shaneboulden
Copy link
Copy Markdown
Contributor

shaneboulden commented Nov 25, 2019

@shaneboulden do we need to add more cyrpto-policy checks for bind, krb, java, etc? Or is ssh just good enough.

I think ssh is fine - this is designed to be a baseline policy, and these services are pretty specific to server roles (DNS, domain-joined, Java app server).

My preferred approach would be for users to create a tailoring file based on the E8 policy that caters for specific server roles.

@redhatrises
Copy link
Copy Markdown
Contributor

@shaneboulden sounds good. Thanks!

Ack and thanks for the work @matejak

@redhatrises redhatrises self-assigned this Nov 25, 2019
@redhatrises redhatrises merged commit 7ccbc61 into ComplianceAsCode:master Nov 25, 2019
@yuumasato yuumasato mentioned this pull request Apr 1, 2020
1 task
@shaneboulden shaneboulden mentioned this pull request Feb 3, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bugfix Fixes to reported bugs.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants