diff --git a/linux_os/guide/system/software/integrity/software-integrity/rpm_verification/rpm_verify_ownership/rule.yml b/linux_os/guide/system/software/integrity/software-integrity/rpm_verification/rpm_verify_ownership/rule.yml index 1e8e59edf8c3..7f3eb6372799 100644 --- a/linux_os/guide/system/software/integrity/software-integrity/rpm_verification/rpm_verify_ownership/rule.yml +++ b/linux_os/guide/system/software/integrity/software-integrity/rpm_verification/rpm_verify_ownership/rule.yml @@ -1,6 +1,6 @@ documentation_complete: true -prodtype: rhel6,rhel7,rhel8,rhv4 +prodtype: rhel6,rhel7,rhel8,rhv4,ocp4 title: 'Verify and Correct Ownership with RPM' diff --git a/linux_os/guide/system/software/integrity/software-integrity/rpm_verification/rpm_verify_permissions/rule.yml b/linux_os/guide/system/software/integrity/software-integrity/rpm_verification/rpm_verify_permissions/rule.yml index 891256dceebc..329ac375fe26 100644 --- a/linux_os/guide/system/software/integrity/software-integrity/rpm_verification/rpm_verify_permissions/rule.yml +++ b/linux_os/guide/system/software/integrity/software-integrity/rpm_verification/rpm_verify_permissions/rule.yml @@ -1,6 +1,6 @@ documentation_complete: true -prodtype: wrlinux1019,rhel6,rhel7,rhel8,fedora,ol7,ol8,rhv4 +prodtype: wrlinux1019,rhel6,rhel7,rhel8,fedora,ol7,ol8,rhv4,ocp4 title: 'Verify and Correct File Permissions with RPM' diff --git a/ocp4/profiles/moderate.profile b/ocp4/profiles/moderate.profile index e7f9a492e8dd..d19491d70095 100644 --- a/ocp4/profiles/moderate.profile +++ b/ocp4/profiles/moderate.profile @@ -563,10 +563,12 @@ selections: - chronyd_or_ntpd_specify_multiple_servers # AU-9 - #- rpm_verify_ownership - #- rpm_verify_permissions + - rpm_verify_ownership + - rpm_verify_permissions - selinux_confinement_of_daemons - #- ensure_logrotate_activated + # TODO - we should update this rule to parameterize the rotation cadence. + # The check curently expects it to be daily, but OCP4 nodes rotate weekly. + - ensure_logrotate_activated - file_permissions_var_log_audit - file_ownership_var_log_audit - directory_permissions_var_log_audit