Skip to content

Add postfix package requirement and audit retention controls to multiple profile controls#14612

Open
Arden97 wants to merge 4 commits intoComplianceAsCode:masterfrom
Arden97:fix_14560
Open

Add postfix package requirement and audit retention controls to multiple profile controls#14612
Arden97 wants to merge 4 commits intoComplianceAsCode:masterfrom
Arden97:fix_14560

Conversation

@Arden97
Copy link
Copy Markdown
Contributor

@Arden97 Arden97 commented Apr 2, 2026

Description:

  • Fixing auditd email-related error for cis, pci-dss, stig and hipaa profiles

Rationale:

Review Hints:

  • use atex to reserve testing environment and run /scanning/boot-errors/ test for updated profiles

@openshift-ci openshift-ci bot added the do-not-merge/work-in-progress Used by openshift-ci bot. label Apr 2, 2026
@openshift-ci
Copy link
Copy Markdown

openshift-ci bot commented Apr 2, 2026

Skipping CI for Draft Pull Request.
If you want CI signal for your change, please convert it to an actual PR.
You can still manually trigger a test run with /test all

@Arden97 Arden97 added this to the 0.1.81 milestone Apr 2, 2026
@Arden97 Arden97 marked this pull request as ready for review April 3, 2026 10:18
@openshift-ci openshift-ci bot removed the do-not-merge/work-in-progress Used by openshift-ci bot. label Apr 3, 2026
@Mab879 Mab879 self-assigned this Apr 3, 2026
@Mab879
Copy link
Copy Markdown
Member

Mab879 commented Apr 3, 2026

@ComplianceAsCode/suse-maintainers can you please take a look as well?

Comment thread linux_os/guide/services/mail/package_postfix_installed/rule.yml Outdated
@Arden97 Arden97 requested a review from a team as a code owner April 7, 2026 08:54
Copy link
Copy Markdown
Contributor

@teacup-on-rockingchair teacup-on-rockingchair left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

In products/sle15/profiles/pci-dss-4.profile can you please add a line

- !package_postfix_installed

So the checks for missing CCE is not failing for sle15 platform

Comment thread products/sle12/profiles/pci-dss-4.profile
Copy link
Copy Markdown
Contributor

@teacup-on-rockingchair teacup-on-rockingchair left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍

Copy link
Copy Markdown
Member

@Mab879 Mab879 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The following rules in ssg-sle12-ds.xml are missing CCEs:
xccdf_org.ssgproject.content_rule_package_postfix_installed

Can you double check this?

@teacup-on-rockingchair
Copy link
Copy Markdown
Contributor

The following rules in ssg-sle12-ds.xml are missing CCEs:
xccdf_org.ssgproject.content_rule_package_postfix_installed

Can you double check this?

Hey @Mab879 since @Arden97 was struggling for some time with that one, and it seems that the solution was not obvious simply to exclude the rule from the default and pci-dss profile I suggested in #14612 (comment) that he can go on like this and once he merges his effort I will handle it in a separate PR

@Arden97
Copy link
Copy Markdown
Contributor Author

Arden97 commented Apr 16, 2026

@teacup-on-rockingchair no worries, the solution was to update both sle12 pci-dss profiles that use pcidss_3.yml and I didn't notice pci_dss.profile until recently

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

auditd complains that /usr/lib/sendmail is not executable after hardening

3 participants