Skip to content

Commit 1332991

Browse files
committed
rhel8,rhel9: DISA STIG v2r8/v2r9, RHEL-08-030610/RHEL-09-653110 - update remediations and warning in the rule
1 parent 7299d76 commit 1332991

3 files changed

Lines changed: 71 additions & 34 deletions

File tree

‎linux_os/guide/auditing/auditd_configure_rules/file_permissions_audit_configuration_stig/ansible/shared.yml‎

Lines changed: 32 additions & 24 deletions
Original file line numberDiff line numberDiff line change
@@ -5,45 +5,53 @@
55
# disruption = low
66

77
# Copied and modified from `file_permissions/ansible.yml` template
8+
#
9+
# Sets mode 0600 and ownership root:root on all audit config files.
10+
# Installs an auditd.service dropin to restore 0600 on audit.rules after augenrules
11+
# rewrites it to 0640 when /etc/audit/rules.d/ content changes (RHEL 8/9 only, not containers).
812

9-
- name: Ensure audit config files are not more permissive than 0600
13+
- name: Set /etc/audit/audit.rules and /etc/audit/auditd.conf to 0600, owned by root
14+
ansible.builtin.file:
15+
path: "{{ item }}"
16+
mode: '0600'
17+
owner: root
18+
group: root
19+
state: file
20+
loop:
21+
- /etc/audit/audit.rules
22+
- /etc/audit/auditd.conf
23+
failed_when: false
24+
25+
- name: Set /etc/audit/rules.d/*.rules files to 0600, owned by root
26+
ansible.builtin.file:
27+
path: "{{ item }}"
28+
mode: '0600'
29+
owner: root
30+
group: root
31+
state: file
32+
with_fileglob:
33+
- /etc/audit/rules.d/*.rules
34+
35+
- name: Install ExecStartPost dropin on auditd.service
1036
block:
11-
- name: Set /etc/audit/audit.rules and /etc/audit/auditd.conf to 0600
12-
ansible.builtin.file:
13-
path: "{{ item }}"
14-
mode: '0600'
15-
state: file
16-
loop:
17-
- /etc/audit/audit.rules
18-
- /etc/audit/auditd.conf
19-
failed_when: false
20-
21-
- name: Set /etc/audit/rules.d/*.rules files to 0600
22-
ansible.builtin.file:
23-
path: "{{ item }}"
24-
mode: '0600'
25-
state: file
26-
with_fileglob:
27-
- /etc/audit/rules.d/*.rules
28-
29-
# augenrules --load hardcodes chmod 0640 on audit.rules on every rewrite of the rules.d files.
30-
# Install ExecStartPost in auditd.service to restore 0600 after each run.
31-
# Runs inside the auditd_t SELinux domain which has write access to auditd_etc_t files.
32-
# On RHEL 8/9, augenrules is called via ExecStartPost in auditd.service directly.
3337
- name: Create dropin directory /etc/systemd/system/auditd.service.d
3438
ansible.builtin.file:
3539
path: /etc/systemd/system/auditd.service.d
3640
state: directory
3741
mode: '0755'
3842

39-
- name: Install /etc/systemd/system/auditd.service.d/permissions.conf - chmod audit.rules to 0600 after augenrules runs
43+
- name: Install /etc/systemd/system/auditd.service.d/permissions.conf
4044
ansible.builtin.copy:
4145
dest: /etc/systemd/system/auditd.service.d/permissions.conf
4246
content: |
4347
[Service]
4448
ExecStartPost=/usr/bin/chmod 0600 /etc/audit/audit.rules
4549
mode: '0644'
4650

51+
- name: Restore SELinux context on /etc/systemd/system/auditd.service.d/permissions.conf
52+
ansible.builtin.command: restorecon /etc/systemd/system/auditd.service.d/permissions.conf
53+
changed_when: false
54+
4755
- name: Reload systemd daemon to pick up permissions.conf
4856
ansible.builtin.systemd:
4957
daemon_reload: true

‎linux_os/guide/auditing/auditd_configure_rules/file_permissions_audit_configuration_stig/bash/shared.sh‎

Lines changed: 11 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -5,20 +5,22 @@
55
# disruption = low
66

77
# Copied and modified from `file_permissions/bash.template` template
8-
9-
if rpm --quiet -q audit && rpm --quiet -q kernel-core; then
8+
#
9+
# Sets mode 0600 and ownership root:root on all audit config files.
10+
# Installs an auditd.service dropin to restore 0600 on audit.rules after augenrules
11+
# rewrites it to 0640 when /etc/audit/rules.d/ content changes (RHEL 8/9 only, not containers).
1012

1113
find /etc/audit/ -maxdepth 1 -type f \
1214
-regextype posix-extended -regex '^.*audit(\.rules|d\.conf)$' \
13-
-exec chmod 0600 {} \;
15+
-exec chmod 0600 {} \; \
16+
-exec chown root:root {} \;
1417

1518
find /etc/audit/rules.d/ -maxdepth 1 -type f -name '*.rules' \
16-
-exec chmod 0600 {} \;
19+
-exec chmod 0600 {} \; \
20+
-exec chown root:root {} \;
21+
22+
if rpm --quiet -q audit && rpm --quiet -q kernel-core; then
1723

18-
# augenrules --load hardcodes chmod 0640 on audit.rules on every rewrite of the rules.d files.
19-
# Install ExecStartPost in auditd.service to restore 0600 after each run.
20-
# Runs inside the auditd_t SELinux domain which has write access to auditd_etc_t files.
21-
# On RHEL 8/9, augenrules is called via ExecStartPost in auditd.service directly.
2224
mkdir -p /etc/systemd/system/auditd.service.d
2325
chmod 0755 /etc/systemd/system/auditd.service.d
2426

@@ -27,9 +29,8 @@ cat > /etc/systemd/system/auditd.service.d/permissions.conf << 'EOF'
2729
ExecStartPost=/usr/bin/chmod 0600 /etc/audit/audit.rules
2830
EOF
2931
chmod 0644 /etc/systemd/system/auditd.service.d/permissions.conf
32+
restorecon /etc/systemd/system/auditd.service.d/permissions.conf
3033

3134
systemctl daemon-reload
3235

33-
else
34-
>&2 echo 'Remediation is not applicable, nothing was done'
3536
fi

‎linux_os/guide/auditing/auditd_configure_rules/file_permissions_audit_configuration_stig/rule.yml‎

Lines changed: 28 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -29,6 +29,34 @@ ocil: |-
2929
{{{ describe_file_permissions(file="/etc/audit/", perms="0600") }}}
3030
{{{ describe_file_permissions(file="/etc/audit/rules.d/", perms="0600") }}}
3131
32+
warnings:
33+
- general: |-
34+
On RHEL 8 and RHEL 9, the <tt>augenrules</tt> script unconditionally
35+
runs <tt>chmod 0640 /etc/audit/audit.rules</tt> every time it rewrites
36+
the file due to a rule change. <tt>auditd.service</tt> calls
37+
<tt>augenrules --load</tt> via <tt>ExecStartPost</tt> on every
38+
<tt>auditd</tt> restart, which resets <tt>/etc/audit/audit.rules</tt>
39+
to <tt>0640</tt> and undoes the <tt>0600</tt> permission set by
40+
remediation.
41+
The remediation installs a dropin at
42+
<tt>/etc/systemd/system/auditd.service.d/permissions.conf</tt> with a
43+
second <tt>ExecStartPost=/usr/bin/chmod 0600 /etc/audit/audit.rules</tt>.
44+
systemd runs both <tt>ExecStartPost</tt> commands in order —
45+
<tt>augenrules --load</tt> first, then the <tt>chmod 0600</tt> — so
46+
the correct mode is restored on every <tt>auditd</tt> restart.
47+
The dropin runs in the <tt>auditd_t</tt> SELinux domain, which has
48+
write access to <tt>auditd_etc_t</tt> files; no SELinux policy changes
49+
are needed.
50+
Note: <tt>auditd.service</tt> sets <tt>RefuseManualStart=yes</tt>.
51+
Restarting with <tt>systemctl restart auditd</tt> fails with
52+
"Operation refused". Use <tt>service auditd restart</tt> instead,
53+
which calls systemctl with <tt>--ignore-dependencies</tt> and bypasses
54+
that restriction.
55+
Calling <tt>augenrules --load</tt> directly outside of systemd still
56+
resets the mode to <tt>0640</tt> until the upstream
57+
<tt>audit-userspace</tt> package is patched to preserve existing
58+
permissions. Repeated scans detect the non-<tt>0600</tt> state.
59+
3260
template:
3361
name: file_permissions
3462
vars:

0 commit comments

Comments
 (0)