Skip to content

New Profile for RHEL9: BSI - #13700

Merged
Mab879 merged 5 commits into
ComplianceAsCode:masterfrom
sluetze:bsi-rhel9-sys
Jul 17, 2025
Merged

New Profile for RHEL9: BSI#13700
Mab879 merged 5 commits into
ComplianceAsCode:masterfrom
sluetze:bsi-rhel9-sys

Conversation

@sluetze

@sluetze sluetze commented Jul 14, 2025

Copy link
Copy Markdown
Contributor

Description:

This PR adds a new profile for RHEL9. The Profile covers the Building Blocks SYS.1.1 and SYS.1.3 of BSI Basic Protection. The BSI is the Federal Office for Security Information in Germany. This profile has been tested with RHEL9 servers in combination with RH Satellite.

Rationale:

This Profile mostly maps existing rules (with one exception see Review Hints) to the controls of the building blocks. Since these controls were already relevant for the RHCOS4 profile the way to a RHEL9 profile was quite short and obvious.

Review Hints:

I cherry-picked b7398e8 into this, as this profile relies on it. It was proposed in #13121 for the rhcos4 profile

@sluetze
sluetze requested a review from a team as a code owner July 14, 2025 12:46
@openshift-ci

openshift-ci Bot commented Jul 14, 2025

Copy link
Copy Markdown

Hi @sluetze. Thanks for your PR.

I'm waiting for a ComplianceAsCode member to verify that this patch is reasonable to test. If it is, they should reply with /ok-to-test on its own line. Until that is done, I will not automatically test new commits in this PR, but the usual testing commands by org members will still work. Regular contributors should join the org to skip this step.

Once the patch is verified, the new status will be reflected by the ok-to-test label.

I understand the commands that are listed here.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@openshift-ci openshift-ci Bot added the needs-ok-to-test Used by openshift-ci bot. label Jul 14, 2025

@Mab879 Mab879 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please fix the YAML formatting and missing CCEs. We have docs for adding cces.

@Mab879 Mab879 self-assigned this Jul 15, 2025
@sluetze
sluetze requested a review from Mab879 July 15, 2025 13:38

@Mab879 Mab879 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please review the CI failures.

Fixing the CCE definition format
@Mab879 Mab879 added this to the 0.1.78 milestone Jul 15, 2025
@sluetze

sluetze commented Jul 16, 2025

Copy link
Copy Markdown
Contributor Author

I think I fixed the relevant CI failures. Current failures are only systems, which do not find a test for the manual rule, which is not relevant for them.

@Mab879 Mab879 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the PR.

Please convert the multi line YAML to use |-.

Comment thread controls/bsi_sys_1_1_rhel9.yml Outdated
@Mab879
Mab879 merged commit dc86901 into ComplianceAsCode:master Jul 17, 2025
@sluetze
sluetze deleted the bsi-rhel9-sys branch July 23, 2025 09:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

needs-ok-to-test Used by openshift-ci bot.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants