Commit graph

150 commits

Author SHA1 Message Date
Milan Lysonek
d9309972e0 Deprecate repository.
Remove last remaning files and update README where to find new
scap-security-guide tests.
2024-07-11 14:27:52 +02:00
Milan Lysonek
04775f1d20 Remove Sanity/smoke-test 2024-07-10 18:00:16 +02:00
Milan Lysonek
48ddf43968 Sanity/smoke-test: remove old unused adjust 2024-07-02 13:47:04 +02:00
Milan Lysonek
0eabefa58c Sanity/ansible-allowed-modules: remove test. Replaced by Contest /static-checks/ansible/allowed-modules 2024-07-02 13:46:48 +02:00
Milan Lysonek
2f0fe6eada Sanity/ansible-machine-hardening: remove test. Replaced by Contest /hardening/host-os/ansible 2024-07-02 13:45:50 +02:00
Milan Lysonek
5cff2011ea Sanity/machine-hardening: remove test. Replaced by Contest /hardening/host-os/oscap 2024-07-02 13:45:35 +02:00
Matus Marhefka
66582ef2b3 Remove scap-security-guide from tiers
We already run daily testing of to-be-released scap-security-guide
against latest RHEL nightlies, and we maintain a list of known
failures compared to that version.

Running tests against the released version of scap-security-guide
here in tiers not only wastes computing resources (any issues found
we wouldn't fix until the next release, tested by our daily runs),
but it also requires us to maintain a copy of the list of known
failures, specifically for this "old" released scap-security-guide.

Therefore, we came to the conclusion that we don't want to run
scap-security-guide (content) tests here in tiers.
2024-03-05 12:05:07 +01:00
Milan Lysonek
05734550e7 Sanity/smoke-test: 0.1.72 reviewed 2024-02-22 13:56:07 +01:00
Milan Lysonek
675df2d7e7 Merge #49 Allow FQCN ini_file in Ansible playbooks 2024-01-19 13:52:03 +00:00
Matthew Burket
225f5c5894
Allow FQCN ini_file in Ansible playbooks 2024-01-10 14:54:00 -06:00
Milan Lysonek
b86b0447ed Sanity/smoke-test: import scap-common library 2023-12-01 10:10:45 +01:00
Milan Lysonek
87985dac2c Sanity/smoke-test: install Ansible as well so it's tested in ctest 2023-12-01 09:40:26 +01:00
Milan Lysonek
3e04a8d8cd After Ansible installation, do not remove anything during cleanup 2023-12-01 09:33:45 +01:00
Milan Lysonek
9e42b02603 Library/scap-common: do not remove ansible-core 2023-11-30 16:23:57 +01:00
Milan Lysonek
668fa43c4e Disable SSL verification only for OSPP profile, where FIPS:OSPP is used 2023-11-08 15:29:35 +01:00
Milan Lysonek
d27b2f29b0 Reduce CI tests by removing CI tags 2023-10-10 17:08:32 +02:00
Milan Lysonek
5aaac6dc37 Sanity/smoke-test: remove not used tags 2023-10-10 16:08:59 +02:00
Milan Lysonek
d5ff3a57b6 Limit sslverify workaround to CentOS8<= 2023-10-06 11:59:02 +02:00
Milan Lysonek
09e33c7597 Sanity/ansible-machine-hardening: change workaround to force Ansible to use sslverify=false 2023-10-05 15:20:49 +02:00
Milan Lysonek
0fc2700166 Disable sslverify for CentOS because of weak RSA key in repos than FIPS:OSPP requires 2023-10-05 11:48:57 +02:00
Milan Lysonek
3221fc5738 Sanity/smoke-test: install dependencies also on CentOS 2023-09-05 13:50:41 +02:00
Marcus Burghardt
ec3acd3f4d Include library in pip3 install line too
This line was forgotten in the previous commit.
2023-09-05 11:01:48 +02:00
Marcus Burghardt
eba10bfa08 Include library used by utils/controleval.py
CI tests were failing because the prometheus-client library was not
present. See https://github.com/ComplianceAsCode/content/pull/11040
2023-09-05 10:52:54 +02:00
Milan Lysonek
90044c399b Sanity/machine-hardening: move the sshd waiver before 'unknown' check 2023-08-29 10:57:48 +02:00
Milan Lysonek
aff8ff3509 Sanity/machine-hardening: waiver for sshd_use_strong_macs 2023-08-28 14:58:49 +02:00
Milan Lysonek
8bed717db5 Sanity/smoke-test/review_notes: 0.1.69 check 2023-08-10 15:00:57 +02:00
Milan Lysonek
153ebf0f62 Sanity/machine-hardening: allow test on all CentOS distros 2023-07-28 09:51:49 +02:00
Jiri Jaburek
667aff7dee Sanity/machine-hardening: replace by Contest
The only distro/arch combos that Contest cannot run on are
RHEL-7 and s390x/ppc64 where EPEL isn't available.

Keep machine-hardening for those combinations.

Signed-off-by: Jiri Jaburek <jjaburek@redhat.com>
2023-07-25 13:15:59 +02:00
Jan Černý
8b2bbccf34 Add waivers for RHEL 9 CCN profiles
Waive rules that fail in the Sanity/ssg-kickstarts
tests and that are already waived in other profiles eg. CIS.
2023-07-24 13:39:35 +02:00
Milan Lysonek
a04fb7e052 Sanity/smoke-test: extend duration to 90min (because of Fedora CI) 2023-06-19 11:34:31 +02:00
Milan Lysonek
8a0d933d8e Library/scap-results/rule_waivers/rhel7: waive sysctl_net_ipv4_ip_forward in CIS Workstation 2023-06-06 10:08:58 +02:00
Milan Lysonek
6630b9509f Library/scap-results/rule_waivers: waive zipl_bootmap_is_up_to_date in CUI (same as in OSPP) 2023-05-31 09:35:02 +02:00
Milan Lysonek
adaf38dad7 Sanity/ansible-machine-hardening: TCMS export for remaining profile tests 2023-05-25 09:36:11 +02:00
Milan Lysonek
efa34a3940 Sanity/machine-hardening: skip ISM on RHEL7 2023-05-25 09:31:10 +02:00
Milan Lysonek
1faca2c660 Sanity/machine-hardening: TCMS export for remaining profile tests 2023-05-24 17:20:42 +02:00
Milan Lysonek
29254f3fa4 Library/scap-results/rule_waivers: waive service_nftables_disable because the service is not seen during first scan 2023-05-17 10:08:00 +02:00
Milan Lysonek
5042220fd5 Sanity/ansible-machine-hardening: add missing profile variants 2023-04-26 10:19:56 +00:00
Milan Lysonek
a08ba6ba5e Sanity/ansible-machine-hardening: change filename to reflect full profile identifier 2023-04-26 10:19:56 +00:00
Milan Lysonek
c4d2eb0905 Sanity/machine-hardening: add missing profile variants 2023-04-26 10:19:56 +00:00
Milan Lysonek
6338c5c37a Machine hardening tests as required in CI 2023-04-26 10:19:56 +00:00
Milan Lysonek
b9e82157b7 Sanity/smoke-test: reduce duration to 1h 2023-04-26 10:19:56 +00:00
Milan Lysonek
3f1de6a7a2 Introduce order numbers for general test plan 2023-04-25 17:06:17 +02:00
cortesana
40fd6a8fb9 Add daily productization tag 2023-04-14 14:27:56 +02:00
Milan Lysonek
21a4212584 Sanity/ansible-machine-hardening: unselect Ansible 2.9 incompatible rules on RHEL 8.4 2023-03-01 11:04:02 +01:00
Milan Lysonek
9eaabe95b4 Sanity/smoke-test: update review_notes to version 0.1.66 2023-02-15 11:37:20 +01:00
Milan Lysonek
fd0fd94d12 Waive rpcbind (beakerlib dependency) and world writable files (beakerlib issue) 2023-01-26 10:13:09 +01:00
Jan Černý
43fa6078e8 Waive rule sshd_use_approved_kex_ordered_stig
The rule sshd_use_approved_kex_ordered_stig depends on "installed
OS is FIPS certified" check so it never pass on CentOS 7.
This rule has been introduced to upstream by:
https://github.com/ComplianceAsCode/content/pull/10103
2023-01-25 16:14:38 +00:00
Milan Lysonek
f9a714e723 Library/scap-results/rule_waivers/rhel8: waive configure_bashrc_tmux (dependency problem) 2023-01-25 14:38:16 +01:00
Milan Lysonek
8f43e46880 Library/scap-results/rule_waivers/rhel8: remove temporary waivers 2023-01-16 12:08:33 +01:00
Milan Lysonek
b460eb802a Do not remove rsync in machine hardening 2023-01-13 09:53:06 +01:00