Commit graph

110 commits

Author SHA1 Message Date
Milan Lysonek
b9e82157b7 Sanity/smoke-test: reduce duration to 1h 2023-04-26 10:19:56 +00:00
Milan Lysonek
3f1de6a7a2 Introduce order numbers for general test plan 2023-04-25 17:06:17 +02:00
cortesana
40fd6a8fb9 Add daily productization tag 2023-04-14 14:27:56 +02:00
Milan Lysonek
21a4212584 Sanity/ansible-machine-hardening: unselect Ansible 2.9 incompatible rules on RHEL 8.4 2023-03-01 11:04:02 +01:00
Milan Lysonek
9eaabe95b4 Sanity/smoke-test: update review_notes to version 0.1.66 2023-02-15 11:37:20 +01:00
Milan Lysonek
fd0fd94d12 Waive rpcbind (beakerlib dependency) and world writable files (beakerlib issue) 2023-01-26 10:13:09 +01:00
Jan Černý
43fa6078e8 Waive rule sshd_use_approved_kex_ordered_stig
The rule sshd_use_approved_kex_ordered_stig depends on "installed
OS is FIPS certified" check so it never pass on CentOS 7.
This rule has been introduced to upstream by:
https://github.com/ComplianceAsCode/content/pull/10103
2023-01-25 16:14:38 +00:00
Milan Lysonek
f9a714e723 Library/scap-results/rule_waivers/rhel8: waive configure_bashrc_tmux (dependency problem) 2023-01-25 14:38:16 +01:00
Milan Lysonek
8f43e46880 Library/scap-results/rule_waivers/rhel8: remove temporary waivers 2023-01-16 12:08:33 +01:00
Milan Lysonek
b460eb802a Do not remove rsync in machine hardening 2023-01-13 09:53:06 +01:00
Milan Lysonek
5c5ecfd200 Sanity/ansible-machine-hardening: ensure NetworkManager is running 2023-01-03 17:19:11 +01:00
Milan Lysonek
3be807f362 Exclude aide_use_fips_hashes rule on CentOS as it requires FIPS certified OS 2023-01-03 17:10:21 +01:00
Milan Lysonek
5173c5aeeb Install firewalld as setup for hardening tests 2023-01-03 15:32:23 +01:00
Milan Lysonek
c1819e9d99 Sanity/ansible-machine-hardening: don't check FIPS certified OS on CentOS 2023-01-03 15:27:21 +01:00
Milan Lysonek
3a05515ca3 Sanity/machine-hardening: don't check FIPS certified OS on CentOS 2023-01-03 15:27:07 +01:00
Milan Lysonek
1dc8c310ea Library/scap-results/rule_waivers: temporary waive some PAM rules 2022-12-14 15:00:44 +01:00
Milan Lysonek
7e7facdc06 Library/scap-results/rule_waivers/rhel8: temporary ANSSI waiver 2022-12-13 16:13:22 +01:00
Milan Lysonek
4de4b2959e Sanity/ansible-machine-hardening: install NetworkManager required by some rules 2022-12-13 14:08:50 +01:00
Milan Lysonek
e7cb70ae62 Library/scap-results/rule_waivers: temporary ANSSI waiver 2022-12-12 15:50:59 +01:00
Milan Lysonek
fbb9db3e8a Sanity/ansible-allowed-modules: disable also on CentOS 7 2022-12-08 15:22:55 +01:00
Watson Sato
5375596b84 Sanity/machine-hardening: Don't test ANSSI on Fedora 2022-12-08 11:13:16 +01:00
Watson Sato
29a4d31ce4 Sanity/ansible-machine-hardening: Don't test ANSSI on Fedora 2022-12-08 11:12:47 +01:00
Matus Marhefka
d713267639 Sanity/ansible-machine-hardening: disable on RHEL7 ppc64 and s390x
We install Ansible from EPEL, but it doesn't support ppc64 and
s390x architectures, see
https://docs.fedoraproject.org/en-US/epel/#what_packages_and_versions_are_available_in_epel
2022-12-07 10:37:12 +01:00
Milan Lysonek
d93bd495e9 Sanity/ansible-machine-hardening: waiver for https://github.com/OpenSCAP/openscap/issues/1867 2022-12-01 12:22:52 +01:00
Milan Lysonek
eade3449e4 Sanity/ansible-machine-hardening: extend duration to 90min (mainly because of STIG profile) 2022-11-25 15:17:30 +01:00
Milan Lysonek
c43e0a4aec Sanity/ansible-machine-hardening: waive pcre_exec error 2022-11-25 13:15:52 +01:00
Milan Lysonek
ff4273a628 Sanity/ansible-machine-hardening: export CIS and ANSSI 2022-11-23 09:57:36 +01:00
Milan Lysonek
6b706c7432 Sanity/ansible-machine-hardening: add CIS and ANSSI TCs 2022-11-23 09:42:56 +01:00
Milan Lysonek
6939b7c9c9 Sanity/ansible-machine-hardening: export to TCMS 2022-11-09 11:49:23 +01:00
Milan Lysonek
332494eaec Sanity/ansible-machine-hardening: print to stdout 2022-11-09 11:48:29 +01:00
Milan Lysonek
e67811ffb5 Sanity/ansible-machine-hardening: add OSPP and STIG cases 2022-11-09 10:33:27 +01:00
Milan Lysonek
d64c9f18f2 Sanity/ansible-machine-hardening: new test case which tests Ansible playbook hardening 2022-11-09 10:33:00 +01:00
Milan Lysonek
33aa9a096d Library/scap-results/rule_waivers: update rhel9 waivers 2022-10-27 16:58:29 +02:00
Milan Lysonek
a2be7569c8 Library/scap-results/rule_waivers: update rhel8 waivers 2022-10-27 16:58:29 +02:00
Milan Lysonek
aa5f96d183 Library/scap-results/rule_waivers: update rhel7 waivers 2022-10-27 12:02:37 +02:00
Milan Lysonek
483fc68050 Sanity/machine-hardening: export CIS and ANSSI test cases 2022-10-26 17:20:01 +02:00
Milan Lysonek
ad4ec4dd36 Sanity/machine-hardening: extend with CIS and ANSSI test cases 2022-10-26 16:59:58 +02:00
Milan Lysonek
29087a5135 Sanity/machine-hardening: scap-common import not needed because it's imported with scap-results lib 2022-10-21 13:46:56 +02:00
Milan Lysonek
7ca6f21d8a Library/scap-results: make scap-common library as scap-results library dependency 2022-10-21 11:40:34 +02:00
Milan Lysonek
9cf8ca43f2 Library/scap-results: make datastream required argument 2022-10-21 11:40:34 +02:00
Milan Lysonek
a500c86fd1 Sanity/machine-hardening: waiver for https://github.com/OpenSCAP/openscap/issues/1867 2022-10-20 14:43:08 +02:00
Matus Marhefka
25e668a36d Sanity/ansible-allowed-modules: make sure allowed modules are obtained properly on Fedora 2022-10-18 13:55:21 +02:00
Matus Marhefka
247d89e594 Sanity/machine-hardening: utilize scap-common library 2022-10-14 18:10:38 +02:00
Matus Marhefka
5718ac0b6c Sanity/ansible-allowed-modules: utilize scap-common library 2022-10-14 13:41:20 +02:00
Matus Marhefka
a81377d5f2 Library/scap-common: new library with common functions for work with SCAP content 2022-10-14 10:59:01 +02:00
Matus Marhefka
6ceba21be9 Sanity/machine-hardening: handle properly disabling FIPS mode on RHEL7 2022-10-05 15:26:49 +02:00
Gabriel Becker
42df391bb4 Add RHEL9 waivers for rpm_verify_permissions (STIG, STIG_GUI). 2022-09-26 11:03:23 +02:00
Matus Marhefka
b3872e74c1 Sanity/machine-hardening: fix sos reports generation
Fixed sos reports generation, we used incorrect timestamp which was generated
after hardening and reboot, now the test uses the timestamp generated before
the hardening and loads it from filesystem after reboot.

There is also optimization when downloading and unselecting rules, we do it
only once now at the beginning of the test and store the updated datastream
on filesystem.
2022-09-23 14:02:28 +02:00
Matus Marhefka
7827b69a1c Sanity/machine-hardening: enable testing of FIPS rules 2022-09-23 14:02:18 +02:00
Matus Marhefka
31ef06b3fa Add RHEL8 and RHEL9 waivers for zipl_bootmap_is_up_to_date rule (OSPP) 2022-08-26 17:35:24 +02:00