ComplianceAsCode / ComplianceAsCode/content

False Positive finding with `harden_sshd_ciphers_openssh_conf_crypto_policy` on Gitlab UBI 9 container

Open
#13,440 1 comment 0 reactions 0 assignees View on GitHub
triaged
Dominant language
Shell
Stars
2.8k
Forks
828
Avg merge
3d 8m
Merged PRs (30d)
80

Description

#### Description of problem:
- The check `xccdf_org.ssgproject.content_rule_harden_sshd_ciphers_openssh_conf_crypto_policy` in STIG mode presents a false positive finding when ran on our minimized UBI 9 containers.
- I have not identified the specific spot where the check is failing, but the check is either failing to access `/etc/crypto-policies/back-ends/openssh.config` or the regex is failing to parse the `Ciphers` line from the config file.

#### SCAP Security Guide Version:
- Using the packages available in the Ubuntu 24.04 repository
```
Package: ssg-base
Version: 0.1.71-1
Priority: optional
Section: universe/admin
Source: scap-security-guide
Origin: Ubuntu
```
```
Package: ssg-nondebian
Version: 0.1.71-1
Priority: optional
Section: universe/admin
Source: scap-security-guide
```

#### Operating System Version:
RHEL 9.5 / UBI 9.5

#### Steps to Reproduce:

1. Setup OpenSCAP, OpenSCAP-Podman, SSG - [relevant bootstrap script](https://gitlab.com/dwilmoth/scap-bootstrapping/-/blob/main/scap-boostrap.sh?ref_type=heads)
2. Pull the Gitlab CNG Fips container `podman pull registry.gitlab.com/gitlab-org/build/cng/gitlab-base:master-fips`
2. Run the check (replace `$image` with the image hash of the container) - `oscap-podman $image xccdf eval --report /tmp/cng-base-stig.html --profile xccdf_org.ssgproject.content_profile_stig /usr/share/xml/scap/ssg/content/ssg-rhel9-ds-1.2.xml`
3. Review the result HTML for "Configure SSH Client to Use FIPS 140-2 Validated Ciphers: openssh.config" and see that it fails
4. run the container, exec into it and check the ciphers manually -
- ` podman run --rm -it $image /bin/bash`
- `cat /etc/crypto-policies/back-ends/openssh.config | grep Ciphers`

#### Actual Results:
fail

#### Expected Results:
pass

#### Additional Information/Debugging Steps:
- This is not related to our containers not having `aes192-ctr` as I still get this issue when I tailor that out of the check.
- I was unable to find the exact check code when digging through the XML - if you can point me to the check in the code I can do more testing to see if I can provide a fix.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.