ComplianceAsCode / ComplianceAsCode/content

DISA-alignment mismatch on audit_rules_sudoers_d — SSG pass, DISA fail (RHEL 9.2/9.4/9.6/9.8/9.9)

Open
#15,052 0 comments 0 reactions 0 assignees View on GitHub
productization-issue triaged
Dominant language
Shell
Stars
2.8k
Forks
828
Avg merge
3d 8m
Merged PRs (30d)
80

Description

DISA-alignment testing shows a consistent mismatch for `audit_rules_sudoers_d`, reproduced across `oscap`, `anaconda`, and `ansible` remediation scenarios.

**Result:** SSG = `pass`, DISA = `fail`
**DISA rule ID:** `SV-258218r1210920_rule`
**Affected:** RHEL 9.2, 9.4, 9.6, 9.8, 9.9 — **not** RHEL 8.10, suggesting either the expected audit rule syntax differs between RHEL 8 and 9 STIG benchmarks, or the underlying audit rule content changed for RHEL 9 in a way that satisfies SSG but not DISA's expected form (e.g. auditctl rule field ordering, key naming, or path form for `/etc/sudoers.d`).

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.