ComplianceAsCode / ComplianceAsCode/content
DISA-alignment mismatch on audit_rules_sudoers_d — SSG pass, DISA fail (RHEL 9.2/9.4/9.6/9.8/9.9)
Open
productization-issue
triaged
- Dominant language
- Shell
- Stars
- 2.8k
- Forks
- 828
- Avg merge
- 3d 8m
- Merged PRs (30d)
- 80
Description
DISA-alignment testing shows a consistent mismatch for `audit_rules_sudoers_d`, reproduced across `oscap`, `anaconda`, and `ansible` remediation scenarios.
**Result:** SSG = `pass`, DISA = `fail`
**DISA rule ID:** `SV-258218r1210920_rule`
**Affected:** RHEL 9.2, 9.4, 9.6, 9.8, 9.9 — **not** RHEL 8.10, suggesting either the expected audit rule syntax differs between RHEL 8 and 9 STIG benchmarks, or the underlying audit rule content changed for RHEL 9 in a way that satisfies SSG but not DISA's expected form (e.g. auditctl rule field ordering, key naming, or path form for `/etc/sudoers.d`).
Contributor guide
Assessment
This issue has not been assessed yet.