ComplianceAsCode / ComplianceAsCode/content
DISA-alignment mismatch on audit_rules_login_events_faillock — SSG pass, DISA fail (RHEL 9.2/9.4/9.6/9.8/9.9)
- Dominant language
- Shell
- Stars
- 2.8k
- Forks
- 828
- Avg merge
- 3d 8m
- Merged PRs (30d)
- 80
Description
DISA-alignment testing shows a consistent mismatch for `audit_rules_login_events_faillock`, reproduced across `oscap`, `anaconda`, and `ansible` remediation scenarios.
**Result:** SSG = `pass`, DISA = `fail`
**DISA rule ID:** `SV-258224r1210926_rule`
**Affected:** RHEL 9.2, 9.4, 9.6, 9.8, 9.9 — not 8.10.
Likely related to the `audit_rules_sudoers_d` and `audit_rules_login_events_lastlog` mismatches — all three RHEL-9-only `audit_rules_*` cases may share a common cause (e.g. an audit rule syntax or path expectation that changed for RHEL 9 STIG content). Worth investigating together.
Contributor guide
Research direction
Start by reproducing the mismatch through the oscap, anaconda, and ansible scenarios on the listed RHEL 9 versions, then compare audit_rules_login_events_faillock with the related audit_rules_sudoers_d and audit_rules_login_events_lastlog cases. Done means identifying the shared cause, documenting the RHEL 9-only difference, and confirming SSG and DISA results agree without affecting RHEL 8.10.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- ansible, linux, shell
- Domain
- operating-systems, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Active
- Clarity
- Needs clarification
- Newbie friendliness
- 38/100