ComplianceAsCode / ComplianceAsCode/content

DISA-alignment mismatch on audit_rules_login_events_faillock — SSG pass, DISA fail (RHEL 9.2/9.4/9.6/9.8/9.9)

Open
#15,053 0 comments 0 reactions 0 assignees View on GitHub
productization-issue triaged
Dominant language
Shell
Stars
2.8k
Forks
828
Avg merge
3d 8m
Merged PRs (30d)
80

Description

DISA-alignment testing shows a consistent mismatch for `audit_rules_login_events_faillock`, reproduced across `oscap`, `anaconda`, and `ansible` remediation scenarios.

**Result:** SSG = `pass`, DISA = `fail`
**DISA rule ID:** `SV-258224r1210926_rule`
**Affected:** RHEL 9.2, 9.4, 9.6, 9.8, 9.9 — not 8.10.

Likely related to the `audit_rules_sudoers_d` and `audit_rules_login_events_lastlog` mismatches — all three RHEL-9-only `audit_rules_*` cases may share a common cause (e.g. an audit rule syntax or path expectation that changed for RHEL 9 STIG content). Worth investigating together.

Contributor guide

Open the contributing guide

Research direction

Start by reproducing the mismatch through the oscap, anaconda, and ansible scenarios on the listed RHEL 9 versions, then compare audit_rules_login_events_faillock with the related audit_rules_sudoers_d and audit_rules_login_events_lastlog cases. Done means identifying the shared cause, documenting the RHEL 9-only difference, and confirming SSG and DISA results agree without affecting RHEL 8.10.

Written by the indexing model from the issue text.

Assessment

Tech stack
ansible, linux, shell
Domain
operating-systems, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Active
Clarity
Needs clarification
Newbie friendliness
38/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.