ComplianceAsCode / ComplianceAsCode/content
DISA-alignment mismatch on audit_rules_login_events_lastlog — SSG pass, DISA fail (RHEL 9.2/9.4/9.6/9.8/9.9)
- Dominant language
- Shell
- Stars
- 2.8k
- Forks
- 828
- Avg merge
- 3d 8m
- Merged PRs (30d)
- 80
Description
DISA-alignment testing shows a consistent mismatch for `audit_rules_login_events_lastlog`, reproduced across `oscap`, `anaconda`, and `ansible` remediation scenarios.
**Result:** SSG = `pass`, DISA = `fail`
**DISA rule ID:** `SV-258225r1210927_rule`
**Affected:** RHEL 9.2, 9.4, 9.6, 9.8, 9.9 — not 8.10.
See `audit_rules_sudoers_d` and `audit_rules_login_events_faillock` — likely same root-cause family among the RHEL-9-only `audit_rules_*` mismatches.
Contributor guide
Research direction
Start by reproducing audit_rules_login_events_lastlog across oscap, anaconda, and ansible on the listed RHEL 9 versions, then compare the SSG result with DISA rule SV-258225r1210927_rule. Check audit_rules_sudoers_d and audit_rules_login_events_faillock for the related mismatch pattern; done means the SSG and DISA results align without regressing RHEL 8.10.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- ansible, linux, shell
- Domain
- operating-systems, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Active
- Clarity
- Needs clarification
- Newbie friendliness
- 42/100