ComplianceAsCode / ComplianceAsCode/content

DISA-alignment mismatch on audit_rules_login_events_lastlog — SSG pass, DISA fail (RHEL 9.2/9.4/9.6/9.8/9.9)

Open
#15,054 0 comments 0 reactions 0 assignees View on GitHub
productization-issue triaged
Dominant language
Shell
Stars
2.8k
Forks
828
Avg merge
3d 8m
Merged PRs (30d)
80

Description

DISA-alignment testing shows a consistent mismatch for `audit_rules_login_events_lastlog`, reproduced across `oscap`, `anaconda`, and `ansible` remediation scenarios.

**Result:** SSG = `pass`, DISA = `fail`
**DISA rule ID:** `SV-258225r1210927_rule`
**Affected:** RHEL 9.2, 9.4, 9.6, 9.8, 9.9 — not 8.10.

See `audit_rules_sudoers_d` and `audit_rules_login_events_faillock` — likely same root-cause family among the RHEL-9-only `audit_rules_*` mismatches.

Contributor guide

Open the contributing guide

Research direction

Start by reproducing audit_rules_login_events_lastlog across oscap, anaconda, and ansible on the listed RHEL 9 versions, then compare the SSG result with DISA rule SV-258225r1210927_rule. Check audit_rules_sudoers_d and audit_rules_login_events_faillock for the related mismatch pattern; done means the SSG and DISA results align without regressing RHEL 8.10.

Written by the indexing model from the issue text.

Assessment

Tech stack
ansible, linux, shell
Domain
operating-systems, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Active
Clarity
Needs clarification
Newbie friendliness
42/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.