Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

RHEL-08-010161 and RHEL-09-611205 removing keytab files, breaking sssd (misaligned with DISA) #11764

Open
GitYukari opened this issue Mar 27, 2024 · 0 comments
Labels
RHEL Red Hat Enterprise Linux product related. STIG STIG Benchmark related.

Comments

@GitYukari
Copy link

GitYukari commented Mar 27, 2024

Description of problem:

https://www.stigviewer.com/stig/red_hat_enterprise_linux_8/2023-09-11/finding/V-230238

The above STIG audits the presence of any keytab files in the location: /etc/*.keytab

However, this STIG has been revised since 2020 to state that if the installed package of krb5-server or krb5-workstation is newer than 1.17-18, then this check is N/A.

The current Ansible workbook is deleting this file regardless of the version of the above packages. This breaks Kerberos authentication and causes the sssd service to crash on startup.

This is directly related to: #11750

SCAP Security Guide Version:

0.1.72 (Feb 2024)

Operating System Version:

RHEL 8
RHEL 9

@GitYukari GitYukari changed the title RHEL-08-010161 removing keytab files, breaking sssd (misaligned with DISA) RHEL-08-010161 and RHEL-09-611205 removing keytab files, breaking sssd (misaligned with DISA) Mar 27, 2024
@marcusburghardt marcusburghardt added STIG STIG Benchmark related. RHEL Red Hat Enterprise Linux product related. labels Apr 18, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
RHEL Red Hat Enterprise Linux product related. STIG STIG Benchmark related.
Projects
None yet
Development

No branches or pull requests

2 participants