diff --git a/dist b/dist deleted file mode 100644 index ad8eb77ba59be071474988a034571694eaa9db8e..0000000000000000000000000000000000000000 --- a/dist +++ /dev/null @@ -1 +0,0 @@ -an7_9 diff --git a/download b/download index c49e2f616c04320a4122e0cf9ae1b82adef00c01..9f5c9ebc068987423e0c97f05813e7f4fc20cbee 100644 --- a/download +++ b/download @@ -1,2 +1,2 @@ 219c992603514558e5f6f3d29adaa534 scap-security-guide-0.1.52-2.el7_9-rhel6.tar.bz2 -ac9d4fcc5a6f44bf63a0b9b065b6b3e9 scap-security-guide-0.1.69.tar.bz2 +28d1e8f00402c11fc0578a047096dee6 scap-security-guide-0.1.72.tar.bz2 diff --git a/disable-not-in-good-shape-profiles.patch b/hide-profiles-not-in-good-shape-for-RHEL.patch similarity index 31% rename from disable-not-in-good-shape-profiles.patch rename to hide-profiles-not-in-good-shape-for-RHEL.patch index f883e6ab46feea67047ddffceefd17a5c241bbee..40a7a28106794472405ee8f9461d73bb5409b335 100644 --- a/disable-not-in-good-shape-profiles.patch +++ b/hide-profiles-not-in-good-shape-for-RHEL.patch @@ -1,61 +1,54 @@ -From 746381a4070fc561651ad65ec0fe9610e8590781 Mon Sep 17 00:00:00 2001 -From: Watson Sato -Date: Mon, 6 Feb 2023 14:44:17 +0100 -Subject: [PATCH] Disable profiles not in good shape +From e0f62e3828b9deda102f247b3789f68aeb4e518d Mon Sep 17 00:00:00 2001 +From: Marcus Burghardt +Date: Fri, 16 Feb 2024 12:07:36 +0100 +Subject: [PATCH] Hide profiles not in good shape for RHEL -Patch-name: disable-not-in-good-shape-profiles.patch -Patch-id: 0 -Patch-status: | - Patch prevents cjis, rht-ccp and standard profiles in RHEL8 datastream +There are some profiles introduced long time ago but no longer +maintained. For compatibility purposes they are not removed from +datastream but are now hidden for RHEL8 to prevent people from +using them. --- - products/rhel8/CMakeLists.txt | 1 - - products/rhel8/profiles/cjis.profile | 2 +- - products/rhel8/profiles/rht-ccp.profile | 2 +- - products/rhel8/profiles/standard.profile | 2 +- - 4 files changed, 3 insertions(+), 4 deletions(-) + products/rhel8/profiles/cjis.profile | 2 ++ + products/rhel8/profiles/rht-ccp.profile | 2 ++ + products/rhel8/profiles/standard.profile | 2 ++ + 3 files changed, 6 insertions(+) -diff --git a/products/rhel8/CMakeLists.txt b/products/rhel8/CMakeLists.txt -index 9c044b68ab..8f6ca03de8 100644 ---- a/products/rhel8/CMakeLists.txt -+++ b/products/rhel8/CMakeLists.txt -@@ -10,7 +10,6 @@ ssg_build_product(${PRODUCT}) - ssg_build_html_ref_tables("${PRODUCT}" "table-${PRODUCT}-{ref_id}refs" "anssi;cis;cui;nist;pcidss") - - ssg_build_html_profile_table("table-${PRODUCT}-nistrefs-ospp" "${PRODUCT}" "ospp" "nist") --ssg_build_html_profile_table("table-${PRODUCT}-nistrefs-standard" "${PRODUCT}" "standard" "nist") - ssg_build_html_profile_table("table-${PRODUCT}-nistrefs-stig" "${PRODUCT}" "stig" "nist") - - ssg_build_html_profile_table("table-${PRODUCT}-anssirefs-bp28_minimal" "${PRODUCT}" "anssi_bp28_minimal" "anssi") diff --git a/products/rhel8/profiles/cjis.profile b/products/rhel8/profiles/cjis.profile -index 22ae5aac72..f60b65bc06 100644 +index 30843b692e..c44c63516f 100644 --- a/products/rhel8/profiles/cjis.profile +++ b/products/rhel8/profiles/cjis.profile -@@ -1,4 +1,4 @@ --documentation_complete: true -+documentation_complete: false +@@ -1,5 +1,7 @@ + documentation_complete: true ++hidden: true ++ metadata: version: 5.4 + SMEs: diff --git a/products/rhel8/profiles/rht-ccp.profile b/products/rhel8/profiles/rht-ccp.profile -index b192461f95..ae1e7d5a15 100644 +index 01133a9bde..3f6cb751c9 100644 --- a/products/rhel8/profiles/rht-ccp.profile +++ b/products/rhel8/profiles/rht-ccp.profile -@@ -1,4 +1,4 @@ --documentation_complete: true -+documentation_complete: false +@@ -1,5 +1,7 @@ + documentation_complete: true ++hidden: true ++ title: 'Red Hat Corporate Profile for Certified Cloud Providers (RH CCP)' + description: |- diff --git a/products/rhel8/profiles/standard.profile b/products/rhel8/profiles/standard.profile -index a63ae2cf32..da669bb843 100644 +index 11d72da2d9..79b491113a 100644 --- a/products/rhel8/profiles/standard.profile +++ b/products/rhel8/profiles/standard.profile -@@ -1,4 +1,4 @@ --documentation_complete: true -+documentation_complete: false +@@ -1,5 +1,7 @@ + documentation_complete: true ++hidden: true ++ title: 'Standard System Security Profile for Red Hat Enterprise Linux 8' + description: |- -- -2.39.1 +2.43.1 diff --git a/scap-security-guide-0.1.52-2.el7_9-rhel6.tar.bz2 b/scap-security-guide-0.1.52-2.el7_9-rhel6.tar.bz2 deleted file mode 100644 index de9ae050870d330cfa22be66e731c4dd6a3890fb..0000000000000000000000000000000000000000 Binary files a/scap-security-guide-0.1.52-2.el7_9-rhel6.tar.bz2 and /dev/null differ diff --git a/scap-security-guide-0.1.69.tar.bz2 b/scap-security-guide-0.1.69.tar.bz2 deleted file mode 100644 index c9321aa7777f364cf5ac8c70118db76d478076f0..0000000000000000000000000000000000000000 Binary files a/scap-security-guide-0.1.69.tar.bz2 and /dev/null differ diff --git a/scap-security-guide.spec b/scap-security-guide.spec index 3170fd58a0f56527f002bdc5643a40d813a5605c..903d6070b6d6a593c2af2051d989b176e6863c9c 100644 --- a/scap-security-guide.spec +++ b/scap-security-guide.spec @@ -6,8 +6,8 @@ %global _static_rhel6_content %{name}-0.1.52-2.el7_9-rhel6 Name: scap-security-guide -Version: 0.1.69 -Release: 1%{?dist} +Version: 0.1.72 +Release: 2%{?dist} Summary: Security guidance and baselines in SCAP formats Group: System Environment/Base @@ -16,9 +16,8 @@ URL: https://github.com/ComplianceAsCode/content Source0: %{name}-%{version}.tar.bz2 # Include tarball with last shipped rhel6 content Source1: %{_static_rhel6_content}.tar.bz2 -# Disable profiles not in good shape -# rhel8 - cjis rht-ccp standard -Patch0: disable-not-in-good-shape-profiles.patch +# Patch hides cjis, rht-ccp and standard profiles for RHEL8 +Patch0: hide-profiles-not-in-good-shape-for-RHEL.patch BuildArch: noarch @@ -121,6 +120,13 @@ cp -r %{_builddir}/%{_static_rhel6_content}/guides %{_builddir}/%{name}-%{versio %endif %changelog +* Fri Feb 16 2024 Marcus Burghardt - 0.1.72-2 +- Unlist profiles no longer maintained in RHEL8. + +* Wed Feb 14 2024 Marcus Burghardt - 0.1.72-1 +- Rebase to a new upstream release 0.1.72 (RHEL-25251) +- Include filter to dracut files in audit_rules_privileged_commands rule (RHEL-11938) + * Fri Aug 04 2023 Jan Černý - 0.1.69-1 - Rebase to the latest upstream release (RHBZ#2221694) - Make IPv6 related rules applicable only in case IPv6 is actually enabled. (RHBZ#2210276)