Skip to content

Update RHEL 9 CCN profile#14321

Merged
Mab879 merged 8 commits intoComplianceAsCode:masterfrom
vojtapolasek:fix_ccn
Jan 23, 2026
Merged

Update RHEL 9 CCN profile#14321
Mab879 merged 8 commits intoComplianceAsCode:masterfrom
vojtapolasek:fix_ccn

Conversation

@vojtapolasek
Copy link
Collaborator

Description:

  • see commit messages, this PR is only about changes in the RHEL 9 CCN control file

Note that I deliberately did not add one rule to the control; mount_option_boot_noauto. This rule has some problem and it needs more investigation.

Rationale:

  • Alignment with official CCN profile.

The profile can be found here: https://www.ccn-cert.cni.es/es/guias-de-acceso-publico-ccn-stic/6768-ccn-stic-610a22-perfilado-de-seguridad-red-hat-enterprise-linux-9-0/file.html

The guide references some configuration scripts. They can be founnd here: https://www.ccn-cert.cni.es/pdf/guias/series-ccn-stic/guias-de-acceso-publico-ccn-stic/6771-ccn-stic-610a22-perfilado-de-seguridad-red-hat-enterprise-linux-9-0-script.html

Please note that our rules configure some features differently than official CCN scripts, for example some parameters for faillock are configured in /etc/security/faillock.conf instead of files within the /etc/pam.d directory.

Review Hints:

Review changes against the CCN. Test the profile through Automatus or Autocontest.

@vojtapolasek vojtapolasek added this to the 0.1.80 milestone Jan 22, 2026
@vojtapolasek vojtapolasek added RHEL9 Red Hat Enterprise Linux 9 product related. Update Profile Issues or pull requests related to Profiles updates. CCN CCN Benchmark related. labels Jan 22, 2026
@Mab879 Mab879 self-assigned this Jan 22, 2026
notes: |-
Related to nosuid, noexec and nodev options but in /boot. More context is needed.
status: automated
rules:
Copy link
Member

@Mab879 Mab879 Jan 22, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Do we also need to check /boot/efi as well. The PDF says we do. If we not checking /boot/efi we should add a note about why.

Copy link
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ACtually I Google translated the guide and it seems /boot/efi should be checked as well. We have only one rule, I added it and I also added a note. I think this should be investigated separately, because I find it suspicious that we do not have other rules... maybe they do not make sense?

@github-actions
Copy link

github-actions bot commented Jan 22, 2026

ATEX Test Results

Test artifacts have been submitted to Testing Farm.

Results: View Test Results
Workflow Run: View Workflow Details

This comment was automatically generated by the ATEX workflow.

add note that we do not currently have more rules regarding /boot/efi
@Mab879 Mab879 merged commit dc73388 into ComplianceAsCode:master Jan 23, 2026
141 of 144 checks passed
@ggbecker ggbecker added the Highlight This PR/Issue should make it to the featured changelog. label Mar 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CCN CCN Benchmark related. Highlight This PR/Issue should make it to the featured changelog. RHEL9 Red Hat Enterprise Linux 9 product related. Update Profile Issues or pull requests related to Profiles updates.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants