SEARCH
NEW RPMS
DIRECTORIES
ABOUT
FAQ
VARIOUS
BLOG

 
 
Changelog for scap-security-guide-0.1.30-3.sl7.noarch.rpm :
Mon Nov 7 13:00:00 2016 Scientific Linux Auto Patch Process
- Added Source: scap-security-guide_spec-add-all-el-stigs.patch
--> Package all EL scap guidelines, not just TUV
- Added Patch: 0002-Rebrand-title-description-of-derivatives.patch
--> de-brand titles and descriptions
- Added Source: scap-security-guide.ini
--> Config file for automated patch script

Wed Aug 10 14:00:00 2016 Jan iankko Lieskovsky 0.1.30-3
- Correct the remediation script for \'Enable Smart Card Login\' rule
for Red Hat Enterprise Linux 7 (RH BZ#1357019)

Thu Jul 14 14:00:00 2016 Jan iankko Lieskovsky 0.1.30-2
- Fix issue of two STIG profiles for Red Hat Enterprise Linux 6 benchmark
having the identical title (RH BZ#1351541)
- Enhance the shared OVAL check for \'Set Deny For Failed Password Attempts\'
rule and also Red Hat Enterprise Linux 7 OVAL check for \'Configure the root
Account for Failed Password Attempts\' rule to report correct system status
WRT to these requirements also in the case the SSSD daemon is used
(RH BZ#1344581)
- Include currently available kickstart files and produced HTML tables for
Red Hat Enterprise Linux 6 and 7 products into the produced RPM package
(RH BZ#1351751)

Wed Jun 22 14:00:00 2016 Jan iankko Lieskovsky 0.1.30-1
- Update to upstream\'s 0.1.30 release:
https://github.com/OpenSCAP/scap-security-guide/releases/tag/v0.1.30
(RH BZ#1289533)
- Drop remediation functions library since starting from 0.1.30 release
remediation scripts are part of the benchmarks directly
- Drop three patches that have been accepted upstream in the meantime
- Update drop-rpm-verify-permissions-rule patch to work properly against
0.1.30 release

Fri Oct 2 14:00:00 2015 Jan iankko Lieskovsky 0.1.25-3
- Drop \"Verify and Correct File Permissions with RPM\" rule from the PCI-DSS
profile for Red Hat Enterprise Linux 7 (RH BZ#1267861)

Wed Sep 9 14:00:00 2015 Jan iankko Lieskovsky 0.1.25-2
- Update R and BR for the openscap-scanner package to 1.2.5 per RHBZ#1202762#c7

Wed Aug 19 14:00:00 2015 Jan iankko Lieskovsky 0.1.25-1
- Rebase to upstream 0.1.25 release

Tue Aug 4 14:00:00 2015 Jan iankko Lieskovsky 0.1.24-4
- Fix false-positive in OVAL check for \'accounts_passwords_pam_faillock_deny\'
rule

Mon Aug 3 14:00:00 2015 Jan iankko Lieskovsky 0.1.24-3
- Add remediation script for \'accounts_passwords_pam_faillock_unlock_time\' rule
for Red Hat Enterprise Linux 7 product
- Override title and description for all existing profiles for Red Hat
Enterprise Linux 6 product that are extending another SCAP profile
(RHBZ#1246529)
- Correct various issues in the included Oscap Anaconda Addon PCI-DSS profile
kickstart file for Red Hat Enterprise Linux 7 product
- Add remediation script for \'audit_rules_time_clock_settime\' rule for
Red Hat Enterprise Linux 7 product
- Add remediation scripts for \'audit_rules_time_adjtimex\',
\'audit_rules_time_settimeofday\', and \'audit_rules_time_stime\' rules for
Red Hat Enterprise Linux 7 product
- Tag current PCI-DSS profile for Red Hat Enterprise Linux 7 product with
\"Draft\" label
- Disable the following rules in the PCI-DSS profile for the Red Hat Enterprise
Linux 7 product:

* dconf_gnome_screensaver_idle_delay -- missing remediation script,

* dconf_gnome_screensaver_idle_activation -- missing remediation script,

* dconf_gnome_screensaver_lock_enabled -- missing remediation script,

* audit_rules_login_events -- incorrect OVAL check (upstream issue #607),

* audit_rules_privileged_commands -- missing remediation script, and

* audit_rules_immutable -- missing remediation script.

Mon Aug 3 14:00:00 2015 Martin Preisler 0.1.24-2
- Break-down firewalld rule description for Red Hat Enterprise Linux 7 product
into multiple lines, prevents HTML guide UX issues

Tue Jul 7 14:00:00 2015 Jan iankko Lieskovsky 0.1.24-1
- Rebase to upstream scap-security-guide-0.1.24 version
- Start producing the -doc subpackage to provide the HTML formatted
documents containing security guides generated from shipped XCCDF benchmarks

Mon Jun 22 14:00:00 2015 Jan iankko Lieskovsky 0.1.23-1
- Rebase to upstream scap-security-guide-0.1.23 version
- Update upstream tarball source URL to GitHub archive location
- Drop the following patches that have been accepted upstream:

* scap-security-guide-0.1.19-rhel7-include-only-rht-ccp-profile.patch

* scap-security-guide-0.1.19-rhel7-drop-restorecond-since-in-optional.patch

* scap-security-guide-0.1.19-update-man-page-for-rhel7-content.patch

* scap-security-guide-0.1.19-rhel7-update-pam-XCCDF-to-use-pam_pwquality.patch

* scap-security-guide-0.1.20-rhel7-shared-fix-limit-password-reuse-remediation.patch

* scap-security-guide-0.1.20-rhel6-rhel7-PR#280-set-deny-prerequisite-#1.patch

* scap-security-guide-0.1.20-rhel6-rhel7-set-deny-prerequisite-#2.patch

* scap-security-guide-0.1.20-shared-fix-set-deny-for-failed-password-attempts-remediation.patch

* scap-security-guide-0.1.20-rhel7-specify-exact-profile-name-when-generating-guide.patch
- Include the datastream versions of Firefox and Java Runtime Environment (JRE) benchmarks
- Include USGCB and DISA STIG profile kickstart files for Red Hat Enterprise Linux 6

Tue Oct 21 14:00:00 2014 Jan iankko Lieskovsky 0.1.19-2
- Fix Limit Password Reuse remediation script error
- Fix Set Deny For Failed Password Attempts remediation script error
- Use RHT-CCP profile name when generating HTML guide
- Describe RHT-CCP profile in the manual page

Mon Sep 29 14:00:00 2014 Jan iankko Lieskovsky 0.1.19-1
- Include RHEL-7 content (RHT-CCP profile only)
- Drop RHEL-7 restorecond XCCDF rule since policycoreutils-restorecond in Optional channel
- Drop RHEL-7 cpuspeed XCCDF rule since obsoleted by cpupower from kernel-tools
- Update manual page to be more appropriate for RHEL-7
- Drop RHEL-6 C2S profile update patch since merged upstream

Tue Sep 2 14:00:00 2014 Jan iankko Lieskovsky 0.1.18-4
- Initial build for Red Hat Enterprise Linux 7

Thu Aug 28 14:00:00 2014 Jan iankko Lieskovsky 0.1.18-3
- Update C2S profile per request from CIS

Thu Jun 26 14:00:00 2014 Jan iankko Lieskovsky 0.1.18-2
- Include the upstream STIG for RHEL 6 Server profile disclaimer file too

Sun Jun 22 14:00:00 2014 Jan iankko Lieskovsky 0.1.18-1
- Make new 0.1.18 release

Wed May 14 14:00:00 2014 Jan iankko Lieskovsky 0.1.17-2
- Drop vendor line from the spec file. Let the build system to provide it.

Fri May 9 14:00:00 2014 Jan iankko Lieskovsky 0.1.17-1
- Upgrade to upstream 0.1.17 version

Mon May 5 14:00:00 2014 Jan iankko Lieskovsky 0.1.16-2
- Initial RPM for RHEL base channels

Mon May 5 14:00:00 2014 Jan iankko Lieskovsky 0.1.16-1
- Change naming scheme (0.1-16 => 0.1.16-1)

Fri Feb 21 13:00:00 2014 Jan iankko Lieskovsky 0.1-16
- Include datastream file into RHEL6 RPM package too
- Bump version

Tue Dec 24 13:00:00 2013 Shawn Wells 0.1-16.rc2
+ RHEL6 stig-rhel6-server XCCDF profile renamed to stig-rhel6-server-upstream

Mon Dec 23 13:00:00 2013 Shawn Wells 0.1-16.rc1
- [bugfix] RHEL6 no_empty_passwords remediation script overwrote
system-auth symlink. Added --follow-symlink to sed command.

Fri Nov 1 13:00:00 2013 Jan iankko Lieskovsky 0.1-15
- Version bump

Sat Oct 26 14:00:00 2013 Jan iankko Lieskovsky 0.1-15.rc5
- Point the spec\'s source to proper remote tarball location
- Modify the main Makefile to use remote tarball when building RHEL/6\'s SRPM

Sat Oct 26 14:00:00 2013 Jan iankko Lieskovsky 0.1-15.rc4
- Don\'t include the table html files two times
- Remove makewhatis

Fri Oct 25 14:00:00 2013 Shawn Wells 0.1-15.rc3
- [bugfix] Updated rsyslog_remote_loghost to scan /etc/rsyslog.conf and /etc/rsyslog.d/
*
- Numberous XCCDF->OVAL naming schema updates
- All rules now have CCE

Fri Oct 25 14:00:00 2013 Shawn Wells 0.1-15.rc2
- RHEL/6 HTML table naming bugfixes (table-rhel6-
*, not table-
*-rhel6)

Fri Oct 25 14:00:00 2013 Jan iankko Lieskovsky 0.1-15.rc1
- Apply spec file changes required by review request (RH BZ#1018905)

Thu Oct 24 14:00:00 2013 Shawn Wells 0.1-14
- Formal RPM release
- Inclusion of rht-ccp profile
- OVAL unit testing patches
- Bash remediation patches
- Bugfixes

Mon Oct 7 14:00:00 2013 Jan iankko Lieskovsky 0.1-14.rc1
- Change RPM versioning scheme to include release into tarball

Sat Sep 28 14:00:00 2013 Shawn Wells 0.1-13
- Updated RPM spec file to fix rpmlint warnings

Wed Jun 26 14:00:00 2013 Shawn Wells 0.1-12
- Updated RPM version to 0.1-12

Fri Apr 26 14:00:00 2013 Shawn Wells 0.1-11
- Significant amount of OVAL bugfixes
- Incorporation of Draft RHEL/6 STIG feedback

Sat Feb 16 13:00:00 2013 Shawn Wells 0.1-10
- `man scap-security-guide`
- OVAL bug fixes
- NIST 800-53 mappings update

Wed Nov 28 13:00:00 2012 Shawn Wells 0.1-9
- Updated BuildRequires to reflect python-lxml (thank you, Ray S.!)
- Reverting to noarch RPM

Tue Nov 27 13:00:00 2012 Shawn Wells 0.1-8
- Significant copy editing to XCCDF rules per community
feedback on the DISA RHEL/6 STIG Initial Draft

Thu Nov 1 13:00:00 2012 Shawn Wells 0.1-7
- Corrected XCCDF content errors
- OpenSCAP now supports CPE dictionaries, important to
utilize --cpe-dict when scanning machines with OpenSCAP,
e.g.:
$ oscap xccdf eval --profile stig-server \\
--cpe-dict ssg-rhel6-cpe-dictionary.xml ssg-rhel6-xccdf.xml

Mon Oct 22 14:00:00 2012 Shawn Wells 0.1-6
- Corrected RPM versioning, we\'re on 0.1 release 6 (not version 1 release 6)
- Updated RPM includes feedback received from DoD Consensus meetings

Fri Oct 5 14:00:00 2012 Jeffrey Blank 1.0-5
- Adjusted installation directory to /usr/share/xml/scap.

Tue Aug 28 14:00:00 2012 Spencer Shimko 1.0-4
- Fix BuildRequires and Requires.

Tue Jul 3 14:00:00 2012 Jeffrey Blank 1.0-3
- Modified install section, made description more concise.

Thu Apr 19 14:00:00 2012 Spencer Shimko 1.0-2
- Minor updates to pass some variables in from build system.

Mon Apr 2 14:00:00 2012 Shawn Wells 1.0-1
- First attempt at SSG RPM. May ${deity} help us...


 
ICM