ansible-lockdown / RHEL7-STIG

Ansible role for Red Hat 7 STIG Baseline

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

V2R6

jamescassell opened this issue · comments

  • RHEL-07-040500 V-72269 - Added "chrony" as a valid application that will satisfy the requirement. (hooray!)

If the "chronyd" process is found, then check the "chrony.conf" file for the "maxpoll" option setting:
# grep maxpoll /etc/chrony.conf
server 0.rhel.pool.ntp.org iburst maxpoll 10
If the option is not set or the line is commented out, this is a finding.

  • the rule-id changed for RHEL-07-010062 but we don't track those (yet)
  • the CCI reference changed for RHEL-07-010020 but we don't track those

https://vaulted.io/library/disa-stigs-srgs/red_hat_enterprise_linux_7_security_technical_implementation_guide?version=V2R5&compareto=V2R6