Skip to content

Releases: ansible-lockdown/RHEL8-STIG

Final - STIG V1R13 release

13 Aug 15:06
48e6bc9
Compare
Choose a tag to compare

STIG Version1 Release 13 release - Jan 24

Remediate

Pre-commit updates
new workflow configurations
removed jmespath dependency

Audit

Improvements and updates

What's Changed

Full Changelog: 3.3.0...3.3.1

STIG V1R13 release

31 May 13:20
9981f76
Compare
Choose a tag to compare

STIG Version1 Release 13 release - Jan 24

Main Release for v1r13 RHEL8 STIG

Remediate

  • Issues closed and PRs merged - What's changed
  • Pre-commit updates
  • Many improvements to different controls
  • Rebase required from v1r12

Audit

  • Related Audit repo updated to improve tests audit binary(goss updated to latest version)

What's Changed

Full Changelog: 3.2.0...3.3.0

STIG v1r12 - April 2024 update

30 Apr 07:51
26e9ed2
Compare
Choose a tag to compare

STIG Version1 Release 12 release - October 23

Main Release for v1r12 RHEL8 STIG

Remediate

  • Issues closed and PRs merged - What's changed
  • Pre-commit updates
  • Many improvements to different controls

Audit

  • Audit_only ability now added to run standalone audit
    • audit_only: true
  • Related Audit repo updated to improve tests audit binary(goss updated to latest version)

What's Changed

Full Changelog: 3.1.0...3.2.0

Final STIG V1R11

19 Mar 16:40
1c4b7db
Compare
Choose a tag to compare

STIG Version1 Release 11 release - July 23

Remediate

Issues closed and PRs merged - What's changed
Pre-commit updates
Many improvements to different controls
Update to allow Galaxy Releases for new galaxy_ng

What's Changed

New Contributors

Full Changelog: 3.0.0...3.1.0

Stig V1R11 - release

13 Sep 14:47
31b5330
Compare
Choose a tag to compare

What's Changed

New Contributors

#Issues:

Controls updated

  • CAT2:
    • 010030 - ruleid
    • 010200 - ruleid
    • 010201 - ruleid
    • 010290 - ruleid and SSH MACS updated
    • 010291 - ruleid and SSH Ciphers updated
    • 010770 - ruleid
    • 020035 - new control idlesession timeout new var rhel_08_020035_idlesessiontimeout
    • 020041 - ruleid and tmux script update
    • 030690 - ruleid and protocol options added
    • 040159 - ruleid
    • 040160 - ruleid
    • 040342 - ruleid and SSH KEX algorithms updated

Full Changelog: 2.9.1...3.0.0

Stig V1R10 - release

19 Jul 13:56
85340ce
Compare
Choose a tag to compare

What's Changed

Full Changelog: 2.9.0...2.9.1

Stig V1R10 Release

22 May 09:09
a9d47c8
Compare
Choose a tag to compare

What's Changed

  • Stig v1r10 - release by @uk-bolly in #201
  • Fixed typo in user password assertion by @Phenix66 in #202
  • Stig V1R10 Release to main by @uk-bolly in #203
  • updates for containers on new version
  • #204
  • boot partition variable usage

New Contributors

Full Changelog: 2.8.1...2.9.0

Stig V1r9 release

20 Mar 08:27
7d5b654
Compare
Choose a tag to compare

Overall Review of Changes:
Release of stig v1r9 to main along with many improvements

Issue Fixes:
#157
#158
#159
#168
#169
#170
#171
#172
#173
#178
#179
#180
#181
#183
#185
#185

Enhancements:
Workflow updates
linting
audit alignment with correct stig benchmark release
Warning layout and updates

Benchmark 1.8 Updates

06 Jan 15:47
2c784de
Compare
Choose a tag to compare

STIG Benchmark Release: Version 1 Release 8
STIG Benchmark Release Date: Oct 27, 2022

Issues Fixed:

  • #139 - RHEL-08-010330 & RHEL-08-010350 | SETroubleshootD Breaks
  • #140 - RHEL-08-020027/020028 | SELinux Permission Discrepancies / Faillock SELinux Denials
  • #142 - RHEL-08-010141 /etc/grub.d/01_users need 755 permission
  • #147 - Install git
  • #148 - RHEL-08-020025 and RHEL-08-020026 - The "preauth" line is NOT listed before pam_unix.so
  • #151 - fstype in fix-cat2.yml set to static value "xfs" on mount tasks (Thanks to @whitehat237 for the PR with the fix idea)

Enhancements:

  • Updates for new benchmark 1.8
  • Updates for banner usage
  • Linting updates

Benchmark 1.7 and Issue Fixes

02 Nov 17:09
f98b63a
Compare
Choose a tag to compare

STIG Benchmark Release: Version 1 Release 7
STIG Benchmark Release Date: Jul 27, 2022

Issues Fixed:

  • #93 - Error with RHEL-08-040137 - Failed
  • #104 - README update - cloudint bug when /var noexec
  • #107 - RHEL-08-020040/41 needs additional configuration.
  • #109 - Broken link for the wiki for Main Variables
  • #115 - List dependencies in requirements.txt
  • #116 - Inconsistent YAML
  • #118 - ansible-lint: 648 failure(s), 0 warning(s) on 18 files
  • #124 - RHEL-08-040090 : Firewall must employ deny-all | Missing Configuration
  • #125 - RHEL-08-040259: Shall not enable IPv4 Forwarding | Update configuration to latest baseline
  • #126 - RHEL-08-010141: Unique Superuser Name for Maintenance | Non-Standard Configuration Method
  • #127 - RHEL-08-010690 / RHEL-08-010770 | Failure in Multiple Steps
  • #128 - RHEL-08-010050 Banner on Login Screen | Missing Configuration
  • #130 - Question regarding RHEL-08-010290 / RHEL-08-010291: Enabling FIPS mode even if not required by STIG?
  • #131 - RHEL-08-020040: TMUX Lock-Command Config | Incomplete Regex
  • #133 - RHEL-08-010295: GnuTLS Encryption | Line Bug
  • #134 - RHEL-08-010740: Group Ownership by Home Dir Owner | Incorrect Ownership by "Nobody" in RHEL 8.6

Enhancements:

  • Benchmarks 1.7 updates
  • Updates for new linting checks