action #92473
closedcoordination #91383: [security][epic] tracker poo for "Lynis test cases softfails in OpenQA"
[sle][security][sle15sp3] Lynis: fix softfailure on "Software_firewalls"
100%
Description
e.g., https://openqa.suse.de/tests/5989942#step/18_[+]_Software:_firewalls/4
This warning ( [4C- Checking for empty ruleset[29C [ WARNING ]) introduces soft failure.
The baseline:
[+] Software: firewalls
[2C- Checking iptables kernel module[26C [ FOUND ]
[4C- Checking iptables policies of chains[19C [ FOUND ]
[4C- Checking for empty ruleset[29C [ OK ]
[4C- Checking for unused rules[30C [ FOUND ]
[2C- Checking host based firewall[29C [ ACTIVE ]
The current contents:
[+] Software: firewalls
[2C- Checking iptables kernel module[26C [ FOUND ]
[4C- Checking iptables policies of chains[19C [ FOUND ]
[4C- Checking for empty ruleset[29C [ WARNING ]
[4C- Checking for unused rules[30C [ OK ]
[2C- Checking host based firewall[29C [ ACTIVE ]
Updated by llzhao over 3 years ago
- Status changed from In Progress to Feedback
- % Done changed from 0 to 90
Please see Bug 1185942 - lynis found a [warning] on firewalls: "Checking for empty ruleset - [ WARNING ]"
for more info.
Test code do not need to be revised atm, let's check the openQA run when the fix (upgrade lynis pkg version to https://github.com/CISOfy/lynis/releases/tag/3.0.4) is available.
Updated by llzhao over 3 years ago
- Status changed from Feedback to Resolved
- % Done changed from 90 to 100
Since the GMC was released let's move this poo to resolved atm.