Skip to content

rsyslog_remote_access_monitoring is misaligned with DISA #15134

Description

@jan-cerny

Description of problem:

Rule rsyslog_remote_access_monitoring is reported as misaligned with DISA by the /scanning/disa-alignment/oscap on RHEL 10.3. This rule isn't reported as misaligned by /scanning/disa-alignment/ansible

SCAP Security Guide Version:

current upstream master as of 2026-09-22

Operating System Version:

RHEL 10.3

Steps to Reproduce:

  1. run /scanning/disa-alignment/oscap

Actual Results:

SSG result: pass, DISA result(s): SV-280990r1165325_rule:fail

Expected Results:

both SSG and DISA passes

Additional Information/Debugging Steps:

DISA's regex seems to be more strict so it doesn't find the authpriv directive in the rsyslog configuration files, whereas our regex can find the authpriv directive there.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    RHEL10Red Hat Enterprise Linux 10 product related.STIGSTIG Benchmark related.productization-issueIssue found in upstream stabilization process.triaged

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions