From febbda04a176ccd0b85b504089d13b14a5935ee1 Mon Sep 17 00:00:00 2001 From: Miha Purg Date: Mon, 16 Dec 2024 20:45:15 +0100 Subject: [PATCH] Fix to prevent oscap crashing on ubuntu The recently added conflicts tags to sshd_enable_warning_banner_* rules cause openscap to crash on Ubuntu (#12718). This change disables the conflicts tags on Ubuntu products until a proper fix is implemented. --- .../services/ssh/ssh_server/sshd_enable_warning_banner/rule.yml | 2 ++ .../ssh/ssh_server/sshd_enable_warning_banner_net/rule.yml | 2 ++ 2 files changed, 4 insertions(+) diff --git a/linux_os/guide/services/ssh/ssh_server/sshd_enable_warning_banner/rule.yml b/linux_os/guide/services/ssh/ssh_server/sshd_enable_warning_banner/rule.yml index 737f18c7371..2437b9f0f1b 100644 --- a/linux_os/guide/services/ssh/ssh_server/sshd_enable_warning_banner/rule.yml +++ b/linux_os/guide/services/ssh/ssh_server/sshd_enable_warning_banner/rule.yml @@ -62,8 +62,10 @@ fixtext: |- srg_requirement: '{{{ full_name }}} must display the Standard Mandatory DoD Notice and Consent Banner before granting local or remote access to the system via a ssh logon.' +{{% if 'ubuntu' not in product %}} conflicts: - sshd_enable_warning_banner_net +{{% endif %}} template: name: sshd_lineinfile diff --git a/linux_os/guide/services/ssh/ssh_server/sshd_enable_warning_banner_net/rule.yml b/linux_os/guide/services/ssh/ssh_server/sshd_enable_warning_banner_net/rule.yml index f0c91da9298..ee838ccd0f9 100644 --- a/linux_os/guide/services/ssh/ssh_server/sshd_enable_warning_banner_net/rule.yml +++ b/linux_os/guide/services/ssh/ssh_server/sshd_enable_warning_banner_net/rule.yml @@ -46,8 +46,10 @@ references: {{{ complete_ocil_entry_sshd_option(default="no", option="Banner", value="/etc/issue.net") }}} +{{% if 'ubuntu' not in product %}} conflicts: - sshd_enable_warning_banner +{{% endif %}} template: name: sshd_lineinfile