>From e786de7bbb781ffc88b835beffc45f61df13808e Mon Sep 17 00:00:00 2001 From: Shawn Wells <[email protected]> Date: Fri, 29 Mar 2013 18:58:13 -0400 Subject: [PATCH 05/21] Updated OVAL rule name for partition_for_var - Renamed OVAL to match XCCDF rule name
--- RHEL6/input/checks/mount_tmp_own_partition.xml | 22 ------------------- RHEL6/input/checks/mount_var_own_partition.xml | 24 --------------------- RHEL6/input/checks/partition_for_var.xml | 24 +++++++++++++++++++++ RHEL6/input/system/software/disk_partitioning.xml | 2 +- 4 files changed, 25 insertions(+), 47 deletions(-) delete mode 100644 RHEL6/input/checks/mount_tmp_own_partition.xml delete mode 100644 RHEL6/input/checks/mount_var_own_partition.xml create mode 100644 RHEL6/input/checks/partition_for_var.xml diff --git a/RHEL6/input/checks/mount_tmp_own_partition.xml b/RHEL6/input/checks/mount_tmp_own_partition.xml deleted file mode 100644 index 62da746..0000000 --- a/RHEL6/input/checks/mount_tmp_own_partition.xml +++ /dev/null @@ -1,22 +0,0 @@ -<def-group> - <definition class="compliance" id="mount_tmp_own_partition" version="1"> - <metadata> - <title>Ensure /tmp Located On Separate Partition</title> - <affected family="unix"> - <platform>Red Hat Enterprise Linux 6</platform> - </affected> - <description>The /tmp directory is a world-writable directory - used for temporary file storage. Verify that it has its own - partition or logical volume.</description> - </metadata> - <criteria> - <criterion test_ref="test_tmp_partition" comment="/tmp on own partition" /> - </criteria> - </definition> - <linux:partition_test check="all" check_existence="all_exist" id="test_tmp_partition" version="1" comment="/tmp on own partition"> - <linux:object object_ref="object_own_tmp_partition" /> - </linux:partition_test> - <linux:partition_object id="object_own_tmp_partition" version="1"> - <linux:mount_point>/tmp</linux:mount_point> - </linux:partition_object> -</def-group> diff --git a/RHEL6/input/checks/mount_var_own_partition.xml b/RHEL6/input/checks/mount_var_own_partition.xml deleted file mode 100644 index 8626f66..0000000 --- a/RHEL6/input/checks/mount_var_own_partition.xml +++ /dev/null @@ -1,24 +0,0 @@ -<def-group> - <definition class="compliance" id="mount_var_own_partition" version="1"> - <metadata> - <title>Ensure /var Located On Separate Partition</title> - <affected family="unix"> - <platform>Red Hat Enterprise Linux 6</platform> - </affected> - <description>Ensuring that /var is mounted on its own partition enables the - setting of more restrictive mount options, which is used as temporary - storage by many program, particularly system services such as daemons. - It is not uncommon for the /var directory to contain world-writable directories, - installed by other software packages.</description> - </metadata> - <criteria> - <criterion test_ref="test_var_partition" comment="/var on own partition" /> - </criteria> - </definition> - <linux:partition_test check="all" check_existence="all_exist" id="test_var_partition" version="1" comment="/var on own partition"> - <linux:object object_ref="object_mount_var_own_partition" /> - </linux:partition_test> - <linux:partition_object id="object_mount_var_own_partition" version="1"> - <linux:mount_point>/var</linux:mount_point> - </linux:partition_object> -</def-group> diff --git a/RHEL6/input/checks/partition_for_var.xml b/RHEL6/input/checks/partition_for_var.xml new file mode 100644 index 0000000..8626f66 --- /dev/null +++ b/RHEL6/input/checks/partition_for_var.xml @@ -0,0 +1,24 @@ +<def-group> + <definition class="compliance" id="mount_var_own_partition" version="1"> + <metadata> + <title>Ensure /var Located On Separate Partition</title> + <affected family="unix"> + <platform>Red Hat Enterprise Linux 6</platform> + </affected> + <description>Ensuring that /var is mounted on its own partition enables the + setting of more restrictive mount options, which is used as temporary + storage by many program, particularly system services such as daemons. + It is not uncommon for the /var directory to contain world-writable directories, + installed by other software packages.</description> + </metadata> + <criteria> + <criterion test_ref="test_var_partition" comment="/var on own partition" /> + </criteria> + </definition> + <linux:partition_test check="all" check_existence="all_exist" id="test_var_partition" version="1" comment="/var on own partition"> + <linux:object object_ref="object_mount_var_own_partition" /> + </linux:partition_test> + <linux:partition_object id="object_mount_var_own_partition" version="1"> + <linux:mount_point>/var</linux:mount_point> + </linux:partition_object> +</def-group> diff --git a/RHEL6/input/system/software/disk_partitioning.xml b/RHEL6/input/system/software/disk_partitioning.xml index 2ba96ce..bab6784 100644 --- a/RHEL6/input/system/software/disk_partitioning.xml +++ b/RHEL6/input/system/software/disk_partitioning.xml @@ -58,7 +58,7 @@ It is not uncommon for the <tt>/var</tt> directory to contain world-writable directories, installed by other software packages. </rationale> <ident cce="26639-5"/> -<oval id="mount_var_own_partition" /> +<oval id="partition_for_var" /> <ref nist="" disa="1208"/> <tested by="MM" on="20120928"/> </Rule> -- 1.7.1
_______________________________________________ scap-security-guide mailing list [email protected] https://lists.fedorahosted.org/mailman/listinfo/scap-security-guide
