-
Notifications
You must be signed in to change notification settings - Fork 92
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
cis-dil-benchmark-5.6 Ubuntu does not have group 'wheel' #138
Comments
This also seems to be the case for Debian. Can you check this too and maybe extend the fix to cover all Debian based distros? |
I am reading up on the CIS DIL benchmark. Maybe we should not change the group to Starting to split hairs: In the benchmark it is not required for a group |
I agree with @schurzi on not changing the group to sudo. Two reasons:
but that still leaves a problem of the control failing on Debian based distros 🤔 |
Here is the 5.6 CIS description: https://secscan.acron.pl/centos7/5/6 I see a 2 phase approach Phase 1: Fix check so it works on ubuntu Phase 1
Phase 2
I'm mostly interested in limiting the scope to just phase 1 right now (so I can get the test passing on ubuntu), then coming back and improving the logic for phase 2 in another PR. |
@spencer-cdw I agree with your approach in general. Two additions:
|
Yes, pushed a new change. Thank you. |
Ubuntu doesn't have a wheel group so test
cis-dil-benchmark-5.6
will always failcis-dil-benchmark/controls/5_4_user_accounts_and_environments.rb
Lines 229 to 244 in c845274
Tested on ubuntu 18.04
The equivalent group on ubuntu is
sudo
https://askubuntu.com/a/1036214The text was updated successfully, but these errors were encountered: