Releases: ansible-lockdown/RHEL8-STIG
V2R1 Release Oct 2024
Release of STIG V2R 24th October 2024
RuleIDs updated for all controls
Nist Control ID associations added
- RHEL-08-010350 - command updated
- RHEL-08-010472 - Not Applicable if fips
- RHEL-08-020035 - version 8.7+
- RHEL-08-020039 RHEL-08-020040 RHEL-08-020041 RHEL-08-020042, RHEL-08-020070 - TMUX removed
- RHEL-08-020220, RHEL-08-020221 - remember not required for PAM
- RHEL-08-020320 - Updated Check and Fix
- RHEL-08-030603, RHEL-08-040139, RHEL-08-040140, RHEL-08-040141 - Rules updated Ok if no USB peripherals
- RHEL-08-040284
- RHEL-08-040370
- RHEL-08-010001 - removed as not a NIST value
- RHEL-08-020035 - updated
- RHEL-08-040132 - updated
- RHEL-08-010040 - tags and conditional
Others updates include
workflow update
new linting
company name update
date changes
What's Changed
- [pre-commit.ci] pre-commit autoupdate by @pre-commit-ci in #331
- Stig v2r1 release to devel by @uk-bolly in #332
- [pre-commit.ci] pre-commit autoupdate by @pre-commit-ci in #333
- [pre-commit.ci] pre-commit autoupdate by @pre-commit-ci in #334
- [pre-commit.ci] pre-commit autoupdate by @pre-commit-ci in #335
- updated readme by @uk-bolly in #336
- Release v2r1 to main by @uk-bolly in #337
Full Changelog: 3.4.0...4.0.0
STIG Version1 Release14 - April 2024
Release of STIG V1R14 24th April 2023
GUI discovery update
RuleID updates
ansible config update
#232 - thanks to @eday87 @BJSmithIEEE
#298 thanks to @mikefrompsu
#299 thanks to @cpu010100
thanks to @dglinder
#301
#302
What's Changed
- [pre-commit.ci] pre-commit autoupdate by @pre-commit-ci in #310
- Stigv1r14 Release to devel by @uk-bolly in #309
- Stigv1r14 release to main by @uk-bolly in #311
- fixed 040132-04 issue 312 by @uk-bolly in #313
- [pre-commit.ci] pre-commit autoupdate by @pre-commit-ci in #315
- [pre-commit.ci] pre-commit autoupdate by @pre-commit-ci in #318
- Name and alignment by @uk-bolly in #319
- [pre-commit.ci] pre-commit autoupdate by @pre-commit-ci in #321
- [pre-commit.ci] pre-commit autoupdate by @pre-commit-ci in #322
- [pre-commit.ci] pre-commit autoupdate by @pre-commit-ci in #323
- [pre-commit.ci] pre-commit autoupdate by @pre-commit-ci in #324
- [pre-commit.ci] pre-commit autoupdate by @pre-commit-ci in #325
- [pre-commit.ci] pre-commit autoupdate by @pre-commit-ci in #326
- [pre-commit.ci] pre-commit autoupdate by @pre-commit-ci in #328
- Feb25 by @uk-bolly in #329
- Stig v1r14 release to main by @uk-bolly in #330
Full Changelog: 3.3.2...3.4.0
Final - STIG V1R13 release
STIG Version1 Release 13 release - Jan 24
Remediate
Pre-commit updates
new workflow configurations
removed jmespath dependency
Audit
Improvements and updates
What's Changed
- [pre-commit.ci] pre-commit autoupdate by @pre-commit-ci in #276
- [pre-commit.ci] pre-commit autoupdate by @pre-commit-ci in #285
- [pre-commit.ci] pre-commit autoupdate by @pre-commit-ci in #286
- [pre-commit.ci] pre-commit autoupdate by @pre-commit-ci in #288
- issues, workflow and jmespath by @uk-bolly in #291
- [pre-commit.ci] pre-commit autoupdate by @pre-commit-ci in #290
- Updated ordering and notify location by @uk-bolly in #293
- workflow and audit updated devel to main by @uk-bolly in #292
- Remove remnants of removed openscap scanning feature by @qwestduck in #295
- Remove duplicate and templated task tags by @qwestduck in #297
- [pre-commit.ci] pre-commit autoupdate by @pre-commit-ci in #300
- [pre-commit.ci] pre-commit autoupdate by @pre-commit-ci in #303
- [pre-commit.ci] pre-commit autoupdate by @pre-commit-ci in #304
- [pre-commit.ci] pre-commit autoupdate by @pre-commit-ci in #307
- Final main release v1r13 - Jan24 -updated by @uk-bolly in #308
Full Changelog: 3.3.0...3.3.3
STIG V1R13 release
STIG Version1 Release 13 release - Jan 24
Main Release for v1r13 RHEL8 STIG
Remediate
- Issues closed and PRs merged - What's changed
- Pre-commit updates
- Many improvements to different controls
- Rebase required from v1r12
Audit
- Related Audit repo updated to improve tests audit binary(goss updated to latest version)
What's Changed
- Stig v1r12 release to devel by @uk-bolly in #259
- [pre-commit.ci] pre-commit autoupdate by @pre-commit-ci in #260
- Updated RHEL-08-020050 to loop over stdout_lines. Fixes issue #261. by @Phenix66 in #262
- [pre-commit.ci] pre-commit autoupdate by @pre-commit-ci in #264
- Meet fix text of V-244546 by @fallenpixel in #266
- [pre-commit.ci] pre-commit autoupdate by @pre-commit-ci in #268
- April 24 issues into devel by @uk-bolly in #269
- fixed error in conditional rhel-08-020022 #271 by @uk-bolly in #272
- Merge in changes from v1r13 - Jan 24 by @uk-bolly in #274
- updated conditional 040260 by @uk-bolly in #279
- Updated of devel - DCO confirmation and signoff update by @uk-bolly in #280
- V13 merge fixes by @uk-bolly in #282
- May24 updates by @uk-bolly in #283
- Initial main release of v1r13 by @uk-bolly in #281
Full Changelog: 3.2.0...3.3.0
STIG v1r12 - April 2024 update
STIG Version1 Release 12 release - October 23
Main Release for v1r12 RHEL8 STIG
Remediate
- Issues closed and PRs merged - What's changed
- Pre-commit updates
- Many improvements to different controls
Audit
- Audit_only ability now added to run standalone audit
- audit_only: true
- Related Audit repo updated to improve tests audit binary(goss updated to latest version)
What's Changed
- Change master to main in actions by @georgenalen in #4
- RHEL8 STIG Version 1 Release 1 by @georgenalen in #7
- Minor Fixes by @georgenalen in #11
- Devel to main by @uk-bolly in #34
- Benchmark Version 1 Rev. 2 and other fixes by @georgenalen in #44
- Added Issue and PR templates and an issue fix by @georgenalen in #49
- Benchmark 1.3 updates and issue fixes by @georgenalen in #61
- Release 2.3.1 by @georgenalen in #71
- V1.5 update by @uk-bolly in #102
- 2.5.0 Release by @georgenalen in #106
- Benchmark 1.7 and issue fixes by @georgenalen in #137
- Main updates to Benchmark v1r8 release by @uk-bolly in #155
- Devel to main release stig v1r9 by @uk-bolly in #188
- Release to main for bug fixes and improvements by @uk-bolly in #200
- Stig V1R10 Release to main by @uk-bolly in #203
- June devel to main by @uk-bolly in #206
- v1r11 updates release to main by @uk-bolly in #221
- devel - main - workflow and discord by @uk-bolly in #225
- New release devel -> main by @uk-bolly in #255
- Release of v1r12 by @uk-bolly in #275
Full Changelog: 3.1.0...3.2.0
Final STIG V1R11
STIG Version1 Release 11 release - July 23
Remediate
Issues closed and PRs merged - What's changed
Pre-commit updates
Many improvements to different controls
Update to allow Galaxy Releases for new galaxy_ng
What's Changed
- Precommit workflow by @uk-bolly in #223
- Issue #222 and tidy up by @uk-bolly in #224
- Issue 226 and alignment by @uk-bolly in #228
- Sysctl and collections by @uk-bolly in #235
- updated the workflow version and galaxy setup by @uk-bolly in #236
- Revert "fixed gnutls as per issue 196 thansk to @jmalpede" by @qwestduck in #234
- Update main.yml by @BillSkiCO in #237
- [pre-commit.ci] pre-commit autoupdate by @pre-commit-ci in #238
- Oracle Linux rhel8stig_bootloader_path and RHEL-08-020030 fix by @BillSkiCO in #253
- [pre-commit.ci] pre-commit autoupdate by @pre-commit-ci in #247
- Adds when criteria for rhel_08_040321 in tasks/fix-cat2.yml, to skip … by @whitehat237 in #250
- Update meta and readme due to galaxy_ng by @uk-bolly in #258
New Contributors
- @qwestduck made their first contribution in #234
- @BillSkiCO made their first contribution in #237
- @pre-commit-ci made their first contribution in #238
Full Changelog: 3.0.0...3.1.0
Stig V1R11 - release
What's Changed
- Fix typo in defaults/main by @fallenpixel in #215
- improve password check by @uk-bolly in #217
- Stig v1r11 release by @uk-bolly in #218
- July23 by @uk-bolly in #219
- Updated when on line 197 of prelim to use an or instead of and by @georgenalen in #220
New Contributors
- @fallenpixel made their first contribution in #215
#Issues:
Controls updated
- CAT2:
- 010030 - ruleid
- 010200 - ruleid
- 010201 - ruleid
- 010290 - ruleid and SSH MACS updated
- 010291 - ruleid and SSH Ciphers updated
- 010770 - ruleid
- 020035 - new control idlesession timeout new var rhel_08_020035_idlesessiontimeout
- 020041 - ruleid and tmux script update
- 030690 - ruleid and protocol options added
- 040159 - ruleid
- 040160 - ruleid
- 040342 - ruleid and SSH KEX algorithms updated
Full Changelog: 2.9.1...3.0.0