You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
that is, a single line with no backslash and none of four lowercase OS names. Two consequences on al2023:
Amazon Linux is not in the list. Its os-release ID is amzn and its name is "Amazon Linux". A one-line banner Amazon Linux 2023 or amzn passes all three rules, while This is ubuntu. fails them. The OCIL of the CIS-specific banner rules (ocil_cis_banner, shared/macros/10-ocil.jinja L1471-L1478) flags the os-release ID with grep -E -i, which returns the amzn banner. The list comes from More flexibility for login banners #7690 (2021); al2023 was added later (Add al2023 product #12006, 2024) and reuses it.
A multi-line site banner without OS information fails, because . does not match a newline in the second alternative. Authorized access only. followed by All activity is logged. on a second line fails banner_etc_issue; the same text on one line passes.
On a default system the result is right: /etc/issue and /etc/issue.net are symlinks to /usr/lib/issue and /usr/lib/issue.net from system-release, both \S / Kernel \r on an \m (\l), and they fail; /etc/motd (from setup) is empty and passes. The two problems above affect site-specific banners.
The CIS control files for RHEL 8/9/10, Fedora, AlmaLinux 9, Ubuntu 22.04/24.04 and Debian 12/13 use banner_etc_motd_cis, banner_etc_issue_cis and banner_etc_issue_net_cis for these controls. #12472 introduced those rules because the generic banner rules did not fit the CIS requirement (site-specific text allowed, no OS or version information); #12619 moved Ubuntu 24.04 to them. al2023 was not moved.
SCAP Security Guide Version:
0.1.82 (release data stream ssg-al2023-ds.xml from scap-security-guide-0.1.82.zip). The control entries and the three variables are unchanged on master at f956856.
The image's root filesystem (docker export of a container that was never started) is evaluated offline. /.dockerenv is removed and an empty noarch package named kernel is registered in its rpm database (rpm --root root --dbpath /var/lib/rpm --justdb --nodeps --noscripts --notriggers --install ...), so that the system_with_kernel platform applies.
Replace the /etc/issue and /etc/issue.net symlinks with files, and write the same one-line text to /etc/issue, /etc/issue.net and /etc/motd:
sudo rm -f root/etc/issue root/etc/issue.net
for f in issue issue.net motd; do echo 'Amazon Linux 2023' | sudo tee root/etc/$f >/dev/null; done
With the current cis_banner template, al2023 renders to (\\v|\\r|\\m|\\s|al2023|Amazon Linux 2023). That catches Amazon Linux 2023 but, being case-sensitive and without the os-release ID, not amzn or amazon linux 2023. Adding the template change proposed in #15150 ((?i) and the os-release ID), with an al2023 branch:
{{% if "debian" in families %}}|debian{{% elif product == "al2023" %}}|amzn{{% endif %}}
renders (?i)(\\v|\\r|\\m|\\s|al2023|Amazon Linux 2023|amzn).
I built al2023 from master (f956856) twice, with the control change alone and with the control and template changes (that build also carried the unrelated 4.3.4 sudo change), and evaluated the same image with banner_etc_issue_cis, banner_etc_issue_net_cis and banner_etc_motd_cis:
Banner text (all three files)
control change only
control and template changes
default files
fail, fail, pass
fail, fail, pass
Amazon Linux 2023
fail, fail, fail
fail, fail, fail
amzn
pass, pass, pass
fail, fail, fail
amazon linux 2023
pass, pass, pass
fail, fail, fail
Authorized users only. All activity may be monitored and reported.
pass, pass, pass
pass, pass, pass
two lines: Authorized access only. / All activity is logged.
pass, pass, pass
pass, pass, pass
(banner_etc_motd_cis passes the default empty /etc/motd, since it does not require a banner.) oscap ds sds-validate accepts both data streams.
The remediation changes with the rules: the _cis rules write cis_banner_text (the same sentence as cis_default) to the file.
Description of problem:
Found while comparing CIS results on Amazon Linux 2023 images.
al2023cis_server_l1,cis; controls 1.7.1, 1.7.2, 1.7.3banner_etc_motd,banner_etc_issue,banner_etc_issue_net, withmotd_banner_text,login_banner_textandremote_login_banner_textset tocis_banners(controls/cis_al2023.yml L463-L491 at v0.1.82, same on master)banner_etc_issuereads/etc/issue(and/etc/issue.d/*) as one string (singleline="true") and pattern-matches it againstlogin_banner_text(banner_etc_issue/oval/shared.xml L14-L23); the motd and issue.net rules work the same way.cis_banners(login_banner_text.var L23; the same value in remote_login_banner_text.var L23 and motd_banner_text.var L23) accepts either thecis_defaulttext (Authorized users only. All activity may be monitored and reported., with any whitespace) orthat is, a single line with no backslash and none of four lowercase OS names. Two consequences on al2023:
IDisamznand its name is "Amazon Linux". A one-line bannerAmazon Linux 2023oramznpasses all three rules, whileThis is ubuntu.fails them. The OCIL of the CIS-specific banner rules (ocil_cis_banner, shared/macros/10-ocil.jinja L1471-L1478) flags the os-release ID withgrep -E -i, which returns theamznbanner. The list comes from More flexibility for login banners #7690 (2021); al2023 was added later (Add al2023 product #12006, 2024) and reuses it..does not match a newline in the second alternative.Authorized access only.followed byAll activity is logged.on a second line failsbanner_etc_issue; the same text on one line passes.On a default system the result is right:
/etc/issueand/etc/issue.netare symlinks to/usr/lib/issueand/usr/lib/issue.netfrom system-release, both\S/Kernel \r on an \m (\l), and they fail;/etc/motd(from setup) is empty and passes. The two problems above affect site-specific banners.The CIS control files for RHEL 8/9/10, Fedora, AlmaLinux 9, Ubuntu 22.04/24.04 and Debian 12/13 use
banner_etc_motd_cis,banner_etc_issue_cisandbanner_etc_issue_net_cisfor these controls. #12472 introduced those rules because the generic banner rules did not fit the CIS requirement (site-specific text allowed, no OS or version information); #12619 moved Ubuntu 24.04 to them. al2023 was not moved.SCAP Security Guide Version:
0.1.82 (release data stream
ssg-al2023-ds.xmlfromscap-security-guide-0.1.82.zip). The control entries and the three variables are unchanged on master at f956856.Operating System Version:
Amazon Linux 2023:
amazonlinux:2023@sha256:74c545e3e04db388b00bd31d7cc5640d4e9c12058a6d72af938d113da3c82893(linux/amd64), system-release 2023.12.20260831-0.amzn2023,ID="amzn". OpenSCAP 1.4.4,oscap-chroot.Steps to Reproduce:
The image's root filesystem (
docker exportof a container that was never started) is evaluated offline./.dockerenvis removed and an empty noarch package namedkernelis registered in its rpm database (rpm --root root --dbpath /var/lib/rpm --justdb --nodeps --noscripts --notriggers --install ...), so that thesystem_with_kernelplatform applies./etc/issueand/etc/issue.netsymlinks with files, and write the same one-line text to/etc/issue,/etc/issue.netand/etc/motd:amznand withThis is ubuntu., and with the two-line bannerAuthorized access only./All activity is logged.in/etc/issue.Actual Results:
banner_etc_issuebanner_etc_issue_netbanner_etc_motdAmazon Linux 2023amznThis is ubuntu.Authorized users only. All activity may be monitored and reported.Two-line banner in
/etc/issue:banner_etc_issuefails; the same text on one line passes.Expected Results:
Banners that name the operating system (
Amazon Linux 2023,amzn) fail. A multi-line site banner without OS information passes.Additional Information/Debugging Steps:
Suggested fix: use the CIS-specific rules, as the other CIS control files do:
With the current
cis_bannertemplate, al2023 renders to(\\v|\\r|\\m|\\s|al2023|Amazon Linux 2023). That catchesAmazon Linux 2023but, being case-sensitive and without the os-release ID, notamznoramazon linux 2023. Adding the template change proposed in #15150 ((?i)and the os-release ID), with an al2023 branch:renders
(?i)(\\v|\\r|\\m|\\s|al2023|Amazon Linux 2023|amzn).I built al2023 from master (f956856) twice, with the control change alone and with the control and template changes (that build also carried the unrelated 4.3.4 sudo change), and evaluated the same image with
banner_etc_issue_cis,banner_etc_issue_net_cisandbanner_etc_motd_cis:Amazon Linux 2023amznamazon linux 2023Authorized users only. All activity may be monitored and reported.Authorized access only./All activity is logged.(
banner_etc_motd_cispasses the default empty/etc/motd, since it does not require a banner.)oscap ds sds-validateaccepts both data streams.The remediation changes with the rules: the
_cisrules writecis_banner_text(the same sentence ascis_default) to the file.