Skip to content

Amazon Linux 2023 CIS 1.7.1-1.7.3: cis_banners does not detect Amazon Linux in banners, and fails multi-line site banners #15153

Description

@dynayl

Description of problem:

Found while comparing CIS results on Amazon Linux 2023 images.

  • Product: al2023
  • Profiles: cis_server_l1, cis; controls 1.7.1, 1.7.2, 1.7.3
  • Rules: banner_etc_motd, banner_etc_issue, banner_etc_issue_net, with motd_banner_text, login_banner_text and remote_login_banner_text set to cis_banners (controls/cis_al2023.yml L463-L491 at v0.1.82, same on master)

banner_etc_issue reads /etc/issue (and /etc/issue.d/*) as one string (singleline="true") and pattern-matches it against login_banner_text (banner_etc_issue/oval/shared.xml L14-L23); the motd and issue.net rules work the same way. cis_banners (login_banner_text.var L23; the same value in remote_login_banner_text.var L23 and motd_banner_text.var L23) accepts either the cis_default text (Authorized users only. All activity may be monitored and reported., with any whitespace) or

^(?!.*(\\|fedora|rhel|sle|ubuntu)).*

that is, a single line with no backslash and none of four lowercase OS names. Two consequences on al2023:

  1. Amazon Linux is not in the list. Its os-release ID is amzn and its name is "Amazon Linux". A one-line banner Amazon Linux 2023 or amzn passes all three rules, while This is ubuntu. fails them. The OCIL of the CIS-specific banner rules (ocil_cis_banner, shared/macros/10-ocil.jinja L1471-L1478) flags the os-release ID with grep -E -i, which returns the amzn banner. The list comes from More flexibility for login banners #7690 (2021); al2023 was added later (Add al2023 product #12006, 2024) and reuses it.
  2. A multi-line site banner without OS information fails, because . does not match a newline in the second alternative. Authorized access only. followed by All activity is logged. on a second line fails banner_etc_issue; the same text on one line passes.

On a default system the result is right: /etc/issue and /etc/issue.net are symlinks to /usr/lib/issue and /usr/lib/issue.net from system-release, both \S / Kernel \r on an \m (\l), and they fail; /etc/motd (from setup) is empty and passes. The two problems above affect site-specific banners.

The CIS control files for RHEL 8/9/10, Fedora, AlmaLinux 9, Ubuntu 22.04/24.04 and Debian 12/13 use banner_etc_motd_cis, banner_etc_issue_cis and banner_etc_issue_net_cis for these controls. #12472 introduced those rules because the generic banner rules did not fit the CIS requirement (site-specific text allowed, no OS or version information); #12619 moved Ubuntu 24.04 to them. al2023 was not moved.

SCAP Security Guide Version:

0.1.82 (release data stream ssg-al2023-ds.xml from scap-security-guide-0.1.82.zip). The control entries and the three variables are unchanged on master at f956856.

Operating System Version:

Amazon Linux 2023: amazonlinux:2023@sha256:74c545e3e04db388b00bd31d7cc5640d4e9c12058a6d72af938d113da3c82893 (linux/amd64), system-release 2023.12.20260831-0.amzn2023, ID="amzn". OpenSCAP 1.4.4, oscap-chroot.

Steps to Reproduce:

The image's root filesystem (docker export of a container that was never started) is evaluated offline. /.dockerenv is removed and an empty noarch package named kernel is registered in its rpm database (rpm --root root --dbpath /var/lib/rpm --justdb --nodeps --noscripts --notriggers --install ...), so that the system_with_kernel platform applies.

  1. Replace the /etc/issue and /etc/issue.net symlinks with files, and write the same one-line text to /etc/issue, /etc/issue.net and /etc/motd:
    sudo rm -f root/etc/issue root/etc/issue.net
    for f in issue issue.net motd; do echo 'Amazon Linux 2023' | sudo tee root/etc/$f >/dev/null; done
    
  2. Evaluate:
    sudo oscap-chroot root xccdf eval \
      --profile xccdf_org.ssgproject.content_profile_cis_server_l1 \
      --rule xccdf_org.ssgproject.content_rule_banner_etc_issue \
      --rule xccdf_org.ssgproject.content_rule_banner_etc_issue_net \
      --rule xccdf_org.ssgproject.content_rule_banner_etc_motd \
      scap-security-guide-0.1.82/ssg-al2023-ds.xml
    
  3. Repeat with amzn and with This is ubuntu., and with the two-line banner Authorized access only. / All activity is logged. in /etc/issue.

Actual Results:

Banner text (all three files) banner_etc_issue banner_etc_issue_net banner_etc_motd
default files fail fail pass
Amazon Linux 2023 pass pass pass
amzn pass pass pass
This is ubuntu. fail fail fail
Authorized users only. All activity may be monitored and reported. pass pass pass

Two-line banner in /etc/issue: banner_etc_issue fails; the same text on one line passes.

Expected Results:

Banners that name the operating system (Amazon Linux 2023, amzn) fail. A multi-line site banner without OS information passes.

Additional Information/Debugging Steps:

Suggested fix: use the CIS-specific rules, as the other CIS control files do:

--- a/controls/cis_al2023.yml
+++ b/controls/cis_al2023.yml
@@ -466,9 +466,8 @@
           - l1_server
       status: automated
       rules:
-          - banner_etc_motd
-          - motd_banner_text=cis_banners
-          - motd_banner_contents=cis_default
+          - banner_etc_motd_cis
+          - cis_banner_text=cis
 
     - id: 1.7.2
       title: Ensure local login warning banner is configured properly (Automated)
@@ -476,9 +475,8 @@
           - l1_server
       status: automated
       rules:
-          - banner_etc_issue
-          - login_banner_text=cis_banners
-          - login_banner_contents=cis_default
+          - banner_etc_issue_cis
+          - cis_banner_text=cis
 
     - id: 1.7.3
       title: Ensure remote login warning banner is configured properly (Automated)
@@ -486,9 +484,8 @@
           - l1_server
       status: automated
       rules:
-          - banner_etc_issue_net
-          - remote_login_banner_text=cis_banners
-          - remote_login_banner_contents=cis_default
+          - banner_etc_issue_net_cis
+          - cis_banner_text=cis
 
     - id: 1.7.4
       title: Ensure permissions on /etc/motd are configured (Automated)

With the current cis_banner template, al2023 renders to (\\v|\\r|\\m|\\s|al2023|Amazon Linux 2023). That catches Amazon Linux 2023 but, being case-sensitive and without the os-release ID, not amzn or amazon linux 2023. Adding the template change proposed in #15150 ((?i) and the os-release ID), with an al2023 branch:

{{% if "debian" in families %}}|debian{{% elif product == "al2023" %}}|amzn{{% endif %}}

renders (?i)(\\v|\\r|\\m|\\s|al2023|Amazon Linux 2023|amzn).

I built al2023 from master (f956856) twice, with the control change alone and with the control and template changes (that build also carried the unrelated 4.3.4 sudo change), and evaluated the same image with banner_etc_issue_cis, banner_etc_issue_net_cis and banner_etc_motd_cis:

Banner text (all three files) control change only control and template changes
default files fail, fail, pass fail, fail, pass
Amazon Linux 2023 fail, fail, fail fail, fail, fail
amzn pass, pass, pass fail, fail, fail
amazon linux 2023 pass, pass, pass fail, fail, fail
Authorized users only. All activity may be monitored and reported. pass, pass, pass pass, pass, pass
two lines: Authorized access only. / All activity is logged. pass, pass, pass pass, pass, pass

(banner_etc_motd_cis passes the default empty /etc/motd, since it does not require a banner.) oscap ds sds-validate accepts both data streams.

The remediation changes with the rules: the _cis rules write cis_banner_text (the same sentence as cis_default) to the file.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions