-
Notifications
You must be signed in to change notification settings - Fork 1.5k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
FILE-6430 Check other files too #1083
Comments
Both tests have a different target. NETW-3200 is focused on network protocols. FILE-6430 on file systems and related modules. So looks like normal behavior. Or am I missing something? |
Kinda no but also yes. IMHO the check for FILE-6430 is not sufficient. I guess you only check a pattern against the file /etc/modprobe.d/blacklist.conf. That are two different files. I try not to touch any files from any package to have an easy way to update the system. |
Had a look, but FILE-6430 looks in /etc/modprobe.d/* and so does NETW-3200. Can you provide a specific example from your blacklist-custom.conf file? Please include the relevant details from the test that shows up ( |
Here you go.
|
Hey, please reopen it. The issue is still present. |
I don't see any mentioning of dccp in that Lynis output, so that is good (as it is tested within NETW-3200). I'm a bit confused now. You stated that you disabled dccp for NETW-3200 (and seeing your configuration files, it looks good to me). You also say that FILE-6430 shows up. And that is correct, as it tests for different kernel modules. Both can pop up independently of each other. So the question is what specifically do you think is being tested incorrectly? |
Yeah, after 4 month I am confused too and I will dig into it nearly from beginning. So, FILE-6430 says that I should disable some unused modules to be more secure. Do I have to use the file /etc/modprobe.d/blacklist.conf for that? Ubuntu is using the file already but only with lines like "blacklist MODULE". I understand the following like that FILE-6430 just searches for the pattern 'install MODULENAME /bin/true' (without quotes) in the file /etc/modprobe.d/blacklist.conf.
Is that correct? I am just wondering why it is not using grep with the pattern over the directories /etc/modprobe.d/ too. Don´t get confused by dccp. It was just an example. So, why is FILE-6430 complaining about disabling unused modules when I have them already disabled in another file? |
Stale issue message |
Describe the bug
I disabled dccp from NETW-3200 in /etc/modprobe.d/blacklist-custom.conf but still get an info about FILE-6430.
Version
Expected behavior
When I disable dccp from NETW-3200 in /etc/modprobe.d/blacklist-custom.conf, I don´t want to get an info about FILE-6430.
Output
The text was updated successfully, but these errors were encountered: