From 944c81615b57651fef4fb56b837d538c9afaf7aa Mon Sep 17 00:00:00 2001 From: teacup-on-rockingchair <315160+teacup-on-rockingchair@users.noreply.github.com> Date: Tue, 14 Nov 2023 09:43:37 +0200 Subject: [PATCH] Add OVAL check for apparmor profile rules --- .../oval/shared.xml | 31 +++++++++++++++++++ 1 file changed, 31 insertions(+) create mode 100644 linux_os/guide/system/apparmor/all_apparmor_profiles_in_enforce_complain_mode/oval/shared.xml diff --git a/linux_os/guide/system/apparmor/all_apparmor_profiles_in_enforce_complain_mode/oval/shared.xml b/linux_os/guide/system/apparmor/all_apparmor_profiles_in_enforce_complain_mode/oval/shared.xml new file mode 100644 index 000000000000..f5db608032ac --- /dev/null +++ b/linux_os/guide/system/apparmor/all_apparmor_profiles_in_enforce_complain_mode/oval/shared.xml @@ -0,0 +1,31 @@ + + + {{{ oval_metadata("Ensure AppArmor profiles are in enforce complain mode") }}} + + + + + /sys/kernel/security/apparmor/profiles + ^.*$ + 1 + + + /sys/kernel/security/apparmor/profiles + ^\(enforce\)*$ + 1 + + + /sys/kernel/security/apparmor/profiles + ^\(complain\)*$ + 1 + + + + + + + + + + +