From 9cbee77c35bc4dc33cf7cd507f78760a724e4481 Mon Sep 17 00:00:00 2001 From: vojtapolasek Date: Tue, 15 Apr 2025 11:55:28 +0200 Subject: [PATCH 1/3] remove talk related rules from RHEL 8 profiles --- products/rhel8/profiles/e8.profile | 2 -- products/rhel8/profiles/hipaa.profile | 2 -- tests/data/profile_stability/rhel8/e8.profile | 2 -- 3 files changed, 6 deletions(-) diff --git a/products/rhel8/profiles/e8.profile b/products/rhel8/profiles/e8.profile index 05b125a4de8..d0dd7a2adbc 100644 --- a/products/rhel8/profiles/e8.profile +++ b/products/rhel8/profiles/e8.profile @@ -21,8 +21,6 @@ description: |- selections: ### Remove obsolete packages - - package_talk_removed - - package_talk-server_removed - package_xinetd_removed - service_xinetd_disabled - package_ypbind_removed diff --git a/products/rhel8/profiles/hipaa.profile b/products/rhel8/profiles/hipaa.profile index b216c731d48..3ae26227118 100644 --- a/products/rhel8/profiles/hipaa.profile +++ b/products/rhel8/profiles/hipaa.profile @@ -41,8 +41,6 @@ selections: - sshd_disable_root_login - libreswan_approved_tunnels - no_rsh_trust_files - - package_talk_removed - - package_talk-server_removed - package_telnet_removed - package_telnet-server_removed - package_xinetd_removed diff --git a/tests/data/profile_stability/rhel8/e8.profile b/tests/data/profile_stability/rhel8/e8.profile index 6df2033c447..3837d6b4ccc 100644 --- a/tests/data/profile_stability/rhel8/e8.profile +++ b/tests/data/profile_stability/rhel8/e8.profile @@ -76,8 +76,6 @@ selections: - package_rear_installed - package_rsyslog_installed - package_squid_removed -- package_talk-server_removed -- package_talk_removed - package_telnet-server_removed - package_telnet_removed - package_xinetd_removed From 2afa3279c8901d25b7f5bb2ef3a2fa62616cdb1e Mon Sep 17 00:00:00 2001 From: vojtapolasek Date: Tue, 15 Apr 2025 11:56:06 +0200 Subject: [PATCH 2/3] remove talk related packages from RHEL 9 profiles --- products/rhel9/profiles/e8.profile | 2 -- products/rhel9/profiles/hipaa.profile | 2 -- 2 files changed, 4 deletions(-) diff --git a/products/rhel9/profiles/e8.profile b/products/rhel9/profiles/e8.profile index e3cc6c76e40..e12b490fa23 100644 --- a/products/rhel9/profiles/e8.profile +++ b/products/rhel9/profiles/e8.profile @@ -21,8 +21,6 @@ description: |- selections: ### Remove obsolete packages - - package_talk_removed - - package_talk-server_removed - package_telnet_removed - service_telnet_disabled - package_telnet-server_removed diff --git a/products/rhel9/profiles/hipaa.profile b/products/rhel9/profiles/hipaa.profile index eb866a58035..439c7d5a988 100644 --- a/products/rhel9/profiles/hipaa.profile +++ b/products/rhel9/profiles/hipaa.profile @@ -45,8 +45,6 @@ selections: - sshd_disable_root_login - libreswan_approved_tunnels - no_rsh_trust_files - - package_talk_removed - - package_talk-server_removed - package_telnet_removed - package_telnet-server_removed - package_cron_installed From 69264d0c67ca336686858eba63172f0fb08b6886 Mon Sep 17 00:00:00 2001 From: vojtapolasek Date: Tue, 15 Apr 2025 11:56:21 +0200 Subject: [PATCH 3/3] remove talk related rules from shared control files in case they are applied on rhel product --- controls/anssi.yml | 2 ++ controls/e8.yml | 2 ++ controls/hipaa.yml | 2 ++ 3 files changed, 6 insertions(+) diff --git a/controls/anssi.yml b/controls/anssi.yml index 89392029f4d..bd20b5d1710 100644 --- a/controls/anssi.yml +++ b/controls/anssi.yml @@ -1298,8 +1298,10 @@ controls: - package_rsh_removed - package_rsh-server_removed - package_sendmail_removed + {{%- if "rhel" not in product %}} - package_talk_removed - package_talk-server_removed + {{%- endif %}} - package_telnet_removed - package_telnet-server_removed - package_tftp_removed diff --git a/controls/e8.yml b/controls/e8.yml index 4098f073ad3..dac6a8c856b 100644 --- a/controls/e8.yml +++ b/controls/e8.yml @@ -11,8 +11,10 @@ controls: - base title: 'Application and operating system patching' rules: + {{%- if "rhel" not in product %}} - package_talk_removed - package_talk-server_removed + {{%- endif %}} - package_ypbind_removed - package_telnet_removed - service_telnet_disabled diff --git a/controls/hipaa.yml b/controls/hipaa.yml index 1cefaa8213d..fdceadaa72d 100644 --- a/controls/hipaa.yml +++ b/controls/hipaa.yml @@ -354,8 +354,10 @@ controls: - service_rexec_disabled - service_rlogin_disabled - service_rsh_disabled + {{%- if "rhel" not in product %}} - package_talk-server_removed - package_talk_removed + {{%- endif %}} - package_telnet-server_removed - package_telnet_removed - service_telnet_disabled