diff --git a/linux_os/guide/auditing/auditd_configure_rules/file_ownership_var_log_audit_stig/oval/shared.xml b/linux_os/guide/auditing/auditd_configure_rules/file_ownership_var_log_audit_stig/oval/shared.xml index 95acf590518..ab8162688bb 100644 --- a/linux_os/guide/auditing/auditd_configure_rules/file_ownership_var_log_audit_stig/oval/shared.xml +++ b/linux_os/guide/auditing/auditd_configure_rules/file_ownership_var_log_audit_stig/oval/shared.xml @@ -6,7 +6,7 @@ - {{% if product in ["ol8", "rhel8"] %}} + {{% if "ol" in families or "rhel" in product %}} @@ -28,7 +28,7 @@ state_owner_not_root_var_log_audit - {{% if product in ["ol8", "rhel8"] %}} + {{% if "ol" in families or "rhel" in product %}} diff --git a/linux_os/guide/auditing/auditd_configure_rules/file_ownership_var_log_audit_stig/tests/correct_value_default_file.pass.sh b/linux_os/guide/auditing/auditd_configure_rules/file_ownership_var_log_audit_stig/tests/correct_value_default_file.pass.sh index 3a0d9a4e983..a90711c9853 100644 --- a/linux_os/guide/auditing/auditd_configure_rules/file_ownership_var_log_audit_stig/tests/correct_value_default_file.pass.sh +++ b/linux_os/guide/auditing/auditd_configure_rules/file_ownership_var_log_audit_stig/tests/correct_value_default_file.pass.sh @@ -1,6 +1,8 @@ # platform = multi_platform_ol,multi_platform_rhel #!/bin/bash +# packages = audit + sed -i "/^\s*log_file.*/d" /etc/audit/auditd.conf useradd testuser_123 touch "/var/log/audit/audit2.log" diff --git a/linux_os/guide/auditing/auditd_configure_rules/file_ownership_var_log_audit_stig/tests/wrong_value_default_file.fail.sh b/linux_os/guide/auditing/auditd_configure_rules/file_ownership_var_log_audit_stig/tests/wrong_value_default_file.fail.sh index 1879113b8a0..246cb203fc1 100644 --- a/linux_os/guide/auditing/auditd_configure_rules/file_ownership_var_log_audit_stig/tests/wrong_value_default_file.fail.sh +++ b/linux_os/guide/auditing/auditd_configure_rules/file_ownership_var_log_audit_stig/tests/wrong_value_default_file.fail.sh @@ -1,6 +1,8 @@ # platform = multi_platform_ol,multi_platform_rhel #!/bin/bash +# packages = audit + sed -i "/^\s*log_file.*/d" /etc/audit/auditd.conf useradd testuser_123 touch "/var/log/audit/audit2.log"