Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

PKGS-7370: debsums cron check does not examine /etc/crontab or /var/spool/cron/crontabs/root #1567

Open
moerkey opened this issue Oct 22, 2024 · 0 comments

Comments

@moerkey
Copy link

moerkey commented Oct 22, 2024

Describe the bug
The current check for existing cronjobs only examines those delivered with the package. However, I manage my own cronjobs through /etc/crontab, /var/spool/cron/crontabs/root, or /etc/cron.d/. Could be related to #1275.

Version

  • Ubuntu 22.04
  • Lynis version 3.1.2-100

Expected behavior
I suggest that the check be updated to include these custom cronjob files for a more comprehensive assessment.

Output

2024-10-10 20:13:21 Performing test ID PKGS-7370 (Checking for debsums utility)
2024-10-10 20:13:21 Result: debsums utility is installed
2024-10-10 20:13:21 Hardening: assigned maximum number of hardening points for this item (1). Currently having 107 points (out of 124)
2024-10-10 20:13:21 Result: Cron job is not configured for debsums utility.
2024-10-10 20:13:21 Hardening: assigned partial number of hardening points (1 of 3). Currently having 108 points (out of 127)
2024-10-10 20:13:21 Suggestion: Check debsums configuration and enable checking regularly via a cron job (CRON_CHECK in default file). [test:P
KGS-7370] [details:-] [solution:-]

Additional context
Thank you for your work on Lynis!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant