From 796a561fe511335298637abb361a20199e3e32ae Mon Sep 17 00:00:00 2001 From: "thibault.dewailly" Date: Wed, 27 Dec 2023 08:58:12 +0000 Subject: [PATCH] enh: add test for 4.2.1.6 --- .../4.2.1.5_syslog-ng_remote_host.sh | 2 +- .../hardening/4.2.1.6_remote_syslog-ng_acl.sh | 33 +++++++++++++++++-- 2 files changed, 31 insertions(+), 4 deletions(-) diff --git a/tests/hardening/4.2.1.5_syslog-ng_remote_host.sh b/tests/hardening/4.2.1.5_syslog-ng_remote_host.sh index d4b9614..7c1efab 100644 --- a/tests/hardening/4.2.1.5_syslog-ng_remote_host.sh +++ b/tests/hardening/4.2.1.5_syslog-ng_remote_host.sh @@ -38,6 +38,6 @@ EOF run subfile "${CIS_CHECKS_DIR}/${script}.sh" --audit-all # Cleanup - rm /etc/syslog-ng/conf.d/1_tcp_destination + rm -f /etc/syslog-ng/conf.d/1_tcp_destination } diff --git a/tests/hardening/4.2.1.6_remote_syslog-ng_acl.sh b/tests/hardening/4.2.1.6_remote_syslog-ng_acl.sh index 5bb5d86..e88160b 100644 --- a/tests/hardening/4.2.1.6_remote_syslog-ng_acl.sh +++ b/tests/hardening/4.2.1.6_remote_syslog-ng_acl.sh @@ -2,10 +2,37 @@ # run-shellcheck test_audit() { describe Running on blank host - register_test retvalshouldbe 0 - dismiss_count_for_test + register_test retvalshouldbe 1 # shellcheck disable=2154 + echo 'REMOTE_HOST="true"' >>"${CIS_CONF_DIR}/conf.d/${script}.cfg" run blank "${CIS_CHECKS_DIR}/${script}.sh" --audit-all - # TODO fill comprehensive tests + cp -a /etc/syslog-ng/syslog-ng.conf /tmp/syslog-ng.conf.bak + echo "source mySyslog tcp (\"127.0.0.1\")" >>/etc/syslog-ng/syslog-ng.conf + + describe Checking one line conf + register_test retvalshouldbe 0 + run oneline "${CIS_CHECKS_DIR}/${script}.sh" --audit-all + + cp -a /tmp/syslog-ng.conf.bak /etc/syslog-ng/syslog-ng.conf + cat >>/etc/syslog-ng/syslog-ng.conf <>/etc/syslog-ng/conf.d/1_tcp_source + cat /etc/syslog-ng/conf.d/1_tcp_source + + describe Checking file in subdirectory + register_test retvalshouldbe 0 + run subfile "${CIS_CHECKS_DIR}/${script}.sh" --audit-all + + rm -f /etc/syslog-ng/conf.d/1_tcp_source + }