From f89a864b33f4eec2ff57dbb52b00e67de643d4f8 Mon Sep 17 00:00:00 2001 From: Thibault Ayanides Date: Tue, 27 Oct 2020 11:06:27 +0100 Subject: [PATCH] IMP(6.2.15): add purposely failing tests --- .../6.2.15_find_passwd_group_inconsistencies.sh | 12 +++++++++++- 1 file changed, 11 insertions(+), 1 deletion(-) diff --git a/tests/hardening/6.2.15_find_passwd_group_inconsistencies.sh b/tests/hardening/6.2.15_find_passwd_group_inconsistencies.sh index b333419..8e1da73 100644 --- a/tests/hardening/6.2.15_find_passwd_group_inconsistencies.sh +++ b/tests/hardening/6.2.15_find_passwd_group_inconsistencies.sh @@ -6,5 +6,15 @@ test_audit() { # shellcheck disable=2154 run blank /opt/debian-cis/bin/hardening/"${script}".sh --audit-all - # TODO fill comprehensive tests + local test_user="testpasswdgroupuser" + local dir="/etc/passwd" + + describe Tests purposely failing + echo "$test_user:x:1100:1100::/home/$test_user:" >> $dir + register_test retvalshouldbe 1 + register_test contain "is referenced by /etc/passwd but does not exist in /etc/group" + run noncompliant /opt/debian-cis/bin/hardening/"${script}".sh --audit-all + + # cleanup + userdel $test_user }