Skip to content

stigenable: drop redundant packages from KS_STIG_PACKAGES - #47

Open
dcasota wants to merge 1 commit into
vmware:masterfrom
dcasota:upstream/stig-drop-redundant-packages
Open

dcasota wants to merge 1 commit into
vmware:masterfrom
dcasota:upstream/stig-drop-redundant-packages

Conversation

@dcasota

@dcasota dcasota commented Sep 1, 2026 •

Copy link
Copy Markdown
Contributor

Removes three of the eight entries in KS_STIG_PACKAGES, and the same three from examples/ova/packages_stig.json. Each is either already satisfied transitively or is dead weight.

Package Why it can go
libselinux-utils Already a dependency of selinux-policy; the stig-hardening role never invokes any of its binaries
ntp Installed but never configured — no task in the role notifies the time-sync handlers, so all three are dead code, and 0 of the 107 PHTN-50-xxxxxx controls cover time sync
libgcrypt A workaround for aide declaring only an unversioned Requires: libgcrypt; that belongs in aide.spec

On ntp specifically

Checked against the role Photon 5.0 actually ships, stig-hardening-2.1-10.ph5 (source: vmware/dod-compliance-and-automation, photon/5.0/ansible/vmware-photon-5.0-stig-ansible-hardening):

  • tasks/ contains 107 distinct PHTN-50-xxxxxx controls and zero occurrences of ntp, chrony or timesync
  • handlers/main.yml defines restart ntpd, restart chrony and restart timesyncd. Of the 25 notify: in the role, they are referenced 0 times — the only handlers ever notified are restart sshd (21), restart rsyslog (2), restart resolved (1) and reload auditd (1)
  • var_ntp_servers appears only in README.md, never in a task

So installing ntp satisfies no control — it just adds a package.

Also dropped from examples/ova/packages_stig.json

Per review feedback. The OVA package list and the installer's own declaration now say the same thing. Keeping the two in step matters here: a list restated in two places is the drift that left the STIG menu offering an option the media could not honour.

Verified on real installs

Ten unattended permutation-matrix rows on both installer variants — photon-os-installer-2.8-7 and 2.9-3 — each a full ISO build plus a kickstart install in a VM, with the STIG rows (k03, k04, k07, k08) exercising this change directly:

  • additional_packages in the install manifest is exactly [audit, rsyslog, openssl-fips-provider, selinux-policy, aide] — 5 entries
  • libselinux-utils and libgcrypt are still installed, as ordinary transitive dependencies; dropping them from the explicit list changed nothing about what lands on the system
  • ntp/ntpsec are not installed, and time sync works: systemd-timesyncd active, System clock synchronized: yes
  • STIG ansible run: 0 failed tasks; 0 failed units and no Error(1011) on any row

One note on SELinux, since an earlier revision of this description got it wrong: these installs boot Permissive, and that is correct rather than a regression. selinux-policy ships SELINUX=permissive at subrelease ≥ 92 by design; only builds at subrelease ≤ 90 boot Enforcing. This change does not affect the mode either way.

Related

The aide side of this is a versioned Requires: libgcrypt >= 1.10.4 guarded by photon_subrelease >= 91, filed separately against the photon repo (dcasota/photon#21).

@oliverkurth

Copy link
Copy Markdown
Collaborator

I guess these can then also be removed from examples/ova/packages_stig.json. Can you please try that and test?

Three of the eight entries are removed. Each is either already satisfied
transitively or is dead weight:

  libselinux-utils  already a dependency of selinux-policy, and the
                    stig-hardening role never invokes any of its binaries
  ntp               installed but never configured - no task in the role
                    notifies the time-sync handlers, and 0 of the 107
                    PHTN-50-xxxxxx controls cover time sync
  libgcrypt         a workaround for aide declaring only an unversioned
                    Requires: libgcrypt; that belongs in aide.spec

The same three are dropped from examples/ova/packages_stig.json, so the OVA
package list and the installer's own list say the same thing. Keeping the two
in step matters: a list restated in two places is how the media and the
installer drifted apart in the first place.

Verified on four real STIG installs - two on photon-os-installer 2.8, two on
latest - whose manifests carry the reduced additional_packages list
[audit, rsyslog, openssl-fips-provider, selinux-policy, aide]:

  libselinux-utils              installed, transitively
  libgcrypt                     installed, transitively
  ntp / ntpsec                  absent, and time sync works via
                                systemd-timesyncd

aide's dependency is now a versioned Requires: libgcrypt >= 1.10.4, confirmed
in aide-0.19-3.ph5, so nothing rests on the unversioned form any more.

Signed-off-by: Daniel Casota <dcasota@gmail.com>
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JW73JTCUGRcaNTUEQcAMtf
@dcasota
dcasota force-pushed the upstream/stig-drop-redundant-packages branch from d3ac861 to 964162b Compare September 2, 2026 06:07
@dcasota

dcasota commented Sep 2, 2026

Copy link
Copy Markdown
Contributor Author

The PR has been modified and tested with minimal ISO, kickstart, x86_64, without/with STIG, prebuilt canister. The ongoing tests with a full iso x86_64 should be fine, too. aarch64 hasn't been tested.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants