STIGQter STIGQter: STIG Summary: Red Hat OpenShift Container Platform 4.x Security Technical Implementation Guide Version: 2 Release: 6 Benchmark Date: 01 Jul 2026:

OpenShift must generate audit records when concurrent logons from different workstations and systems occur.

DISA Rule

SV-257582r961833_rule

Vulnerability Number

V-257582

Group Title

SRG-APP-000506-CTR-001290

Rule Version

CNTR-OS-001000

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Apply the machine config so concurrent logons are audited by executing the following:

for mcpool in $(oc get mcp -oname | sed "s:.*/::" ); do
echo "apiVersion: machineconfiguration.openshift.io/v1
kind: MachineConfig
metadata:
name: 75-concurrent-logons-rules
labels:
machineconfiguration.openshift.io/role: $mcpool
spec:
config:
ignition:
version: 3.1.0
storage:
files:
- contents:
source: data:,-w%20/var/run/faillock%20-p%20wa%20-k%20logins%0A
mode: 0644
path: /etc/audit/rules.d/75-faillock_login_events.rules
overwrite: true
- contents:
source: data:,-w%20/var/log/lastlog%20-p%20wa%20-k%20logins%0A
mode: 0644
path: /etc/audit/rules.d/75-lastlog_login_events.rules
overwrite: true
" | oc apply -f -
done

Check Contents

Verify that concurrent logons are audited by executing the following:

for node in $(oc get node -oname); do oc debug $node -- chroot /host /bin/bash -c 'echo -n "$HOSTNAME "; grep "logins" /etc/audit/audit.rules /etc/audit/rules.d/*' 2>/dev/null; done

The output will look similar to:

node-name /etc/audit/<file>:-w /var/run/faillock -p wa -k logins
/etc/audit/<file>:-w /var/log/lastlog -p wa -k logins

If the two rules above are not found on each node, this is a finding.

Vulnerability Number

V-257582

Documentable

False

Rule Version

CNTR-OS-001000

Severity Override Guidance

Verify that concurrent logons are audited by executing the following:

for node in $(oc get node -oname); do oc debug $node -- chroot /host /bin/bash -c 'echo -n "$HOSTNAME "; grep "logins" /etc/audit/audit.rules /etc/audit/rules.d/*' 2>/dev/null; done

The output will look similar to:

node-name /etc/audit/<file>:-w /var/run/faillock -p wa -k logins
/etc/audit/<file>:-w /var/log/lastlog -p wa -k logins

If the two rules above are not found on each node, this is a finding.

Check Content Reference

M

Target Key

5547