Feature Requests
New / Open / Unreviewed

Improve OpenSCAP remediation safety with backup, validation and rollback

Description

PatchMon displays remediation scripts provided by OpenSCAP / SCAP Security Guide.

Some remediations can modify critical authentication or system configuration such as:

- PAM

- SSH

- firewall rules

- networking

- system authentication settings

While these remediations may be valid from a compliance perspective, applying them directly on a remote production server can cause loss of administrative access if something goes wrong.

A concrete example is the CIS rule:

xccdf_org.ssgproject.content_rule_no_empty_passwords_unix

On Debian, the generated remediation can modify PAM configuration and run pam-auth-update.

Current concern

For remote-managed systems, some remediation scripts should probably not be treated the same way as low-risk configuration changes.

For example, a PAM or SSH remediation could potentially lock administrators out of the host.

Suggested improvement

It would be useful if PatchMon introduced a safer remediation workflow:

1. Pre-check

2. Backup affected configuration

3. Preview remediation

4. Risk classification

5. Apply remediation

6. Validate configuration or service

7. Re-run the compliance rule

8. Roll back if validation fails

Suggested risk levels

- LOW — permissions or low-impact configuration

- MEDIUM — system configuration

- HIGH — authentication or service configuration

- CRITICAL — PAM, SSH, firewall or networking where remote access could be lost

HIGH and CRITICAL remediations should require explicit confirmation and ideally be excluded from unattended bulk remediation by default.

PAM example

Before applying a PAM remediation, PatchMon could:

- check whether accounts with empty passwords actually exist;

- back up /etc/pam.d;

- back up /usr/share/pam-configs;

- apply the remediation;

- validate PAM / sudo configuration;

- re-run the OpenSCAP rule;

- provide a rollback option if validation fails.

Why this would help

PatchMon is commonly used to manage remote Linux servers.

A remediation that is correct from a compliance point of view can still have operational consequences depending on the server role.

Adding safety controls around remediation would make OpenSCAP remediation safer for production environments.

0 Comments

Posting anonymously

No comments yet. Be the first to share your thoughts!