Improve OpenSCAP remediation safety with backup, validation and rollback
Description
PatchMon displays remediation scripts provided by OpenSCAP / SCAP Security Guide.
Some remediations can modify critical authentication or system configuration such as:
- PAM
- SSH
- firewall rules
- networking
- system authentication settings
While these remediations may be valid from a compliance perspective, applying them directly on a remote production server can cause loss of administrative access if something goes wrong.
A concrete example is the CIS rule:
xccdf_org.ssgproject.content_rule_no_empty_passwords_unix
On Debian, the generated remediation can modify PAM configuration and run pam-auth-update.
Current concern
For remote-managed systems, some remediation scripts should probably not be treated the same way as low-risk configuration changes.
For example, a PAM or SSH remediation could potentially lock administrators out of the host.
Suggested improvement
It would be useful if PatchMon introduced a safer remediation workflow:
1. Pre-check
2. Backup affected configuration
3. Preview remediation
4. Risk classification
5. Apply remediation
6. Validate configuration or service
7. Re-run the compliance rule
8. Roll back if validation fails
Suggested risk levels
- LOW — permissions or low-impact configuration
- MEDIUM — system configuration
- HIGH — authentication or service configuration
- CRITICAL — PAM, SSH, firewall or networking where remote access could be lost
HIGH and CRITICAL remediations should require explicit confirmation and ideally be excluded from unattended bulk remediation by default.
PAM example
Before applying a PAM remediation, PatchMon could:
- check whether accounts with empty passwords actually exist;
- back up /etc/pam.d;
- back up /usr/share/pam-configs;
- apply the remediation;
- validate PAM / sudo configuration;
- re-run the OpenSCAP rule;
- provide a rollback option if validation fails.
Why this would help
PatchMon is commonly used to manage remote Linux servers.
A remediation that is correct from a compliance point of view can still have operational consequences depending on the server role.
Adding safety controls around remediation would make OpenSCAP remediation safer for production environments.
0 Comments
No comments yet. Be the first to share your thoughts!
