)]}'
{"defaults/main.yml":[{"author":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"change_message_id":"0d10da96cc498899b96ad0746cecd8ceab5241c8","unresolved":true,"context_lines":[{"line_number":354,"context_line":"security_sshd_disallow_gssapi: yes                           # V-72259"},{"line_number":355,"context_line":"# Disallow compression or delay after login."},{"line_number":356,"context_line":"security_sshd_compression: \u0027delayed\u0027                         # V-72267"},{"line_number":357,"context_line":"# Require privilege separation at every opportunity."},{"line_number":358,"context_line":"security_sshd_enable_privilege_separation: no                # V-72265"},{"line_number":359,"context_line":"# Require strict mode checking of home directory configuration files."},{"line_number":360,"context_line":"security_sshd_enable_strict_modes: yes                       # V-72263"},{"line_number":361,"context_line":"# Disallow Kerberos authentication."}],"source_content_type":"text/x-yaml","patch_set":1,"id":"07c4dad2_85350b1d","line":358,"range":{"start_line":357,"start_character":0,"end_line":358,"end_character":70},"updated":"2022-01-17 12:22:16.000000000","message":"I don\u0027t think it\u0027s aligned with https://www.stigviewer.com/stig/red_hat_enterprise_linux_7/2017-07-08/finding/V-72265\n\nShould we just drop that STIG instead if it makes no sense nowadays? Also no idea about centos-7 sshd version...","commit_id":"09ff17ad256a9590df042d64fb22657cbf05b9ae"},{"author":{"_account_id":16011,"name":"James Denton","email":"james.denton@outlook.com","username":"busterswt"},"change_message_id":"59deaf8491fafec1478f18b0b9332bad81614ad0","unresolved":true,"context_lines":[{"line_number":354,"context_line":"security_sshd_disallow_gssapi: yes                           # V-72259"},{"line_number":355,"context_line":"# Disallow compression or delay after login."},{"line_number":356,"context_line":"security_sshd_compression: \u0027delayed\u0027                         # V-72267"},{"line_number":357,"context_line":"# Require privilege separation at every opportunity."},{"line_number":358,"context_line":"security_sshd_enable_privilege_separation: no                # V-72265"},{"line_number":359,"context_line":"# Require strict mode checking of home directory configuration files."},{"line_number":360,"context_line":"security_sshd_enable_strict_modes: yes                       # V-72263"},{"line_number":361,"context_line":"# Disallow Kerberos authentication."}],"source_content_type":"text/x-yaml","patch_set":1,"id":"6cb1854a_041c9d4e","line":358,"range":{"start_line":357,"start_character":0,"end_line":358,"end_character":70},"in_reply_to":"07c4dad2_85350b1d","updated":"2022-01-17 16:52:10.000000000","message":"It may be that STIG for RHEL7 is too outdated in some regards, as there is now one for RHEL8 (and others - not Ubuntu), and I\u0027m not sure if it deprecates the RHEL7 one.","commit_id":"09ff17ad256a9590df042d64fb22657cbf05b9ae"},{"author":{"_account_id":28619,"name":"Dmitriy Rabotyagov","email":"noonedeadpunk@gmail.com","username":"noonedeadpunk"},"change_message_id":"8a0da187019d9228beab5883a775cc8be9039393","unresolved":true,"context_lines":[{"line_number":354,"context_line":"security_sshd_disallow_gssapi: yes                           # V-72259"},{"line_number":355,"context_line":"# Disallow compression or delay after login."},{"line_number":356,"context_line":"security_sshd_compression: \u0027delayed\u0027                         # V-72267"},{"line_number":357,"context_line":"# Require privilege separation at every opportunity."},{"line_number":358,"context_line":"security_sshd_enable_privilege_separation: no                # V-72265"},{"line_number":359,"context_line":"# Require strict mode checking of home directory configuration files."},{"line_number":360,"context_line":"security_sshd_enable_strict_modes: yes                       # V-72263"},{"line_number":361,"context_line":"# Disallow Kerberos authentication."}],"source_content_type":"text/x-yaml","patch_set":1,"id":"7671f068_453ba0e5","line":358,"range":{"start_line":357,"start_character":0,"end_line":358,"end_character":70},"in_reply_to":"6cb1854a_041c9d4e","updated":"2022-02-01 19:49:19.000000000","message":"What I was trying to say - we shouldn\u0027t really just by default disable some stig hat makes sense.\n\nThen I\u0027d say we should do that conditionally, based on the OS or version of sshd.","commit_id":"09ff17ad256a9590df042d64fb22657cbf05b9ae"}]}
