2025-11-03 - 2026-02-03

Overview

0 Active Pull Requests
333 Active Issues
Excluding merges, 0 authors have pushed 0 commits to main and 171 commits to all branches. On main, 0 files have changed and there have been 0 additions and 0 deletions.

4 Releases published by 1 user

Published tahoe_rev2 2025-12-18 18:21:37 +00:00

Published sequoia_rev4 2025-12-18 18:21:06 +00:00

Published visionos26_rev2 2025-12-18 18:20:36 +00:00

Published ios26_rev2 2025-12-18 18:20:16 +00:00

312 Issues closed from 1 user

Closed #329 profile_generator.py - All baselines use the same 'mobileconfigs' directory 2026-01-19 18:30:05 +00:00

Closed #328 Consider adding a mapping for Common Criteria GPOS 4.2.1 2026-01-19 18:30:05 +00:00

Closed #330 Suggest mapping to the NCSC CyberEssentials 2026-01-19 18:30:05 +00:00

Closed #332 Baselines path incorrect in Wiki documentation 2026-01-19 18:30:05 +00:00

Closed #333 Baseline names should be more descriptive. 2026-01-19 18:30:05 +00:00

Closed #331 Consider adding an 800-171 baseline 2026-01-19 18:30:05 +00:00

Closed #327 Suggest mapping to the ACSC ISM 2026-01-19 18:30:04 +00:00

Closed #325 Setting for TimeServer 2026-01-19 18:30:04 +00:00

Closed #326 sysprefs_ad_tracking_disable check 2026-01-19 18:30:04 +00:00

Closed #323 Filename tweak 2026-01-19 18:30:03 +00:00

Closed #322 Missing full paths 2026-01-19 18:30:03 +00:00

Closed #324 Additional rule Disable Improve Siri & Dictation 2026-01-19 18:30:03 +00:00

Closed #320 Overwriting baseline files 2026-01-19 18:30:03 +00:00

Closed #319 profile_generator.py doesn't work unless you change directory to the "scripts" directory first 2026-01-19 18:30:03 +00:00

Closed #321 rules listed in the wrong section in baselines 2026-01-19 18:30:03 +00:00

Closed #318 sysprefs_diagnostics_reports_disable 2026-01-19 18:30:02 +00:00

Closed #313 sysprefs_find_my_disable 2026-01-19 18:30:02 +00:00

Closed #314 Concurrent session limit for SSH is not working 2026-01-19 18:30:02 +00:00

Closed #317 Consider adding a GLBA baseline 2026-01-19 18:30:02 +00:00

Closed #316 os_camera_disable 2026-01-19 18:30:02 +00:00

Closed #315 os_siri_prompt_disable 2026-01-19 18:30:02 +00:00

Closed #310 Option to sign generated profiles please! 2026-01-19 18:30:01 +00:00

Closed #312 Add a default value / Arg to generate_script 2026-01-19 18:30:01 +00:00

Closed #311 Generate Guidance script - excel export 2026-01-19 18:30:01 +00:00

Closed #307 Check for Apple Mobile File Integrity 2026-01-19 18:30:00 +00:00

Closed #305 cross reference for how rules are implemented in a tool 2026-01-19 18:30:00 +00:00

Closed #306 audit_events Sandbox violations 2026-01-19 18:30:00 +00:00

Closed #304 custom reference data should be displayed in generated documents and spreadsheet 2026-01-19 18:30:00 +00:00

Closed #309 Check for Library Validation 2026-01-19 18:30:00 +00:00

Closed #308 Option to generate plists for custom configuration profiles 2026-01-19 18:30:00 +00:00

Closed #299 Cleanup references 2026-01-19 18:29:59 +00:00

Closed #298 metadata subsection to track changes in customized rules 2026-01-19 18:29:59 +00:00

Closed #301 os_mdm_require.yaml needs to be updated for macOS 11 2026-01-19 18:29:59 +00:00

Closed #300 CJIS Baseline 2026-01-19 18:29:59 +00:00

Closed #302 Re-Map os_guest_account_disable 2026-01-19 18:29:59 +00:00

Closed #303 Fix language in os_certificate_authority_trust 2026-01-19 18:29:59 +00:00

Closed #297 Definition of exemption 2026-01-19 18:29:58 +00:00

Closed #295 add (sub)subtitles for the documentation. 2026-01-19 18:29:58 +00:00

Closed #296 fixtext commands are broken; have newline chars instead of spaces 2026-01-19 18:29:58 +00:00

Closed #289 Creation of the Excel doc with Custom references, adds extra rows while the name is the same 2026-01-19 18:29:57 +00:00

Closed #294 Missing result for this test 2026-01-19 18:29:57 +00:00

Closed #293 Fix audit_files_(group/mode/owner)_configure 2026-01-19 18:29:57 +00:00

Closed #292 Use domain-specific naming in 'PayloadDisplayName' key of configuration profiles 2026-01-19 18:29:57 +00:00

Closed #291 mobileconfig creation ignores exempt preferences settings 2026-01-19 18:29:57 +00:00

Closed #290 os_sshd_key_exchange_algorithm_configure.yaml does not have a fallback to adding the relevant line 2026-01-19 18:29:57 +00:00

Closed #284 Rule - os_facetime_app_disable.yaml - STIG ID is listed as ASOX-14-002010. It should be APPL-11-002010 2026-01-19 18:29:56 +00:00

Closed #286 os_guest_access_smb_disable 2026-01-19 18:29:56 +00:00

Closed #285 Rule - os_filevault_user_account - Change needed for Apple silicon 2026-01-19 18:29:56 +00:00

Closed #283 Add "all_rules" to generate_baseline.py -l 2026-01-19 18:29:56 +00:00

Closed #287 os_airdrop_disable check and remediation are inconsistent 2026-01-19 18:29:56 +00:00

Closed #288 audit_flags_fm_configure 2026-01-19 18:29:56 +00:00

Closed #282 audit_control policy cnt vs ahlt 2026-01-19 18:29:55 +00:00

Closed #281 auth_ssh_smartcard_enforce rename 2026-01-19 18:29:55 +00:00

Closed #280 Prevent fixes when not needed 2026-01-19 18:29:55 +00:00

Closed #277 big_sur branch has two rules that claim to be APPL-11-000001 2026-01-19 18:29:54 +00:00

Closed #278 git clone is broken 2026-01-19 18:29:54 +00:00

Closed #274 ASOX is not a normal STIG ID 2026-01-19 18:29:54 +00:00

Closed #275 mismatch between STIG rules and current version for big_sur branch 2026-01-19 18:29:54 +00:00

Closed #276 compliance_count function in generated guidance script does not correctly count findings 2026-01-19 18:29:54 +00:00

Closed #279 custom rule that sets mobileconfig: false still ends up creating a .mobileprofile file 2026-01-19 18:29:54 +00:00

Closed #269 Directory services integration test returns multiple values 2026-01-19 18:29:53 +00:00

Closed #270 Add sections for project and local site authors to custom baselines 2026-01-19 18:29:53 +00:00

Closed #271 Tag and Compliance Script check for Intel vs Apple Silicon 2026-01-19 18:29:53 +00:00

Closed #273 setting pwpolicy_file 2026-01-19 18:29:53 +00:00

Closed #272 Errors generating CIS compliance profiles 2026-01-19 18:29:53 +00:00

Closed #268 14.3. Password Policy Supplemental duplicate entry? 2026-01-19 18:29:53 +00:00

Closed #266 Firmware password check does not work on Apple Silicon-based machines. 2026-01-19 18:29:52 +00:00

Closed #267 Sudoers authenticate on per -tty basis 2026-01-19 18:29:52 +00:00

Closed #265 Mobileconfig profiles do not honor compliance script exemptions 2026-01-19 18:29:52 +00:00

Closed #259 STIG Big_Sure os_ESS_installed 2026-01-19 18:29:51 +00:00

Closed #264 Compliance script run with --fix does not apply fixes unless --check was run first 2026-01-19 18:29:51 +00:00

Closed #262 baseline compliance script output to Unified Logging 2026-01-19 18:29:51 +00:00

Closed #260 ChallengeResponseAuthentication not present in macOS Monterey 2026-01-19 18:29:51 +00:00

Closed #261 JXA Checks are causing the generated baseline_compliance.sh to break 2026-01-19 18:29:51 +00:00

Closed #263 sysprefs_wifi_disable.yaml ignored for STIG compliance 2026-01-19 18:29:51 +00:00

Closed #258 os_sudo_timeout_configure adjust check for possible spaces 2026-01-19 18:29:50 +00:00

Closed #257 time server enforcement values possibly deprecated. 2026-01-19 18:29:50 +00:00

Closed #256 (dev_monterey) os_install_log_retention_policy and audit_flags_configure not remediating 2026-01-19 18:29:50 +00:00

Closed #252 Duplicate security controls and missing reference values in 2026-01-19 18:29:49 +00:00

Closed #254 mismatched test and remediate for Monterey os_blank_bluray_disable.yaml 2026-01-19 18:29:49 +00:00

Closed #255 Disable Siri prefpane 2026-01-19 18:29:49 +00:00

Closed #253 mismatched test and mobileconfig for Monterey os_burn_support_disable 2026-01-19 18:29:49 +00:00

Closed #248 os_sudoers_tty_configure.yaml check and fix don't work 2026-01-19 18:29:48 +00:00

Closed #249 missing EOS in some rules 2026-01-19 18:29:48 +00:00

Closed #251 Add an "id:" tag to the baseline .yaml files for easier distinction between baselines versus using the "title:" tag 2026-01-19 18:29:48 +00:00

Closed #247 Modify the arg checking to suit Jamf Pro policies 2026-01-19 18:29:48 +00:00

Closed #250 remediation for os_policy_banner_loginwindow_enforce creates a wrongly named directory 2026-01-19 18:29:48 +00:00

Closed #244 Test Rule 2 2026-01-19 18:29:47 +00:00

Closed #241 Stats Reporting Incorrect 2026-01-19 18:29:47 +00:00

Closed #243 Removing a rule from guidance will not remove the rule from audit file 2026-01-19 18:29:47 +00:00

Closed #242 audit_retention_configure_sixty_days remediation not getting picked up by Jamf Protect insights 2026-01-19 18:29:47 +00:00

Closed #245 Test screensaver timeout 2026-01-19 18:29:47 +00:00

Closed #246 TOC not being generated when asciidoctor-pdf 2.0.x is installed 2026-01-19 18:29:47 +00:00

Closed #239 Remove requirement for admin prompt when install ruby gems 2026-01-19 18:29:46 +00:00

Closed #238 os_software_update_deferral gives fails finding if 'enforcedSoftwareUpdateDelay' key is not set 2026-01-19 18:29:46 +00:00

Closed #240 pwpolicy_account_lockout_enforce should check if value is less than or equal 2026-01-19 18:29:46 +00:00

Closed #234 Update sshd Checks 2026-01-19 18:29:45 +00:00

Closed #237 Add an option to view a description of rules when creating a tailored baseline 2026-01-19 18:29:45 +00:00

Closed #236 Make Configuration Profile Display Names specific to payload 2026-01-19 18:29:45 +00:00

Closed #235 os_recovery_lock_enable has incorrect key 2026-01-19 18:29:45 +00:00

Closed #233 rules/os/os_library_validation_enabled.yaml fails with: "run_fix:242: command not found: This" 2026-01-19 18:29:45 +00:00

Closed #232 sysprefs_software_update_app_update_enforce 2026-01-19 18:29:45 +00:00

Closed #230 Ummm, HOWTO 2026-01-19 18:29:44 +00:00

Closed #229 sysprefs_screensaver_ask_for_password_delay_enforce not remediated 2026-01-19 18:29:44 +00:00

Closed #231 os_hibernate_mode_enable: remediation is not effective 2026-01-19 18:29:44 +00:00

Closed #227 Disabled launchctl reports incorrectly (Ventura) 2026-01-19 18:29:44 +00:00

Closed #226 Generate_baseline -t crash 2026-01-19 18:29:44 +00:00

Closed #228 Format problem in remediation of a number of 'os' section rules 2026-01-19 18:29:44 +00:00

Closed #225 Modify sysprefs_siri_disable to use "com.apple.assistant.support" instead of "com.apple.ironwood.support" 2026-01-19 18:29:43 +00:00

Closed #223 ODV - Parent value not being applied properly 2026-01-19 18:29:43 +00:00

Closed #224 sysprefs_system_wide_preferences_configure shared key doesn't exist on some systems 2026-01-19 18:29:43 +00:00

Closed #221 Profiles with multiple disabled Pref Panes keys not detected 2026-01-19 18:29:42 +00:00

Closed #222 Big Sur Compliance Script Error 2026-01-19 18:29:42 +00:00

Closed #220 Fix CIS mappings from new draft 2026-01-19 18:29:42 +00:00

Closed #217 os_sshd_permit_root_login_configure code fails to run the validation script 2026-01-19 18:29:41 +00:00

Closed #219 Rules missing 800-53 references 2026-01-19 18:29:41 +00:00

Closed #218 icloud_appleid_system_settings_disable checking script seems to be returning inconsistent data 2026-01-19 18:29:41 +00:00

Closed #216 auth_ssh_password_authentication_disable needs to be updated for Ventura 2026-01-19 18:29:40 +00:00

Closed #215 JCE CIS Level 1 Rules are showing 2.9.3 (Level 2) 2026-01-19 18:29:40 +00:00

Closed #213 system_settings_ssh_enable check 2026-01-19 18:29:40 +00:00

Closed #214 system_settings_system_wide_preferences_configure for loop syntax 2026-01-19 18:29:40 +00:00

Closed #212 os_sshd_fips_compliant remediate issue 2026-01-19 18:29:40 +00:00

Closed #211 os_sshd_key_exchange_algorithm_configure detection issue 2026-01-19 18:29:40 +00:00

Closed #207 How to run macOS security compliance script on multiple mac devices using workspaceone MDM 2026-01-19 18:29:39 +00:00

Closed #205 os_sshd_permit_root_login_configure remediation code appends "permitrootlogin no" 2026-01-19 18:29:39 +00:00

Closed #210 Generated compliance script debug mode 2026-01-19 18:29:39 +00:00

Closed #206 Consider creating a rule that turns off Xcode Ads for Xcode Cloud 2026-01-19 18:29:39 +00:00

Closed #208 os_install_log_retention_configure 2026-01-19 18:29:39 +00:00

Closed #209 os_hibernate_mode_enable Missing hibernatemode (and spelling error) 2026-01-19 18:29:39 +00:00

Closed #202 generate_baseline.py crash with custom baselines 2026-01-19 18:29:38 +00:00

Closed #204 Rogue Highlighter 4.0.0 is not compatible with built-in Ruby 2026-01-19 18:29:38 +00:00

Closed #203 DisableGuestAccount/EnableGuestAccount key 2026-01-19 18:29:38 +00:00

Closed #201 system_settings_time_machine_encrypted_configure.yaml incorrect tag for CIS 2026-01-19 18:29:37 +00:00

Closed #196 handful of settings aren't "fixed" by compliance script 2026-01-19 18:29:37 +00:00

Closed #200 Include check that FileVault cannot be disabled in system_settings_filevault_enforce or create new rule to check 2026-01-19 18:29:37 +00:00

Closed #199 os_hibernate_mode_enable: Standby setting for Apple silicon is incorrect 2026-01-19 18:29:37 +00:00

Closed #197 where is the page that describes how to install these ? 2026-01-19 18:29:37 +00:00

Closed #198 USB Restricted Mode 2026-01-19 18:29:37 +00:00

Closed #195 Tweak SSH rules for FIPS 186-5 addition of curve25519-sha256 2026-01-19 18:29:36 +00:00

Closed #194 JAMF integration? 2026-01-19 18:29:36 +00:00

Closed #193 checking for authenticated-root hangs forever when multiple OSes are available 2026-01-19 18:29:36 +00:00

Closed #190 Create a script who doesn't need answer to fix non compliant settings 2026-01-19 18:29:35 +00:00

Closed #191 Add Safari rules for Monterey (CIS) 2026-01-19 18:29:35 +00:00

Closed #192 Set rules with pathBlackList to deprecated 2026-01-19 18:29:35 +00:00

Closed #184 Script should explicitly set LANG=C to avoid problems with localized output 2026-01-19 18:29:34 +00:00

Closed #189 Add command to remove uchg flag from /etc/security/audit_control 2026-01-19 18:29:34 +00:00

Closed #185 forceInternetSharingOff is failing check, but the key is set in com.apple.MCX 2026-01-19 18:29:34 +00:00

Closed #186 os_anti_virus_installed returns unexpected result ('integer': 3) 2026-01-19 18:29:34 +00:00

Closed #188 Scutil is referenced without full path 2026-01-19 18:29:34 +00:00

Closed #187 os_secure_boot_verify - bputil 2026-01-19 18:29:34 +00:00

Closed #182 sshd checks sometimes fail for reasons other than the rule 2026-01-19 18:29:32 +00:00

Closed #183 Checks adding to /etc/sudoers.d directory fail on fresh 13.3 installs 2026-01-19 18:29:32 +00:00

Closed #181 generate_scap crash 2026-01-19 18:29:32 +00:00

Closed #180 Asciidoctor-pdf 2.3.6 [undefined method `absolute_path?' for File:Class] error 2026-01-19 18:29:31 +00:00

Closed #177 sshd banner check and fix 2026-01-19 18:29:31 +00:00

Closed #176 clientalivecountmax and clientaliveinterval 2026-01-19 18:29:31 +00:00

Closed #179 Provide indication of whether each Guideline corresponds to Apple's default setting 2026-01-19 18:29:31 +00:00

Closed #178 Using "heredoc" Breaks Commands 2026-01-19 18:29:31 +00:00

Closed #173 Ventura firewall mobileconfig fails to install 2026-01-19 18:29:30 +00:00

Closed #175 Rule 7.7 Secure User's Home Folder is not reporting correctly 2026-01-19 18:29:30 +00:00

Closed #172 os_policy_banner_ssh_configure fails on Ventura even after remediation 2026-01-19 18:29:30 +00:00

Closed #174 compliance script should be able to say which rules fail 2026-01-19 18:29:30 +00:00

Closed #171 firmware password requirement not applicable to Apple silicon according to STIG 2026-01-19 18:29:29 +00:00

Closed #170 Compliance percentage incorrect when exempted rules pass 2026-01-19 18:29:29 +00:00

Closed #169 os_anti_virus_installed rule 2026-01-19 18:29:29 +00:00

Closed #167 Application Layer Firewall new check required 2026-01-19 18:29:28 +00:00

Closed #163 Computers that fail os_time_offset_limit_configure 2026-01-19 18:29:28 +00:00

Closed #166 Remediations on audit_control cause chaos if file is missing 2026-01-19 18:29:28 +00:00

Closed #168 Fraudulent typo 2026-01-19 18:29:28 +00:00

Closed #164 Sonoma - sshd config updates 2026-01-19 18:29:28 +00:00

Closed #165 com.apple.locationmenu missing from supported_payloads 2026-01-19 18:29:28 +00:00

Closed #162 CIS Manual Recommendations not generating properly 2026-01-19 18:29:27 +00:00

Closed #161 Indicate manual rules that are included in the baseline 2026-01-19 18:29:27 +00:00

Closed #160 Compliance percentage incorrect when exempted rules pass #267 “best practice!!! 2026-01-19 18:29:27 +00:00

Closed #154 os_install_log_retention_configure - remediation does not match check 2026-01-19 18:29:26 +00:00

Closed #155 CIS Lvl 1 6.1.1 failing false positives 2026-01-19 18:29:26 +00:00

Closed #159 submit profiles by CIS section vs functionality section 2026-01-19 18:29:26 +00:00

Closed #157 Generate recommendations Python script relies on very out of date Ruby gems 2026-01-19 18:29:26 +00:00

Closed #158 Monterey 800-171 .GlobalPreferences settings mobile config not importing into JAMF 2026-01-19 18:29:26 +00:00

Closed #156 Wiki Compliance Script typo 2026-01-19 18:29:26 +00:00

Closed #151 audit_retention_configure fails to edit the /etc/security/audit_control file 2026-01-19 18:29:25 +00:00

Closed #153 os_anti_virus_installed errors: Load Failed 5 (Sonoma) 2026-01-19 18:29:25 +00:00

Closed #152 audit_flags_fm_configure fails in dev_sonoma because of the ^fm 2026-01-19 18:29:25 +00:00

Closed #148 Configuration Profile -locationmenu not working 2026-01-19 18:29:24 +00:00

Closed #149 os_sshd_unused_connection_timeout_configure for dev_sonoma typo error 2026-01-19 18:29:24 +00:00

Closed #150 icloud_appleid_system_settings_disable (dev_sonoma) refers to deprecated domain 2026-01-19 18:29:24 +00:00

Closed #147 pwpolicy_account_lockout_enforce issues with Sonoma 2026-01-19 18:29:23 +00:00

Closed #145 os_safari_javascript_enabled not detected properly 2026-01-19 18:29:23 +00:00

Closed #144 Configuration Profile Generation 2026-01-19 18:29:23 +00:00

Closed #142 os_recovery_lock_enable should not have a manual tag 2026-01-19 18:29:23 +00:00

Closed #143 feat: support syspolicy_check a new feature in Sonoma to determine if the provided macOS application will pass the current running configurations’ system policy. 2026-01-19 18:29:23 +00:00

Closed #146 Suppress Script Output Option 2026-01-19 18:29:23 +00:00

Closed #140 iCloud privacy relay disable not working 2026-01-19 18:29:22 +00:00

Closed #141 os_gatekeeper_enable - Sonoma - Misconfiguration 2026-01-19 18:29:22 +00:00

Closed #139 Space missing in $CURRENT_USER code in adoc files 2026-01-19 18:29:22 +00:00

Closed #138 build/cis_lvl1/cis_lvl1_compliance.sh: line 6359: syntax error near unexpected token `fi' 2026-01-19 18:29:21 +00:00

Closed #137 Add baseline tags to supplemental rules 2026-01-19 18:29:21 +00:00

Closed #133 Different payload type for system_settings_screensaver_timeout_enforce 2026-01-19 18:29:21 +00:00

Closed #136 Bug: syslog daemon changes break its usage on macOS 10.13 and above 2026-01-19 18:29:21 +00:00

Closed #135 Remove multiple NTP servers from system_settings_time_server_configure.yaml 2026-01-19 18:29:21 +00:00

Closed #134 system_settings_apple_watch_unlock_disable & system_settings_touchid_unlock_disable should not be mapped to AC-11 2026-01-19 18:29:21 +00:00

Closed #127 os_mail_app_disable results in annoying popups after every login 2026-01-19 18:29:20 +00:00

Closed #132 safariAllowPopups doesn't work in Sonoma (and possibly earlier versions) 2026-01-19 18:29:20 +00:00

Closed #131 Add requirement to review exemptions to smart card login. 2026-01-19 18:29:20 +00:00

Closed #129 Prohibit execution from /tmp 2026-01-19 18:29:20 +00:00

Closed #130 Tailored by is missing in PDF output 2026-01-19 18:29:20 +00:00

Closed #128 os_hibernate_mode_apple_silicon_enable checking is broken 2026-01-19 18:29:20 +00:00

Closed #126 Rules having both the fix and the profile 2026-01-19 18:29:19 +00:00

Closed #124 Rule: os_password_hint_remove reports wrong for Guest account in the as-is audit script 2026-01-19 18:29:19 +00:00

Closed #125 os_unlock_active_user_session_disable should be an ODV 2026-01-19 18:29:19 +00:00

Closed #118 generate_baseline.py invalid escape sequence 2026-01-19 18:29:18 +00:00

Closed #122 system_settings_remote_management_disable avoid undocumented mdmclient 2026-01-19 18:29:18 +00:00

Closed #123 os_root_disable alternative implementation 2026-01-19 18:29:18 +00:00

Closed #121 SIP protected services 2026-01-19 18:29:18 +00:00

Closed #116 pwpolicy_custom_regex_enforce fix statement and note 2026-01-19 18:29:17 +00:00

Closed #115 Rules are tagged with 'stig' that do not have STIG References 2026-01-19 18:29:17 +00:00

Closed #117 os_world_writable_system_folder_configure new restricted folder 2026-01-19 18:29:17 +00:00

Closed #110 os_setup_assistant_filevault_enforce checks for wrong type 2026-01-19 18:29:16 +00:00

Closed #113 DISA customer pointed out potential issue with regex in pwpolicy_custom_regex_enforce 2026-01-19 18:29:16 +00:00

Closed #114 SyntaxWarning for python string \| with sufficiently new python version 2026-01-19 18:29:16 +00:00

Closed #112 STIG guidance leads to inconsistent failed password account locking time 2026-01-19 18:29:16 +00:00

Closed #111 Retain previous finding if check fails 2026-01-19 18:29:16 +00:00

Closed #109 unable to generate tailored baseline 2026-01-19 18:29:16 +00:00

Closed #104 Add --no-rcs to compliance script 2026-01-19 18:29:15 +00:00

Closed #108 Update PDF & HTML based on platform 2026-01-19 18:29:15 +00:00

Closed #105 Set ODV values (and perhaps other things like excluded rules) non-interactively 2026-01-19 18:29:15 +00:00

Closed #106 pwpolicy_account_lockout_enforce not presenting expected result in Log 2026-01-19 18:29:15 +00:00

Closed #107 kickstart references in benchmarks 2026-01-19 18:29:15 +00:00

Closed #103 os_world_writable_system_folder_configure borken since Sonoma 14.4 2026-01-19 18:29:15 +00:00

Closed #100 generate_guidance fails when using all_rules on the Sonoma branch 2026-01-19 18:29:14 +00:00

Closed #102 Add SFR references to iOS documents 2026-01-19 18:29:14 +00:00

Closed #101 system_settings_system_wide_preferences_configure 2026-01-19 18:29:14 +00:00

Closed #98 pwpolicy_force_pin_enable 2026-01-19 18:29:14 +00:00

Closed #99 Feature Proposal: Generate guidance in Markdown format 2026-01-19 18:29:14 +00:00

Closed #94 Asciidoctor 2.0.23 breaks html and pdf output 2026-01-19 18:29:13 +00:00

Closed #96 Changing time server value is not respected, always, in the remediation section 2026-01-19 18:29:13 +00:00

Closed #97 authorizationdb rules 2026-01-19 18:29:13 +00:00

Closed #95 DISA STIG - Text Updates 2026-01-19 18:29:13 +00:00

Closed #92 Undefined reference to 'parser' in main() of generate_baseline.py 2026-01-19 18:29:12 +00:00

Closed #90 Add basic usage instructions 2026-01-19 18:29:12 +00:00

Closed #93 SyntaxWarning: invalid escape sequence '\|' 2026-01-19 18:29:12 +00:00

Closed #88 Scripts fail if yaml file has .yml extension 2026-01-19 18:29:12 +00:00

Closed #89 system_settings_siri_listen_disable result check incorrect 2026-01-19 18:29:12 +00:00

Closed #91 Store lastComplianceCheck date string as a regularised value 2026-01-19 18:29:12 +00:00

Closed #83 system_settings_wake_network_access_disable resets on check 2026-01-19 18:29:11 +00:00

Closed #87 system_settings_wake_network_access_disable failed in VM devices 2026-01-19 18:29:11 +00:00

Closed #86 system_settings_loginwindow_loginwindowtext_enable appear in the configuration profile when not selected 2026-01-19 18:29:11 +00:00

Closed #85 system_settings_system_wide_preferences_configure.yaml is missing full path to security binary 2026-01-19 18:29:11 +00:00

Closed #81 Consider adding the newsyslog.d directory to the newsyslog rules 2026-01-19 18:29:10 +00:00

Closed #79 remove system_settings_cd_dvd_sharing_disable 2026-01-19 18:29:10 +00:00

Closed #82 $ODV value not replaced correctly in nested dict 2026-01-19 18:29:10 +00:00

Closed #80 New privacy switches in macOS 15 are not managed by allowDiagnosticSubmission 2026-01-19 18:29:10 +00:00

Closed #78 system_settings_improve_assistive_voice_disable.yaml mis-identified CIS control number 2026-01-19 18:29:09 +00:00

Closed #77 system_settings_improve_search_disable.yaml mis-identified as a CIS Level 1 control 2026-01-19 18:29:09 +00:00

Closed #76 system_settings_software_update_enforce.yaml has been silently deprecated by Apple 2026-01-19 18:29:09 +00:00

Closed #74 fix for os_ssh_server_alive_interval_configure.yaml is not successful 2026-01-19 18:29:08 +00:00

Closed #72 "check" script in system_settings_screensaver_ask_for_password_delay_enforce.yaml throws a syntax error 2026-01-19 18:29:08 +00:00

Closed #71 STIG tag missing from system_settings_improve_assistive_voice_disable.yaml 2026-01-19 18:29:08 +00:00

Closed #73 Add Apple Intelligence Controls 2026-01-19 18:29:08 +00:00

Closed #75 os_world_writable_library_folder_configure.yaml blocked by SIP? 2026-01-19 18:29:08 +00:00

Closed #70 pwpolicy_special_character_enforce: enforce more than 1 special character. 2026-01-19 18:29:08 +00:00

Closed #69 os_install_log_retention_configure - TTL will be removed after update 2026-01-19 18:29:07 +00:00

Closed #68 Running compliance script generated by Jamf Compliance Editor in terminal and the GUI "Audit Run" results differ. (CISL1) 2026-01-19 18:29:07 +00:00

Closed #63 15.3/18.3 and 15.4/18.4 keys to add 2026-01-19 18:29:06 +00:00

Closed #64 Generate Guidance does not fill out Severity Column in xlsx spreadsheet 2026-01-19 18:29:06 +00:00

Closed #62 Create a 2.x release of mSCP 2026-01-19 18:29:06 +00:00

Closed #65 ScreenSaver 2026-01-19 18:29:06 +00:00

Closed #61 forelliN 2026-01-19 18:29:06 +00:00

Closed #66 Fix pwpolicy_upper_case_character_enforce.yaml 2026-01-19 18:29:06 +00:00

Closed #59 CIS1 Password length incorrect 2026-01-19 18:29:05 +00:00

Closed #58 openSSH 9.8 - SC-05 2026-01-19 18:29:05 +00:00

Closed #60 Compliance Count CIS lvl2 2026-01-19 18:29:05 +00:00

Closed #56 system_settings_siri_listen_disable not working as intended 2026-01-19 18:29:04 +00:00

Closed #55 macOS Major version specific Audit preference file domains 2026-01-19 18:29:04 +00:00

Closed #57 Multiple issues with pwpolicy_ on Sequoia (Using Jamf Connect with EntraID as the OIDC Provider) 2026-01-19 18:29:04 +00:00

Closed #49 User Preferences Revert to Defaults Following Reboot 2026-01-19 18:29:03 +00:00

Closed #51 Request for Script or Function to Rollback Executed Commands 2026-01-19 18:29:03 +00:00

Closed #50 Generate findings report in XLS and PDF format 2026-01-19 18:29:03 +00:00

Closed #54 generate_scap.py is not functioning as expected 2026-01-19 18:29:03 +00:00

Closed #48 MacOS 15 defintion for CCE-94310 "Configure Sudo To Log Events" calls the same testID twice 2026-01-19 18:29:02 +00:00

Closed #46 Platform SSO and os_unlock_active_user_session_disable 2026-01-19 18:29:02 +00:00

Closed #45 Inconsistent Output with Guest User Directory Detection Script 2026-01-19 18:29:02 +00:00

Closed #47 False negative with V-268546 - The macOS system must enforce multifactor authentication for privilege escalation through the sudo command. 2026-01-19 18:29:02 +00:00

Closed #41 SecureKeyboardEntry not working in Tahoe 2026-01-19 18:29:01 +00:00

Closed #43 system_settings_ssh_disable (Commands discrepancy) 2026-01-19 18:29:01 +00:00

Closed #40 CMMC Baselines (SSH set to both Disable and Enable) 2026-01-19 18:29:01 +00:00

Closed #42 Rule updates for Sequoia -- os_appleid_prompt_disable, os_icloud_storage_prompt_disable, and more... 2026-01-19 18:29:01 +00:00

Closed #39 os_authenticated_root_enable is need to supress the errors 2026-01-19 18:29:00 +00:00

Closed #37 launchctl list vs print-disabled 2026-01-19 18:29:00 +00:00

Closed #34 Output of check using jq for two DDM rules fail to match 2026-01-19 18:29:00 +00:00

Closed #36 False failures with os_unlock_active_user_session_disable (Sequioa Branch) 2026-01-19 18:29:00 +00:00

Closed #30 FileVault enforcement requires FileVault payload 2026-01-19 18:28:59 +00:00

Closed #29 Password enforcement fails with allowPasscodeModification=false 2026-01-19 18:28:59 +00:00

Closed #33 Time Machine encryption check fails with space in mount point - system_settings_time_machine_encrypted_configure 2026-01-19 18:28:59 +00:00

Closed #32 Generate a consolidated configuration profile 2026-01-19 18:28:59 +00:00

Closed #26 system_settings_cd_dvd_sharing_disable rule missing from macOS 14 Sequoia and macOS 15 Sonoma 2026-01-19 18:28:58 +00:00

Closed #28 pwpolicy_minimum_length_enforce fails when min length > ODV 2026-01-19 18:28:58 +00:00

Closed #25 Configure the default behavior of the check/remediate script when run from a MDM without flag support. 2026-01-19 18:28:58 +00:00

Closed #27 Typo in os_notes_transcription_summary_disable rule on iOS_26 branch 2026-01-19 18:28:58 +00:00

Closed #23 Typo for os_siri_assistant_disable 2026-01-19 18:28:57 +00:00

Closed #24 Typo in os_implement_cryptography and os_required_crypto_module in macOS Tahoe 2026-01-19 18:28:57 +00:00

Closed #22 Modifications to "authorizationdb" in 2.6.8 cause other commands to fail when run by root, sudo or by an mdm agent 2026-01-19 18:28:57 +00:00

Closed #19 system_settings_sleep_enforce rule has same detection limitations as os_sleep_and_display_sleep_apple_silicon_enable on Apple Silicon 2026-01-19 18:28:57 +00:00

Closed #21 Incorrect MacBook detection logic in os_sleep_and_display_sleep_apple_silicon_enable check script on Apple Silicon 2026-01-19 18:28:57 +00:00

Closed #15 Screen Saver Password Enforce needs CIS lvl1 and lvl2 tag 2026-01-19 18:28:56 +00:00

Closed #16 Typo in os_sshd_fips_compliant.yaml fix code 2026-01-19 18:28:56 +00:00

Closed #18 Data quality issues. 2026-01-19 18:28:56 +00:00

Closed #8 Rule system_settings_softwareupdate_current ODV missing interval 2026-01-19 18:28:55 +00:00

Closed #9 audit_flags_fm_configure fix script no longer working 2026-01-19 18:28:55 +00:00

Closed #10 Granular MobileConfig Output 2026-01-19 18:28:55 +00:00

Closed #4 Redacted 2026-01-19 18:28:54 +00:00

Closed #6 Issue with generating pdf with generate_guidance script 2026-01-19 18:28:54 +00:00

333 Issues created by 1 user

Opened #2 pwpolicy_history_enforce set incorrectly for Tahoe CIS lvl1 2026-01-19 18:28:53 +00:00

Opened #3 Tailoring system_settings_screensaver_ask_for_password_delay_enforce $ODV=0 does not create a custom rule 2026-01-19 18:28:53 +00:00

Opened #1 system_settings_screensaver_timeout_enforce set incorrectly for Tahoe CIS lvl1 2026-01-19 18:28:53 +00:00

Opened #5 Dev_2.0 spot check on rules - noticed a few empty platforms: {} mappings 2026-01-19 18:28:54 +00:00

Opened #6 Issue with generating pdf with generate_guidance script 2026-01-19 18:28:54 +00:00

Opened #4 Redacted 2026-01-19 18:28:54 +00:00

Opened #12 Consolidated and granular .mobileconfig outputs 2026-01-19 18:28:55 +00:00

Opened #9 audit_flags_fm_configure fix script no longer working 2026-01-19 18:28:55 +00:00

Opened #10 Granular MobileConfig Output 2026-01-19 18:28:55 +00:00

Opened #8 Rule system_settings_softwareupdate_current ODV missing interval 2026-01-19 18:28:55 +00:00

Opened #11 os_anti_virus_installed errors: Tahoe 2026-01-19 18:28:55 +00:00

Opened #7 manual tag not removable by rule customization 2026-01-19 18:28:55 +00:00

Opened #15 Screen Saver Password Enforce needs CIS lvl1 and lvl2 tag 2026-01-19 18:28:56 +00:00

Opened #13 Generate remediation scripts rather than depend on check script 2026-01-19 18:28:56 +00:00

Opened #16 Typo in os_sshd_fips_compliant.yaml fix code 2026-01-19 18:28:56 +00:00

Opened #14 rules/os/os_root_disable does more than prevent root login- it breaks functionality (and isn't actually needed) 2026-01-19 18:28:56 +00:00

Opened #17 os_unlock_active_user_session_disable negatively impacts Platform SSO Accounts 2026-01-19 18:28:56 +00:00

Opened #18 Data quality issues. 2026-01-19 18:28:56 +00:00

Opened #24 Typo in os_implement_cryptography and os_required_crypto_module in macOS Tahoe 2026-01-19 18:28:57 +00:00

Opened #21 Incorrect MacBook detection logic in os_sleep_and_display_sleep_apple_silicon_enable check script on Apple Silicon 2026-01-19 18:28:57 +00:00

Opened #23 Typo for os_siri_assistant_disable 2026-01-19 18:28:57 +00:00

Opened #20 Enhanced Unification of Documentation and Scripting - Dev_2.0 2026-01-19 18:28:57 +00:00

Opened #22 Modifications to "authorizationdb" in 2.6.8 cause other commands to fail when run by root, sudo or by an mdm agent 2026-01-19 18:28:57 +00:00

Opened #19 system_settings_sleep_enforce rule has same detection limitations as os_sleep_and_display_sleep_apple_silicon_enable on Apple Silicon 2026-01-19 18:28:57 +00:00

Opened #25 Configure the default behavior of the check/remediate script when run from a MDM without flag support. 2026-01-19 18:28:58 +00:00

Opened #29 Password enforcement fails with allowPasscodeModification=false 2026-01-19 18:28:58 +00:00

Opened #27 Typo in os_notes_transcription_summary_disable rule on iOS_26 branch 2026-01-19 18:28:58 +00:00

Opened #26 system_settings_cd_dvd_sharing_disable rule missing from macOS 14 Sequoia and macOS 15 Sonoma 2026-01-19 18:28:58 +00:00

Opened #30 FileVault enforcement requires FileVault payload 2026-01-19 18:28:58 +00:00

Opened #28 pwpolicy_minimum_length_enforce fails when min length > ODV 2026-01-19 18:28:58 +00:00

Opened #31 Incorrect logic in system_settings_softwareupdate_current 2026-01-19 18:28:59 +00:00

Opened #32 Generate a consolidated configuration profile 2026-01-19 18:28:59 +00:00

Opened #33 Time Machine encryption check fails with space in mount point - system_settings_time_machine_encrypted_configure 2026-01-19 18:28:59 +00:00

Opened #37 launchctl list vs print-disabled 2026-01-19 18:29:00 +00:00

Opened #35 Add safariAllowJavaScript 2026-01-19 18:29:00 +00:00

Opened #38 Rule pwpolicy_account_inactivity_enforce can lock-out user account 2026-01-19 18:29:00 +00:00

Opened #39 os_authenticated_root_enable is need to supress the errors 2026-01-19 18:29:00 +00:00

Opened #34 Output of check using jq for two DDM rules fail to match 2026-01-19 18:29:00 +00:00

Opened #36 False failures with os_unlock_active_user_session_disable (Sequioa Branch) 2026-01-19 18:29:00 +00:00

Opened #42 Rule updates for Sequoia -- os_appleid_prompt_disable, os_icloud_storage_prompt_disable, and more... 2026-01-19 18:29:01 +00:00

Opened #44 Create Python SCP Library 2026-01-19 18:29:01 +00:00

Opened #45 Inconsistent Output with Guest User Directory Detection Script 2026-01-19 18:29:01 +00:00

Opened #40 CMMC Baselines (SSH set to both Disable and Enable) 2026-01-19 18:29:01 +00:00

Opened #41 SecureKeyboardEntry not working in Tahoe 2026-01-19 18:29:01 +00:00

Opened #43 system_settings_ssh_disable (Commands discrepancy) 2026-01-19 18:29:01 +00:00

Opened #46 Platform SSO and os_unlock_active_user_session_disable 2026-01-19 18:29:02 +00:00

Opened #48 MacOS 15 defintion for CCE-94310 "Configure Sudo To Log Events" calls the same testID twice 2026-01-19 18:29:02 +00:00

Opened #47 False negative with V-268546 - The macOS system must enforce multifactor authentication for privilege escalation through the sudo command. 2026-01-19 18:29:02 +00:00

Opened #54 generate_scap.py is not functioning as expected 2026-01-19 18:29:03 +00:00

Opened #51 Request for Script or Function to Rollback Executed Commands 2026-01-19 18:29:03 +00:00

Opened #49 User Preferences Revert to Defaults Following Reboot 2026-01-19 18:29:03 +00:00

Opened #52 Migration from MSCP 1 to MSCP 2.0 2026-01-19 18:29:03 +00:00

Opened #53 com.apple.mail.managed 2026-01-19 18:29:03 +00:00

Opened #50 Generate findings report in XLS and PDF format 2026-01-19 18:29:03 +00:00

Opened #56 system_settings_siri_listen_disable not working as intended 2026-01-19 18:29:04 +00:00

Opened #55 macOS Major version specific Audit preference file domains 2026-01-19 18:29:04 +00:00

Opened #57 Multiple issues with pwpolicy_ on Sequoia (Using Jamf Connect with EntraID as the OIDC Provider) 2026-01-19 18:29:04 +00:00

Opened #58 openSSH 9.8 - SC-05 2026-01-19 18:29:05 +00:00

Opened #59 CIS1 Password length incorrect 2026-01-19 18:29:05 +00:00

Opened #60 Compliance Count CIS lvl2 2026-01-19 18:29:05 +00:00

Opened #63 15.3/18.3 and 15.4/18.4 keys to add 2026-01-19 18:29:06 +00:00

Opened #66 Fix pwpolicy_upper_case_character_enforce.yaml 2026-01-19 18:29:06 +00:00

Opened #61 forelliN 2026-01-19 18:29:06 +00:00

Opened #65 ScreenSaver 2026-01-19 18:29:06 +00:00

Opened #62 Create a 2.x release of mSCP 2026-01-19 18:29:06 +00:00

Opened #64 Generate Guidance does not fill out Severity Column in xlsx spreadsheet 2026-01-19 18:29:06 +00:00

Opened #68 Running compliance script generated by Jamf Compliance Editor in terminal and the GUI "Audit Run" results differ. (CISL1) 2026-01-19 18:29:07 +00:00

Opened #69 os_install_log_retention_configure - TTL will be removed after update 2026-01-19 18:29:07 +00:00

Opened #67 os_sshd_fips_compliant remediation does not gracefully handle previous similar configuration settings 2026-01-19 18:29:07 +00:00

Opened #75 os_world_writable_library_folder_configure.yaml blocked by SIP? 2026-01-19 18:29:08 +00:00

Opened #72 "check" script in system_settings_screensaver_ask_for_password_delay_enforce.yaml throws a syntax error 2026-01-19 18:29:08 +00:00

Opened #70 pwpolicy_special_character_enforce: enforce more than 1 special character. 2026-01-19 18:29:08 +00:00

Opened #71 STIG tag missing from system_settings_improve_assistive_voice_disable.yaml 2026-01-19 18:29:08 +00:00

Opened #74 fix for os_ssh_server_alive_interval_configure.yaml is not successful 2026-01-19 18:29:08 +00:00

Opened #73 Add Apple Intelligence Controls 2026-01-19 18:29:08 +00:00

Opened #78 system_settings_improve_assistive_voice_disable.yaml mis-identified CIS control number 2026-01-19 18:29:09 +00:00

Opened #76 system_settings_software_update_enforce.yaml has been silently deprecated by Apple 2026-01-19 18:29:09 +00:00

Opened #77 system_settings_improve_search_disable.yaml mis-identified as a CIS Level 1 control 2026-01-19 18:29:09 +00:00

Opened #80 New privacy switches in macOS 15 are not managed by allowDiagnosticSubmission 2026-01-19 18:29:10 +00:00

Opened #84 Enforce TouchID for password autofill 2026-01-19 18:29:10 +00:00

Opened #82 $ODV value not replaced correctly in nested dict 2026-01-19 18:29:10 +00:00

Opened #83 system_settings_wake_network_access_disable resets on check 2026-01-19 18:29:10 +00:00

Opened #79 remove system_settings_cd_dvd_sharing_disable 2026-01-19 18:29:10 +00:00

Opened #81 Consider adding the newsyslog.d directory to the newsyslog rules 2026-01-19 18:29:10 +00:00

Opened #88 Scripts fail if yaml file has .yml extension 2026-01-19 18:29:11 +00:00

Opened #85 system_settings_system_wide_preferences_configure.yaml is missing full path to security binary 2026-01-19 18:29:11 +00:00

Opened #87 system_settings_wake_network_access_disable failed in VM devices 2026-01-19 18:29:11 +00:00

Opened #86 system_settings_loginwindow_loginwindowtext_enable appear in the configuration profile when not selected 2026-01-19 18:29:11 +00:00

Opened #92 Undefined reference to 'parser' in main() of generate_baseline.py 2026-01-19 18:29:12 +00:00

Opened #93 SyntaxWarning: invalid escape sequence '\|' 2026-01-19 18:29:12 +00:00

Opened #91 Store lastComplianceCheck date string as a regularised value 2026-01-19 18:29:12 +00:00

Opened #90 Add basic usage instructions 2026-01-19 18:29:12 +00:00

Opened #89 system_settings_siri_listen_disable result check incorrect 2026-01-19 18:29:12 +00:00

Opened #98 pwpolicy_force_pin_enable 2026-01-19 18:29:13 +00:00

Opened #96 Changing time server value is not respected, always, in the remediation section 2026-01-19 18:29:13 +00:00

Opened #95 DISA STIG - Text Updates 2026-01-19 18:29:13 +00:00

Opened #94 Asciidoctor 2.0.23 breaks html and pdf output 2026-01-19 18:29:13 +00:00

Opened #97 authorizationdb rules 2026-01-19 18:29:13 +00:00

Opened #99 Feature Proposal: Generate guidance in Markdown format 2026-01-19 18:29:13 +00:00

Opened #104 Add --no-rcs to compliance script 2026-01-19 18:29:14 +00:00

Opened #101 system_settings_system_wide_preferences_configure 2026-01-19 18:29:14 +00:00

Opened #102 Add SFR references to iOS documents 2026-01-19 18:29:14 +00:00

Opened #103 os_world_writable_system_folder_configure borken since Sonoma 14.4 2026-01-19 18:29:14 +00:00

Opened #105 Set ODV values (and perhaps other things like excluded rules) non-interactively 2026-01-19 18:29:14 +00:00

Opened #100 generate_guidance fails when using all_rules on the Sonoma branch 2026-01-19 18:29:14 +00:00

Opened #107 kickstart references in benchmarks 2026-01-19 18:29:15 +00:00

Opened #108 Update PDF & HTML based on platform 2026-01-19 18:29:15 +00:00

Opened #106 pwpolicy_account_lockout_enforce not presenting expected result in Log 2026-01-19 18:29:15 +00:00

Opened #114 SyntaxWarning for python string \| with sufficiently new python version 2026-01-19 18:29:16 +00:00

Opened #112 STIG guidance leads to inconsistent failed password account locking time 2026-01-19 18:29:16 +00:00

Opened #109 unable to generate tailored baseline 2026-01-19 18:29:16 +00:00

Opened #113 DISA customer pointed out potential issue with regex in pwpolicy_custom_regex_enforce 2026-01-19 18:29:16 +00:00

Opened #110 os_setup_assistant_filevault_enforce checks for wrong type 2026-01-19 18:29:16 +00:00

Opened #111 Retain previous finding if check fails 2026-01-19 18:29:16 +00:00

Opened #117 os_world_writable_system_folder_configure new restricted folder 2026-01-19 18:29:17 +00:00

Opened #115 Rules are tagged with 'stig' that do not have STIG References 2026-01-19 18:29:17 +00:00

Opened #116 pwpolicy_custom_regex_enforce fix statement and note 2026-01-19 18:29:17 +00:00

Opened #120 os_asl_log_files_*_configure are completely broken 2026-01-19 18:29:18 +00:00

Opened #123 os_root_disable alternative implementation 2026-01-19 18:29:18 +00:00

Opened #119 os_newsyslog_files_*_configure don't take /etc/newsyslog.d into account 2026-01-19 18:29:18 +00:00

Opened #121 SIP protected services 2026-01-19 18:29:18 +00:00

Opened #118 generate_baseline.py invalid escape sequence 2026-01-19 18:29:18 +00:00

Opened #122 system_settings_remote_management_disable avoid undocumented mdmclient 2026-01-19 18:29:18 +00:00

Opened #124 Rule: os_password_hint_remove reports wrong for Guest account in the as-is audit script 2026-01-19 18:29:19 +00:00

Opened #125 os_unlock_active_user_session_disable should be an ODV 2026-01-19 18:29:19 +00:00

Opened #126 Rules having both the fix and the profile 2026-01-19 18:29:19 +00:00

Opened #129 Prohibit execution from /tmp 2026-01-19 18:29:20 +00:00

Opened #132 safariAllowPopups doesn't work in Sonoma (and possibly earlier versions) 2026-01-19 18:29:20 +00:00

Opened #128 os_hibernate_mode_apple_silicon_enable checking is broken 2026-01-19 18:29:20 +00:00

Opened #131 Add requirement to review exemptions to smart card login. 2026-01-19 18:29:20 +00:00

Opened #127 os_mail_app_disable results in annoying popups after every login 2026-01-19 18:29:20 +00:00

Opened #130 Tailored by is missing in PDF output 2026-01-19 18:29:20 +00:00

Opened #138 build/cis_lvl1/cis_lvl1_compliance.sh: line 6359: syntax error near unexpected token `fi' 2026-01-19 18:29:21 +00:00

Opened #133 Different payload type for system_settings_screensaver_timeout_enforce 2026-01-19 18:29:21 +00:00

Opened #137 Add baseline tags to supplemental rules 2026-01-19 18:29:21 +00:00

Opened #134 system_settings_apple_watch_unlock_disable & system_settings_touchid_unlock_disable should not be mapped to AC-11 2026-01-19 18:29:21 +00:00

Opened #136 Bug: syslog daemon changes break its usage on macOS 10.13 and above 2026-01-19 18:29:21 +00:00

Opened #135 Remove multiple NTP servers from system_settings_time_server_configure.yaml 2026-01-19 18:29:21 +00:00

Opened #141 os_gatekeeper_enable - Sonoma - Misconfiguration 2026-01-19 18:29:22 +00:00

Opened #140 iCloud privacy relay disable not working 2026-01-19 18:29:22 +00:00

Opened #143 feat: support syspolicy_check a new feature in Sonoma to determine if the provided macOS application will pass the current running configurations’ system policy. 2026-01-19 18:29:22 +00:00

Opened #139 Space missing in $CURRENT_USER code in adoc files 2026-01-19 18:29:22 +00:00

Opened #142 os_recovery_lock_enable should not have a manual tag 2026-01-19 18:29:22 +00:00

Opened #146 Suppress Script Output Option 2026-01-19 18:29:23 +00:00

Opened #144 Configuration Profile Generation 2026-01-19 18:29:23 +00:00

Opened #147 pwpolicy_account_lockout_enforce issues with Sonoma 2026-01-19 18:29:23 +00:00

Opened #145 os_safari_javascript_enabled not detected properly 2026-01-19 18:29:23 +00:00

Opened #149 os_sshd_unused_connection_timeout_configure for dev_sonoma typo error 2026-01-19 18:29:24 +00:00

Opened #150 icloud_appleid_system_settings_disable (dev_sonoma) refers to deprecated domain 2026-01-19 18:29:24 +00:00

Opened #148 Configuration Profile -locationmenu not working 2026-01-19 18:29:24 +00:00

Opened #152 audit_flags_fm_configure fails in dev_sonoma because of the ^fm 2026-01-19 18:29:25 +00:00

Opened #151 audit_retention_configure fails to edit the /etc/security/audit_control file 2026-01-19 18:29:25 +00:00

Opened #153 os_anti_virus_installed errors: Load Failed 5 (Sonoma) 2026-01-19 18:29:25 +00:00

Opened #154 os_install_log_retention_configure - remediation does not match check 2026-01-19 18:29:26 +00:00

Opened #158 Monterey 800-171 .GlobalPreferences settings mobile config not importing into JAMF 2026-01-19 18:29:26 +00:00

Opened #159 submit profiles by CIS section vs functionality section 2026-01-19 18:29:26 +00:00

Opened #157 Generate recommendations Python script relies on very out of date Ruby gems 2026-01-19 18:29:26 +00:00

Opened #156 Wiki Compliance Script typo 2026-01-19 18:29:26 +00:00

Opened #155 CIS Lvl 1 6.1.1 failing false positives 2026-01-19 18:29:26 +00:00

Opened #160 Compliance percentage incorrect when exempted rules pass #267 “best practice!!! 2026-01-19 18:29:27 +00:00

Opened #162 CIS Manual Recommendations not generating properly 2026-01-19 18:29:27 +00:00

Opened #161 Indicate manual rules that are included in the baseline 2026-01-19 18:29:27 +00:00

Opened #166 Remediations on audit_control cause chaos if file is missing 2026-01-19 18:29:28 +00:00

Opened #168 Fraudulent typo 2026-01-19 18:29:28 +00:00

Opened #165 com.apple.locationmenu missing from supported_payloads 2026-01-19 18:29:28 +00:00

Opened #164 Sonoma - sshd config updates 2026-01-19 18:29:28 +00:00

Opened #167 Application Layer Firewall new check required 2026-01-19 18:29:28 +00:00

Opened #163 Computers that fail os_time_offset_limit_configure 2026-01-19 18:29:28 +00:00

Opened #171 firmware password requirement not applicable to Apple silicon according to STIG 2026-01-19 18:29:29 +00:00

Opened #169 os_anti_virus_installed rule 2026-01-19 18:29:29 +00:00

Opened #170 Compliance percentage incorrect when exempted rules pass 2026-01-19 18:29:29 +00:00

Opened #172 os_policy_banner_ssh_configure fails on Ventura even after remediation 2026-01-19 18:29:30 +00:00

Opened #173 Ventura firewall mobileconfig fails to install 2026-01-19 18:29:30 +00:00

Opened #174 compliance script should be able to say which rules fail 2026-01-19 18:29:30 +00:00

Opened #176 clientalivecountmax and clientaliveinterval 2026-01-19 18:29:30 +00:00

Opened #177 sshd banner check and fix 2026-01-19 18:29:30 +00:00

Opened #175 Rule 7.7 Secure User's Home Folder is not reporting correctly 2026-01-19 18:29:30 +00:00

Opened #182 sshd checks sometimes fail for reasons other than the rule 2026-01-19 18:29:31 +00:00

Opened #179 Provide indication of whether each Guideline corresponds to Apple's default setting 2026-01-19 18:29:31 +00:00

Opened #180 Asciidoctor-pdf 2.3.6 [undefined method `absolute_path?' for File:Class] error 2026-01-19 18:29:31 +00:00

Opened #181 generate_scap crash 2026-01-19 18:29:31 +00:00

Opened #178 Using "heredoc" Breaks Commands 2026-01-19 18:29:31 +00:00

Opened #183 Checks adding to /etc/sudoers.d directory fail on fresh 13.3 installs 2026-01-19 18:29:32 +00:00

Opened #189 Add command to remove uchg flag from /etc/security/audit_control 2026-01-19 18:29:34 +00:00

Opened #185 forceInternetSharingOff is failing check, but the key is set in com.apple.MCX 2026-01-19 18:29:34 +00:00

Opened #186 os_anti_virus_installed returns unexpected result ('integer': 3) 2026-01-19 18:29:34 +00:00

Opened #187 os_secure_boot_verify - bputil 2026-01-19 18:29:34 +00:00

Opened #184 Script should explicitly set LANG=C to avoid problems with localized output 2026-01-19 18:29:34 +00:00

Opened #188 Scutil is referenced without full path 2026-01-19 18:29:34 +00:00

Opened #190 Create a script who doesn't need answer to fix non compliant settings 2026-01-19 18:29:35 +00:00

Opened #192 Set rules with pathBlackList to deprecated 2026-01-19 18:29:35 +00:00

Opened #191 Add Safari rules for Monterey (CIS) 2026-01-19 18:29:35 +00:00

Opened #195 Tweak SSH rules for FIPS 186-5 addition of curve25519-sha256 2026-01-19 18:29:36 +00:00

Opened #197 where is the page that describes how to install these ? 2026-01-19 18:29:36 +00:00

Opened #193 checking for authenticated-root hangs forever when multiple OSes are available 2026-01-19 18:29:36 +00:00

Opened #196 handful of settings aren't "fixed" by compliance script 2026-01-19 18:29:36 +00:00

Opened #194 JAMF integration? 2026-01-19 18:29:36 +00:00

Opened #200 Include check that FileVault cannot be disabled in system_settings_filevault_enforce or create new rule to check 2026-01-19 18:29:37 +00:00

Opened #199 os_hibernate_mode_enable: Standby setting for Apple silicon is incorrect 2026-01-19 18:29:37 +00:00

Opened #198 USB Restricted Mode 2026-01-19 18:29:37 +00:00

Opened #201 system_settings_time_machine_encrypted_configure.yaml incorrect tag for CIS 2026-01-19 18:29:37 +00:00

Opened #203 DisableGuestAccount/EnableGuestAccount key 2026-01-19 18:29:38 +00:00

Opened #204 Rogue Highlighter 4.0.0 is not compatible with built-in Ruby 2026-01-19 18:29:38 +00:00

Opened #207 How to run macOS security compliance script on multiple mac devices using workspaceone MDM 2026-01-19 18:29:38 +00:00

Opened #206 Consider creating a rule that turns off Xcode Ads for Xcode Cloud 2026-01-19 18:29:38 +00:00

Opened #202 generate_baseline.py crash with custom baselines 2026-01-19 18:29:38 +00:00

Opened #205 os_sshd_permit_root_login_configure remediation code appends "permitrootlogin no" 2026-01-19 18:29:38 +00:00

Opened #210 Generated compliance script debug mode 2026-01-19 18:29:39 +00:00

Opened #208 os_install_log_retention_configure 2026-01-19 18:29:39 +00:00

Opened #209 os_hibernate_mode_enable Missing hibernatemode (and spelling error) 2026-01-19 18:29:39 +00:00

Opened #212 os_sshd_fips_compliant remediate issue 2026-01-19 18:29:40 +00:00

Opened #216 auth_ssh_password_authentication_disable needs to be updated for Ventura 2026-01-19 18:29:40 +00:00

Opened #211 os_sshd_key_exchange_algorithm_configure detection issue 2026-01-19 18:29:40 +00:00

Opened #213 system_settings_ssh_enable check 2026-01-19 18:29:40 +00:00

Opened #214 system_settings_system_wide_preferences_configure for loop syntax 2026-01-19 18:29:40 +00:00

Opened #215 JCE CIS Level 1 Rules are showing 2.9.3 (Level 2) 2026-01-19 18:29:40 +00:00

Opened #217 os_sshd_permit_root_login_configure code fails to run the validation script 2026-01-19 18:29:41 +00:00

Opened #218 icloud_appleid_system_settings_disable checking script seems to be returning inconsistent data 2026-01-19 18:29:41 +00:00

Opened #219 Rules missing 800-53 references 2026-01-19 18:29:41 +00:00

Opened #221 Profiles with multiple disabled Pref Panes keys not detected 2026-01-19 18:29:42 +00:00

Opened #220 Fix CIS mappings from new draft 2026-01-19 18:29:42 +00:00

Opened #222 Big Sur Compliance Script Error 2026-01-19 18:29:42 +00:00

Opened #223 ODV - Parent value not being applied properly 2026-01-19 18:29:42 +00:00

Opened #226 Generate_baseline -t crash 2026-01-19 18:29:43 +00:00

Opened #225 Modify sysprefs_siri_disable to use "com.apple.assistant.support" instead of "com.apple.ironwood.support" 2026-01-19 18:29:43 +00:00

Opened #224 sysprefs_system_wide_preferences_configure shared key doesn't exist on some systems 2026-01-19 18:29:43 +00:00

Opened #228 Format problem in remediation of a number of 'os' section rules 2026-01-19 18:29:44 +00:00

Opened #229 sysprefs_screensaver_ask_for_password_delay_enforce not remediated 2026-01-19 18:29:44 +00:00

Opened #230 Ummm, HOWTO 2026-01-19 18:29:44 +00:00

Opened #227 Disabled launchctl reports incorrectly (Ventura) 2026-01-19 18:29:44 +00:00

Opened #231 os_hibernate_mode_enable: remediation is not effective 2026-01-19 18:29:44 +00:00

Opened #234 Update sshd Checks 2026-01-19 18:29:45 +00:00

Opened #233 rules/os/os_library_validation_enabled.yaml fails with: "run_fix:242: command not found: This" 2026-01-19 18:29:45 +00:00

Opened #232 sysprefs_software_update_app_update_enforce 2026-01-19 18:29:45 +00:00

Opened #235 os_recovery_lock_enable has incorrect key 2026-01-19 18:29:45 +00:00

Opened #236 Make Configuration Profile Display Names specific to payload 2026-01-19 18:29:45 +00:00

Opened #237 Add an option to view a description of rules when creating a tailored baseline 2026-01-19 18:29:45 +00:00

Opened #240 pwpolicy_account_lockout_enforce should check if value is less than or equal 2026-01-19 18:29:46 +00:00

Opened #241 Stats Reporting Incorrect 2026-01-19 18:29:46 +00:00

Opened #239 Remove requirement for admin prompt when install ruby gems 2026-01-19 18:29:46 +00:00

Opened #238 os_software_update_deferral gives fails finding if 'enforcedSoftwareUpdateDelay' key is not set 2026-01-19 18:29:46 +00:00

Opened #243 Removing a rule from guidance will not remove the rule from audit file 2026-01-19 18:29:47 +00:00

Opened #245 Test screensaver timeout 2026-01-19 18:29:47 +00:00

Opened #242 audit_retention_configure_sixty_days remediation not getting picked up by Jamf Protect insights 2026-01-19 18:29:47 +00:00

Opened #244 Test Rule 2 2026-01-19 18:29:47 +00:00

Opened #246 TOC not being generated when asciidoctor-pdf 2.0.x is installed 2026-01-19 18:29:47 +00:00

Opened #247 Modify the arg checking to suit Jamf Pro policies 2026-01-19 18:29:48 +00:00

Opened #251 Add an "id:" tag to the baseline .yaml files for easier distinction between baselines versus using the "title:" tag 2026-01-19 18:29:48 +00:00

Opened #250 remediation for os_policy_banner_loginwindow_enforce creates a wrongly named directory 2026-01-19 18:29:48 +00:00

Opened #249 missing EOS in some rules 2026-01-19 18:29:48 +00:00

Opened #248 os_sudoers_tty_configure.yaml check and fix don't work 2026-01-19 18:29:48 +00:00

Opened #252 Duplicate security controls and missing reference values in 2026-01-19 18:29:48 +00:00

Opened #253 mismatched test and mobileconfig for Monterey os_burn_support_disable 2026-01-19 18:29:49 +00:00

Opened #255 Disable Siri prefpane 2026-01-19 18:29:49 +00:00

Opened #254 mismatched test and remediate for Monterey os_blank_bluray_disable.yaml 2026-01-19 18:29:49 +00:00

Opened #256 (dev_monterey) os_install_log_retention_policy and audit_flags_configure not remediating 2026-01-19 18:29:50 +00:00

Opened #257 time server enforcement values possibly deprecated. 2026-01-19 18:29:50 +00:00

Opened #258 os_sudo_timeout_configure adjust check for possible spaces 2026-01-19 18:29:50 +00:00

Opened #263 sysprefs_wifi_disable.yaml ignored for STIG compliance 2026-01-19 18:29:51 +00:00

Opened #260 ChallengeResponseAuthentication not present in macOS Monterey 2026-01-19 18:29:51 +00:00

Opened #259 STIG Big_Sure os_ESS_installed 2026-01-19 18:29:51 +00:00

Opened #261 JXA Checks are causing the generated baseline_compliance.sh to break 2026-01-19 18:29:51 +00:00

Opened #264 Compliance script run with --fix does not apply fixes unless --check was run first 2026-01-19 18:29:51 +00:00

Opened #262 baseline compliance script output to Unified Logging 2026-01-19 18:29:51 +00:00

Opened #267 Sudoers authenticate on per -tty basis 2026-01-19 18:29:52 +00:00

Opened #265 Mobileconfig profiles do not honor compliance script exemptions 2026-01-19 18:29:52 +00:00

Opened #266 Firmware password check does not work on Apple Silicon-based machines. 2026-01-19 18:29:52 +00:00

Opened #273 setting pwpolicy_file 2026-01-19 18:29:53 +00:00

Opened #269 Directory services integration test returns multiple values 2026-01-19 18:29:53 +00:00

Opened #270 Add sections for project and local site authors to custom baselines 2026-01-19 18:29:53 +00:00

Opened #272 Errors generating CIS compliance profiles 2026-01-19 18:29:53 +00:00

Opened #271 Tag and Compliance Script check for Intel vs Apple Silicon 2026-01-19 18:29:53 +00:00

Opened #268 14.3. Password Policy Supplemental duplicate entry? 2026-01-19 18:29:53 +00:00

Opened #274 ASOX is not a normal STIG ID 2026-01-19 18:29:54 +00:00

Opened #279 custom rule that sets mobileconfig: false still ends up creating a .mobileprofile file 2026-01-19 18:29:54 +00:00

Opened #277 big_sur branch has two rules that claim to be APPL-11-000001 2026-01-19 18:29:54 +00:00

Opened #278 git clone is broken 2026-01-19 18:29:54 +00:00

Opened #275 mismatch between STIG rules and current version for big_sur branch 2026-01-19 18:29:54 +00:00

Opened #276 compliance_count function in generated guidance script does not correctly count findings 2026-01-19 18:29:54 +00:00

Opened #280 Prevent fixes when not needed 2026-01-19 18:29:55 +00:00

Opened #281 auth_ssh_smartcard_enforce rename 2026-01-19 18:29:55 +00:00

Opened #282 audit_control policy cnt vs ahlt 2026-01-19 18:29:55 +00:00

Opened #288 audit_flags_fm_configure 2026-01-19 18:29:56 +00:00

Opened #287 os_airdrop_disable check and remediation are inconsistent 2026-01-19 18:29:56 +00:00

Opened #285 Rule - os_filevault_user_account - Change needed for Apple silicon 2026-01-19 18:29:56 +00:00

Opened #284 Rule - os_facetime_app_disable.yaml - STIG ID is listed as ASOX-14-002010. It should be APPL-11-002010 2026-01-19 18:29:56 +00:00

Opened #286 os_guest_access_smb_disable 2026-01-19 18:29:56 +00:00

Opened #283 Add "all_rules" to generate_baseline.py -l 2026-01-19 18:29:56 +00:00

Opened #294 Missing result for this test 2026-01-19 18:29:57 +00:00

Opened #293 Fix audit_files_(group/mode/owner)_configure 2026-01-19 18:29:57 +00:00

Opened #290 os_sshd_key_exchange_algorithm_configure.yaml does not have a fallback to adding the relevant line 2026-01-19 18:29:57 +00:00

Opened #292 Use domain-specific naming in 'PayloadDisplayName' key of configuration profiles 2026-01-19 18:29:57 +00:00

Opened #291 mobileconfig creation ignores exempt preferences settings 2026-01-19 18:29:57 +00:00

Opened #289 Creation of the Excel doc with Custom references, adds extra rows while the name is the same 2026-01-19 18:29:57 +00:00

Opened #296 fixtext commands are broken; have newline chars instead of spaces 2026-01-19 18:29:58 +00:00

Opened #297 Definition of exemption 2026-01-19 18:29:58 +00:00

Opened #295 add (sub)subtitles for the documentation. 2026-01-19 18:29:58 +00:00

Opened #300 CJIS Baseline 2026-01-19 18:29:59 +00:00

Opened #303 Fix language in os_certificate_authority_trust 2026-01-19 18:29:59 +00:00

Opened #301 os_mdm_require.yaml needs to be updated for macOS 11 2026-01-19 18:29:59 +00:00

Opened #302 Re-Map os_guest_account_disable 2026-01-19 18:29:59 +00:00

Opened #299 Cleanup references 2026-01-19 18:29:59 +00:00

Opened #298 metadata subsection to track changes in customized rules 2026-01-19 18:29:59 +00:00

Opened #309 Check for Library Validation 2026-01-19 18:30:00 +00:00

Opened #304 custom reference data should be displayed in generated documents and spreadsheet 2026-01-19 18:30:00 +00:00

Opened #306 audit_events Sandbox violations 2026-01-19 18:30:00 +00:00

Opened #305 cross reference for how rules are implemented in a tool 2026-01-19 18:30:00 +00:00

Opened #307 Check for Apple Mobile File Integrity 2026-01-19 18:30:00 +00:00

Opened #308 Option to generate plists for custom configuration profiles 2026-01-19 18:30:00 +00:00

Opened #310 Option to sign generated profiles please! 2026-01-19 18:30:01 +00:00

Opened #312 Add a default value / Arg to generate_script 2026-01-19 18:30:01 +00:00

Opened #311 Generate Guidance script - excel export 2026-01-19 18:30:01 +00:00

Opened #317 Consider adding a GLBA baseline 2026-01-19 18:30:02 +00:00

Opened #314 Concurrent session limit for SSH is not working 2026-01-19 18:30:02 +00:00

Opened #316 os_camera_disable 2026-01-19 18:30:02 +00:00

Opened #313 sysprefs_find_my_disable 2026-01-19 18:30:02 +00:00

Opened #315 os_siri_prompt_disable 2026-01-19 18:30:02 +00:00

Opened #318 sysprefs_diagnostics_reports_disable 2026-01-19 18:30:02 +00:00

Opened #320 Overwriting baseline files 2026-01-19 18:30:03 +00:00

Opened #319 profile_generator.py doesn't work unless you change directory to the "scripts" directory first 2026-01-19 18:30:03 +00:00

Opened #321 rules listed in the wrong section in baselines 2026-01-19 18:30:03 +00:00

Opened #323 Filename tweak 2026-01-19 18:30:03 +00:00

Opened #324 Additional rule Disable Improve Siri & Dictation 2026-01-19 18:30:03 +00:00

Opened #322 Missing full paths 2026-01-19 18:30:03 +00:00

Opened #325 Setting for TimeServer 2026-01-19 18:30:04 +00:00

Opened #326 sysprefs_ad_tracking_disable check 2026-01-19 18:30:04 +00:00

Opened #327 Suggest mapping to the ACSC ISM 2026-01-19 18:30:04 +00:00

Opened #332 Baselines path incorrect in Wiki documentation 2026-01-19 18:30:05 +00:00

Opened #333 Baseline names should be more descriptive. 2026-01-19 18:30:05 +00:00

Opened #331 Consider adding an 800-171 baseline 2026-01-19 18:30:05 +00:00

Opened #329 profile_generator.py - All baselines use the same 'mobileconfigs' directory 2026-01-19 18:30:05 +00:00

Opened #328 Consider adding a mapping for Common Criteria GPOS 4.2.1 2026-01-19 18:30:05 +00:00

Opened #330 Suggest mapping to the NCSC CyberEssentials 2026-01-19 18:30:05 +00:00