Skip to content

2025

Remediating RHEL-09-431016

I get a lot of questions about how to remediate RHEL-09-431016. People report issues like sudo or SSH no longer working afterwards. I was discussing this with my partner in crime, and we ultimately came to the conclusion that unless you really know the RHEL product or you were intimately familiar with the RHEL 7 STIG you would never know that there are a couple of missing links in the process for making RHEL-09-431016 work properly. We had to learn these things the hard way by watching test systems brick over the years, so keep in mind these are lessons we learned back with RHEL 7 and carried forward because not only would we have consistent baselines between generations, but we genuinely believed that the STIG would eventually catch up because these controls are necessary in the context of RHEL-09-431016. You'll see some of that reflected in the Ansible task naming included in this post where we carried forward two critical controls that enable RHEL-09-431016 to function without bricking the system.

Where did the time go?

I have been a busy bee. I started this little project in 2023, got busy, and then forgot about it. I originally started this blog on a hosted Wordpress site. I am not impressed with my former host. I am not particularly amused with the antics going around with Wordpress, nevermind that it's a nightmare to manage and maintain.

I finally got around to shutting down the old blog, turning off anything resembling an automatic renewal, and harvesting the content for re-publishing.