CentOS 5.6 and PCI Compliance

Support for security such as Firewalls and securing linux
foxb
Posts: 1927
Joined: 2006/04/20 19:03:33
Location: Montreal/QC

Re: CentOS 5.6 and PCI Compliance

Post by foxb » 2011/08/08 15:07:24

[quote]
broberts wrote:
Thanks Phil, what you say makes sense and it is going to cause ongoing pain.

The main point of my original post was to see if other CentOS 5 users had some thoughts on addressing the problems I see. It sounds like CentOS 6 may help a reasonable amount as baseline version of apache is substantially newer, but maybe I should be looking at a distro that does things differently.[/quote]

I do pass PCI with CentOS 5 - that's blind reading of the requirements. Reality is a bit different... but as already quoted you need to contact TUV if you encounter problems or get a consultant to do preliminary scan. CentOS team cannot help you.

awilson
Posts: 1
Joined: 2011/12/12 16:07:12

Re: CentOS 5.6 and PCI Compliance

Post by awilson » 2011/12/12 16:14:59

While Red Hat does say they don't consider this a vulnerability, they do supply a patch:

http://www.redhat.com/security/data/cve/CVE-2007-6203.html

"However, this has been fixed in Red Hat Enterprise Linux 5 via RHBA-2009:0185 as a bug fix."


I am having the same problem as the original poster - PCI scan does not care if the vender doesn't view this a vulnerability. So my question is - is there a a reason that RHBA-2009:0185 can't be applied to a CENTOS box? If it can't, where is the documentation that says it can't?

User avatar
TrevorH
Site Admin
Posts: 33219
Joined: 2009/09/24 10:40:56
Location: Brighton, UK

Re: CentOS 5.6 and PCI Compliance

Post by TrevorH » 2011/12/12 16:50:16

The patch referenced in that bugzilla - httpd-2.0.52-escaperrs.patch - is included in the latest CentOS httpd source RPM so it appears that this was fixed a long time ago and there's no mention of it in the changelog.

Post Reply