[8.6] OpenSCAP anssi bp28 high broken -> No boot

Hello,

I am testing openscap profiles for almalinux and I found that if you directly remediate with anssi bp28 high profile, system does not boot. That happens both if you install with that profile selected or if you manually apply profile latter wish oscap xccdf eval --remediate

After reboot emergency console shows and there you can find that the problem is that /boot/efi could not be mounted.

#journalctl -xb 
systemd[1]: Failed to mount /boot/efi.

I do not have found were in the profile remediation vfat filesystem is forbbiden.

# modprobe -v vfat
insmod /lib/modules/4.18.0-372.19.1.el8_6.x86_64/kernel/fs/fat/fat.ko.xz
modprobe: ERROR: could not insert 'vfat': Operation not permitted

It is not blacklisted on modprobe.d files, checked /etc/modprobe.d [/usr]/lib/modprobe.d/
Secure boot is enabled. But I saw no difference disabling it.

Workarround could be to comment /boot/efi entry in /etc/fstab, but that only allows you to start, if grub/kernel packages needed to be upgraded there will not upgrade content of real /boot/efi (you could manually select new kernel on boot menu to start), so no long term solution.

Any thought will be welcomed.

Best Regards,

Diego

Hello,

Seems that is a selinux related configuration.
With SELINUX=permissive in /etc/selinux/config is it possible again to mount /boot/efi

Now I will look for the selinux rule that affects it.

Best Regards,

Diego