diff --git a/handlers/main.yml b/handlers/main.yml index 212eacc..552d29f 100644 --- a/handlers/main.yml +++ b/handlers/main.yml @@ -13,7 +13,7 @@ sysctl_set: true ignore_errors: true # noqa ignore-errors when: - - flush_ipv4_route + - rhel9cis_flush_ipv4_route - not system_is_container - name: Sysctl flush ipv6 route table @@ -22,7 +22,7 @@ value: '1' sysctl_set: true when: - - flush_ipv6_route + - rhel9cis_flush_ipv6_route - not system_is_container - name: Systemd restart tmp.mount diff --git a/tasks/auditd.yml b/tasks/auditd.yml index 2a2eb9c..486ef31 100644 --- a/tasks/auditd.yml +++ b/tasks/auditd.yml @@ -3,7 +3,7 @@ - name: POST | AUDITD | Apply auditd template will for section 4.1.3 - only required rules will be added | stat file ansible.builtin.stat: path: /etc/audit/rules.d/99_auditd.rules - register: auditd_file + register: rhel9cis_auditd_file - name: POST | AUDITD | Apply auditd template will for section 4.1.3 - only required rules will be added | setup file ansible.builtin.template: @@ -12,8 +12,8 @@ owner: root group: root mode: 0640 - diff: "{{ auditd_file.stat.exists }}" # Only run diff if not a new file - register: auditd_template_updated + diff: "{{ rhel9cis_auditd_file.stat.exists }}" # Only run diff if not a new file + register: rhel9cis_auditd_template_updated notify: - Auditd immutable check - Audit immutable fact @@ -24,13 +24,13 @@ vars: warn_control_id: 'Auditd template updated, see diff output for details' when: - - auditd_template_updated.changed - - auditd_file.stat.exists + - rhel9cis_auditd_template_updated.changed + - rhel9cis_auditd_file.stat.exists - name: POST | AUDITD | Apply auditd template will for section 4.1.3 - only required rules will be added | stat file ansible.builtin.stat: path: /etc/audit/rules.d/98_auditd_exceptions.rules - register: auditd_exception_file + register: rhel9cis_auditd_exception_file - name: POST | Set up auditd user logging exceptions | setup file ansible.builtin.template: @@ -39,7 +39,7 @@ owner: root group: root mode: 0640 - diff: "{{ auditd_exception_file.stat.exists }}" + diff: "{{ rhel9cis_auditd_exception_file.stat.exists }}" notify: Restart auditd when: - rhel9cis_allow_auditd_uid_user_exclusions diff --git a/tasks/post.yml b/tasks/post.yml index 591cfda..8e8fea7 100644 --- a/tasks/post.yml +++ b/tasks/post.yml @@ -22,7 +22,7 @@ - 60-netipv4_sysctl.conf - 60-netipv6_sysctl.conf when: - - sysctl_update + - rhel9cis_sysctl_update - not system_is_container - "'procps-ng' in ansible_facts.packages"