mirror of
https://github.com/ansible-lockdown/RHEL9-CIS.git
synced 2025-12-27 15:33:06 +00:00
Revert "Added vars for streams."
[IP] I see no benefit to duplicate vars in defaults/main.yml in other files like specific vars for Alma/Rocky, especially since
we're using the same values for those vars. Also, replacing rsyslog with journald is not fine for this current doc-extension proposal.
This reverts commit a57333dcf1.
This commit is contained in:
parent
f1dde22aaf
commit
0ed60c583f
3 changed files with 1 additions and 13 deletions
|
|
@ -886,7 +886,7 @@ rhel9cis_auditd_uid_exclude:
|
|||
# This variable governs which logging service should be used, choosing between 'rsyslog'(CIS recommendation)
|
||||
# or 'journald'(only one is implemented) will trigger the execution of the associated subsection, as the-best
|
||||
# practices are written wholly independent of each other.
|
||||
rhel9cis_syslog: journald
|
||||
rhel9cis_syslog: rsyslog
|
||||
## Control 4.2.1.5 | PATCH | Ensure logging is configured
|
||||
# This variable governs if current Ansible role should manage syslog settings
|
||||
# in /etc/rsyslog.conf file, namely mail, news and misc(warn, messages)
|
||||
|
|
|
|||
|
|
@ -5,9 +5,3 @@ os_gpg_key_pubkey_name: gpg-pubkey-b86b3716-61e69f29
|
|||
os_gpg_key_pubkey_content: "AlmaLinux OS 9 <packager@almalinux.org> b86b3716"
|
||||
# disable repo_gpgcheck due to OS default repos
|
||||
rhel9cis_rule_enable_repogpg: false
|
||||
|
||||
rhel9cis_sshd:
|
||||
# This variable sets the maximum number of unresponsive "keep-alive" messages
|
||||
# that can be sent from the server to the client before the connection is considered
|
||||
# inactive and thus, closed.
|
||||
clientalivecountmax: 3
|
||||
|
|
@ -3,9 +3,3 @@
|
|||
|
||||
os_gpg_key_pubkey_name: gpg-pubkey-350d275d-6279464b
|
||||
os_gpg_key_pubkey_content: "Rocky Enterprise Software Foundation - Release key 2022 <releng@rockylinux.org> 350d275d"
|
||||
|
||||
rhel9cis_sshd:
|
||||
# This variable sets the maximum number of unresponsive "keep-alive" messages
|
||||
# that can be sent from the server to the client before the connection is considered
|
||||
# inactive and thus, closed.
|
||||
clientalivecountmax: 3
|
||||
Loading…
Add table
Add a link
Reference in a new issue