mirror of
https://github.com/ansible-lockdown/RHEL9-CIS.git
synced 2025-12-24 22:23:06 +00:00
Merge pull request #390 from polski-g/modular_section_5_r2
Support section modularization (for Sec 5 only right now)
This commit is contained in:
commit
23b60bc629
2 changed files with 44 additions and 27 deletions
|
|
@ -18,11 +18,17 @@ rhel9cis_disruption_high: true
|
|||
# These variables govern whether the tasks of a particular section are to be executed when running the role.
|
||||
# E.g: If you want to execute the tasks of Section 1 you should set the "_section1" variable to true.
|
||||
# If you do not want the tasks from that section to get executed you simply set the variable to "false".
|
||||
# Some sections support sub-section modularization. The super-section and sub-section must both be true
|
||||
# for the sub-section to execute.
|
||||
rhel9cis_section1: true
|
||||
rhel9cis_section2: true
|
||||
rhel9cis_section3: true
|
||||
rhel9cis_section4: true
|
||||
rhel9cis_section5: true
|
||||
rhel9cis_section5_1: true
|
||||
rhel9cis_section5_2: true
|
||||
rhel9cis_section5_3: true
|
||||
rhel9cis_section5_4: true
|
||||
rhel9cis_section6: true
|
||||
rhel9cis_section7: true
|
||||
|
||||
|
|
|
|||
|
|
@ -5,13 +5,20 @@
|
|||
- name: "SECTION | 5.1 | Configure SSH Server"
|
||||
when:
|
||||
- "'openssh-server' in ansible_facts.packages"
|
||||
- rhel9cis_section5_1
|
||||
ansible.builtin.import_tasks:
|
||||
file: cis_5.1.x.yml
|
||||
|
||||
- name: "SECTION | 5.2 | Configure privilege escalation"
|
||||
when:
|
||||
- - rhel9cis_section5_2
|
||||
ansible.builtin.import_tasks:
|
||||
file: cis_5.2.x.yml
|
||||
|
||||
- name: "SECTION | 5.3"
|
||||
when:
|
||||
- rhel9cis_section5_3
|
||||
block:
|
||||
- name: "SECTION | 5.3.1.x | Configure PAM software packages"
|
||||
ansible.builtin.import_tasks:
|
||||
file: cis_5.3.1.x.yml
|
||||
|
|
@ -36,6 +43,10 @@
|
|||
ansible.builtin.import_tasks:
|
||||
file: cis_5.3.3.4.x.yml
|
||||
|
||||
- name: "SECTION | 5.4"
|
||||
when:
|
||||
- rhel9cis_section5_4
|
||||
block:
|
||||
- name: "SECTION | 5.4.1.x | Configure shadow password suite parameters"
|
||||
ansible.builtin.import_tasks:
|
||||
file: cis_5.4.1.x.yml
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue