mirror of
https://github.com/ansible-lockdown/RHEL9-CIS.git
synced 2026-03-25 22:37:11 +00:00
Merge branch 'devel' into pub_feb26_updates
Signed-off-by: uk-bolly <69214557+uk-bolly@users.noreply.github.com>
This commit is contained in:
commit
3015e2fe2f
5 changed files with 18 additions and 16 deletions
|
|
@ -93,10 +93,10 @@
|
|||
loop:
|
||||
- regexp: "auth\\s+required\\s+pam_faillock.so\\s+preauth"
|
||||
after: "auth\\s+required\\s+pam_env.so" # yamllint disable-line rule:colons
|
||||
line: "auth required pam_faillock.so preauth silent deny=3 unlock_timeout={{ rhel9cis_pam_faillock_unlock_time }}" # yamllint disable-line rule:colons
|
||||
line: "auth required pam_faillock.so preauth silent unlock_timeout={{ rhel9cis_pam_faillock_unlock_time }}" # yamllint disable-line rule:colons
|
||||
- regexp: "auth\\s+required\\s+pam_faillock.so\\s+authfail"
|
||||
before: "auth\\s+required\\s+pam_deny.so"
|
||||
line: "auth required pam_faillock.so authfail silent deny=3 unlock_timeout={{ rhel9cis_pam_faillock_unlock_time }}" # yamllint disable-line rule:colons
|
||||
line: "auth required pam_faillock.so authfail silent unlock_timeout={{ rhel9cis_pam_faillock_unlock_time }}" # yamllint disable-line rule:colons
|
||||
- regexp: "account\\s+required\\s+pam_faillock.so"
|
||||
before: "account\\s+required\\s+pam_unix.so"
|
||||
line: "account required pam_faillock.so" # yamllint disable-line rule:colons
|
||||
|
|
@ -112,10 +112,10 @@
|
|||
loop:
|
||||
- regexp: "auth\\s+required\\s+pam_faillock.so\\s+preauth"
|
||||
after: "auth\\s+required\\s+pam_env.so" # yamllint disable-line rule:colons
|
||||
line: "auth required pam_faillock.so preauth silent deny=3 unlock_timeout={{ rhel9cis_pam_faillock_unlock_time }}" # yamllint disable-line rule:colons
|
||||
line: "auth required pam_faillock.so preauth silent unlock_timeout={{ rhel9cis_pam_faillock_unlock_time }}" # yamllint disable-line rule:colons
|
||||
- regexp: "auth\\s+required\\s+pam_faillock.so\\s+authfail"
|
||||
before: "auth\\s+required\\s+pam_deny.so"
|
||||
line: "auth required pam_faillock.so authfail silent deny=3 unlock_timeout={{ rhel9cis_pam_faillock_unlock_time }}" # yamllint disable-line rule:colons
|
||||
line: "auth required pam_faillock.so authfail silent unlock_timeout={{ rhel9cis_pam_faillock_unlock_time }}" # yamllint disable-line rule:colons
|
||||
- regexp: "account\\s+required\\s+pam_faillock.so"
|
||||
before: "account\\s+required\\s+pam_unix.so"
|
||||
line: "account required pam_faillock.so" # yamllint disable-line rule:colons
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue