mirror of
https://github.com/ansible-lockdown/RHEL9-CIS.git
synced 2025-12-24 22:23:06 +00:00
Set boolean true/false
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
This commit is contained in:
parent
dfedc652cb
commit
5469adcf4b
2 changed files with 6 additions and 6 deletions
|
|
@ -3,7 +3,7 @@
|
||||||
|
|
||||||
- name: Perform DNF package cleanup
|
- name: Perform DNF package cleanup
|
||||||
dnf:
|
dnf:
|
||||||
autoremove: yes
|
autoremove: true
|
||||||
changed_when: no
|
changed_when: no
|
||||||
|
|
||||||
- name: trigger update sysctl
|
- name: trigger update sysctl
|
||||||
|
|
|
||||||
|
|
@ -16,7 +16,7 @@
|
||||||
- name: "4.2.1.2 | L1 | PATCH | Ensure rsyslog Service is enabled"
|
- name: "4.2.1.2 | L1 | PATCH | Ensure rsyslog Service is enabled"
|
||||||
service:
|
service:
|
||||||
name: rsyslog
|
name: rsyslog
|
||||||
enabled: yes
|
enabled: true
|
||||||
when:
|
when:
|
||||||
- rhel9cis_rule_4_2_1_2
|
- rhel9cis_rule_4_2_1_2
|
||||||
tags:
|
tags:
|
||||||
|
|
@ -46,10 +46,10 @@
|
||||||
shell: cat /etc/rsyslog.conf
|
shell: cat /etc/rsyslog.conf
|
||||||
args:
|
args:
|
||||||
warn: false
|
warn: false
|
||||||
become: yes
|
become: true
|
||||||
changed_when: false
|
changed_when: false
|
||||||
failed_when: no
|
failed_when: false
|
||||||
check_mode: no
|
check_mode: false
|
||||||
register: rhel_09_4_2_1_4_audit
|
register: rhel_09_4_2_1_4_audit
|
||||||
|
|
||||||
- name: "4.2.1.4 | L1 | AUDIT | Ensure logging is configured | rsyslog current config message out"
|
- name: "4.2.1.4 | L1 | AUDIT | Ensure logging is configured | rsyslog current config message out"
|
||||||
|
|
@ -157,7 +157,7 @@
|
||||||
with_items:
|
with_items:
|
||||||
- '^(\$ModLoad imtcp)'
|
- '^(\$ModLoad imtcp)'
|
||||||
- '^(\$InputTCPServerRun)'
|
- '^(\$InputTCPServerRun)'
|
||||||
when: not rhel9cis_system_is_log_server
|
when: falset rhel9cis_system_is_log_server
|
||||||
|
|
||||||
- name: "4.2.1.6 | L1 | PATCH | Ensure remote rsyslog messages are only accepted on designated log hosts. | When log host"
|
- name: "4.2.1.6 | L1 | PATCH | Ensure remote rsyslog messages are only accepted on designated log hosts. | When log host"
|
||||||
replace:
|
replace:
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue