mirror of
https://github.com/ansible-lockdown/RHEL9-CIS.git
synced 2025-12-24 14:23:05 +00:00
Removed multiple blank lines
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
This commit is contained in:
parent
312b460cfc
commit
5f7dd08838
12 changed files with 3 additions and 21 deletions
1
.github/workflows/main.tf
vendored
1
.github/workflows/main.tf
vendored
|
|
@ -5,7 +5,6 @@ provider "aws" {
|
|||
|
||||
// Create a security group with access to port 22 and port 80 open to serve HTTP traffic
|
||||
|
||||
|
||||
resource "random_id" "server" {
|
||||
keepers = {
|
||||
# Generate a new id each time we switch to a new AMI id
|
||||
|
|
|
|||
|
|
@ -3,8 +3,8 @@ extends: default
|
|||
|
||||
ignore: |
|
||||
tests/
|
||||
molecule/
|
||||
.github/
|
||||
molecule
|
||||
.github
|
||||
.gitlab-ci.yml
|
||||
*molecule.yml
|
||||
|
||||
|
|
|
|||
|
|
@ -61,7 +61,6 @@ following text in your contribution commit message:
|
|||
|
||||
::
|
||||
|
||||
|
||||
This message can be entered manually, or if you have configured git
|
||||
with the correct `user.name` and `user.email`, you can use the `-s`
|
||||
option to `git commit` to automatically include the signoff message.
|
||||
|
|
|
|||
3
Makefile
3
Makefile
|
|
@ -1,6 +1,5 @@
|
|||
.PHONY: all help galaxy-install ansible-list yamllint pip-requirements
|
||||
|
||||
|
||||
GALAXY=ansible-galaxy
|
||||
ANSIBLE_LINT='/usr/local/bin/ansible-lint'
|
||||
ANSIBLE_FILE=site.yml
|
||||
|
|
@ -15,7 +14,6 @@ help:
|
|||
@echo " yamllint to lint playbook files"
|
||||
@echo " pip-requirements add pip required file"
|
||||
|
||||
|
||||
galaxy-install:
|
||||
$(GALAXY) install -r ./collections/requirements.yml
|
||||
|
||||
|
|
@ -29,4 +27,3 @@ pip-requirements:
|
|||
@echo 'Python dependencies:'
|
||||
@cat requirements.txt
|
||||
pip3 install -r requirements.txt
|
||||
|
||||
|
|
|
|||
|
|
@ -12,7 +12,6 @@ stdout_callback = yaml
|
|||
# Use the stdout_callback when running ad-hoc commands.
|
||||
bin_ansible_callbacks = True
|
||||
|
||||
|
||||
[privilege_escalation]
|
||||
|
||||
[paramiko_connection]
|
||||
|
|
|
|||
|
|
@ -15,4 +15,3 @@
|
|||
- name: "Include tasks"
|
||||
ansible.builtin.include_role:
|
||||
name: "{{ role_name }}"
|
||||
|
||||
|
|
|
|||
|
|
@ -27,4 +27,3 @@ lint: |
|
|||
|
||||
verifier:
|
||||
name: ansible
|
||||
|
||||
|
|
|
|||
|
|
@ -24,4 +24,3 @@
|
|||
- name: "Include tasks"
|
||||
ansible.builtin.include_role:
|
||||
name: "{{ role_name }}"
|
||||
|
||||
|
|
|
|||
|
|
@ -26,4 +26,3 @@ lint: |
|
|||
|
||||
verifier:
|
||||
name: ansible
|
||||
|
||||
|
|
|
|||
|
|
@ -9,7 +9,6 @@ benchmark_version: '1.0.0'
|
|||
# If run via script this is discovered and set
|
||||
host_os_distribution: {{ ansible_distribution | lower }}
|
||||
|
||||
|
||||
# timeout for each command to run where set - default = 10seconds/10000ms
|
||||
timeout_ms: 60000
|
||||
|
||||
|
|
@ -127,7 +126,6 @@ rhel9cis_rule_1_9: {{ rhel9cis_rule_1_9 }}
|
|||
# Ensure system-wide crypto policy is not legacy
|
||||
rhel9cis_rule_1_10: {{ rhel9cis_rule_1_10 }}
|
||||
|
||||
|
||||
# section 2
|
||||
# Services
|
||||
# 2.1 Time Synchronization
|
||||
|
|
@ -191,7 +189,6 @@ rhel9cis_rule_3_4_2_5: {{ rhel9cis_rule_3_4_2_5 }}
|
|||
rhel9cis_rule_3_4_2_6: {{ rhel9cis_rule_3_4_2_6 }}
|
||||
rhel9cis_rule_3_4_2_7: {{ rhel9cis_rule_3_4_2_7 }}
|
||||
|
||||
|
||||
# Section 4 rules
|
||||
# 4.1 Configure System Accounting
|
||||
rhel9cis_rule_4_1_1_1: {{ rhel9cis_rule_4_1_1_1 }}
|
||||
|
|
@ -265,7 +262,6 @@ rhel9cis_rule_4_2_3: {{ rhel9cis_rule_4_2_3 }}
|
|||
# 4.3 Logrotate
|
||||
rhel9cis_rule_4_3: {{ rhel9cis_rule_4_3 }}
|
||||
|
||||
|
||||
# Section 5
|
||||
# Authentication and Authorization
|
||||
# 5.1 Configure time-based job schedulers
|
||||
|
|
@ -450,7 +446,6 @@ rhel9cis_nft_tables_autonewtable: {{ rhel9cis_nft_tables_autonewtable }}
|
|||
rhel9cis_nft_tables_tablename: {{ rhel9cis_nft_tables_tablename }}
|
||||
rhel9cis_nft_tables_autochaincreate: {{ rhel9cis_nft_tables_autochaincreate }}
|
||||
|
||||
|
||||
# Section 4
|
||||
|
||||
## Set if host is a logserver
|
||||
|
|
@ -486,7 +481,6 @@ rhel9cis_authselect:
|
|||
custom_profile_name: {{ rhel9cis_authselect['custom_profile_name'] }}
|
||||
default_file_to_copy: {{ rhel9cis_authselect['default_file_to_copy'] }}
|
||||
|
||||
|
||||
## 5.4.1 Enable automation to create custom profile settings, using the setings above
|
||||
rhel9cis_authselect_custom_profile_create: {{ rhel9cis_authselect_custom_profile_create }}
|
||||
|
||||
|
|
|
|||
|
|
@ -2,7 +2,6 @@
|
|||
# Added as part of ansible-lockdown CIS baseline
|
||||
# provided by MindPointGroup LLC
|
||||
|
||||
|
||||
# Specify the dconf path
|
||||
[org/gnome/desktop/session]
|
||||
|
||||
|
|
|
|||
|
|
@ -1,8 +1,7 @@
|
|||
## This file is managed by Ansible, YOUR CHANGES WILL BE LOST!
|
||||
|
||||
|
||||
{% if rhel9cis_rule_1_5_3 %}
|
||||
# Kernel sysctl
|
||||
# CIS 1.5.3
|
||||
kernel.randomize_va_space = 2
|
||||
{% endif %}
|
||||
{% endif %}
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue