mirror of
https://github.com/ansible-lockdown/RHEL9-CIS.git
synced 2025-12-24 14:23:05 +00:00
added args warn for shell
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
This commit is contained in:
parent
e9a390c693
commit
66814a6f01
4 changed files with 16 additions and 2 deletions
|
|
@ -37,6 +37,8 @@
|
|||
block:
|
||||
- name: "Check su group exists if defined"
|
||||
shell: grep -w "{{ rhel9cis_sugroup }}" /etc/group
|
||||
args:
|
||||
warn: false
|
||||
register: sugroup_exists
|
||||
changed_when: false
|
||||
failed_when: sugroup_exists.rc >= 2
|
||||
|
|
|
|||
|
|
@ -8,6 +8,8 @@
|
|||
|
||||
- name: trigger update sysctl
|
||||
shell: /bin/true
|
||||
args:
|
||||
warn: false
|
||||
changed_when: false
|
||||
check_mode: false
|
||||
notify: update sysctl
|
||||
|
|
@ -30,6 +32,8 @@
|
|||
|
||||
- name: trigger update auditd
|
||||
shell: /bin/true
|
||||
args:
|
||||
warn: false
|
||||
notify: update auditd
|
||||
changed_when: false
|
||||
check_mode: false
|
||||
|
|
|
|||
|
|
@ -2,7 +2,7 @@
|
|||
|
||||
- name: "Post Audit | Run post_remediation {{ benchmark }} audit"
|
||||
shell: "{{ audit_conf_dir }}/run_audit.sh -v {{ audit_vars_path }} -o {{ post_audit_outfile }} -g {{ group_names }}"
|
||||
vars:
|
||||
args:
|
||||
warn: false
|
||||
|
||||
- name: Post Audit | ensure audit files readable by users
|
||||
|
|
@ -18,6 +18,8 @@
|
|||
block:
|
||||
- name: "capture data {{ post_audit_outfile }}"
|
||||
shell: "cat {{ post_audit_outfile }}"
|
||||
args:
|
||||
warn: false
|
||||
register: post_audit
|
||||
changed_when: false
|
||||
|
||||
|
|
@ -33,6 +35,8 @@
|
|||
block:
|
||||
- name: "Post Audit | capture data {{ post_audit_outfile }}"
|
||||
shell: "tail -2 {{ post_audit_outfile }}"
|
||||
args:
|
||||
warn: false
|
||||
register: post_audit
|
||||
changed_when: false
|
||||
|
||||
|
|
|
|||
|
|
@ -86,13 +86,15 @@
|
|||
|
||||
- name: "Pre Audit | Run pre_remediation {{ benchmark }} audit"
|
||||
shell: "{{ audit_conf_dir }}/run_audit.sh -v {{ audit_vars_path }} -o {{ pre_audit_outfile }} -g {{ group_names }}"
|
||||
vars:
|
||||
args:
|
||||
warn: false
|
||||
|
||||
- name: Pre Audit | Capture audit data if json format
|
||||
block:
|
||||
- name: "Pre Audit | capture data {{ pre_audit_outfile }}"
|
||||
shell: "cat {{ pre_audit_outfile }}"
|
||||
args:
|
||||
warn: false
|
||||
register: pre_audit
|
||||
changed_when: false
|
||||
|
||||
|
|
@ -108,6 +110,8 @@
|
|||
block:
|
||||
- name: "Pre Audit | capture data {{ pre_audit_outfile }}"
|
||||
shell: "tail -2 {{ pre_audit_outfile }}"
|
||||
args:
|
||||
warn: false
|
||||
register: pre_audit
|
||||
changed_when: false
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue