mirror of
https://github.com/ansible-lockdown/RHEL9-CIS.git
synced 2025-12-24 22:23:06 +00:00
tidy up layout
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
This commit is contained in:
parent
9f829accd0
commit
6ed7c7e420
1 changed files with 16 additions and 32 deletions
|
|
@ -1,8 +1,7 @@
|
||||||
---
|
---
|
||||||
|
|
||||||
- name: "1.1.1.1 | PATCH | Ensure cramfs kernel module is not available"
|
- name: "1.1.1.1 | PATCH | Ensure cramfs kernel module is not available"
|
||||||
when:
|
when: rhel9cis_rule_1_1_1_1
|
||||||
- rhel9cis_rule_1_1_1_1
|
|
||||||
tags:
|
tags:
|
||||||
- level1-server
|
- level1-server
|
||||||
- level1-workstation
|
- level1-workstation
|
||||||
|
|
@ -35,8 +34,7 @@
|
||||||
state: absent
|
state: absent
|
||||||
|
|
||||||
- name: "1.1.1.2 | PATCH | Ensure freevxfs kernel module is not available"
|
- name: "1.1.1.2 | PATCH | Ensure freevxfs kernel module is not available"
|
||||||
when:
|
when: rhel9cis_rule_1_1_1_2
|
||||||
- rhel9cis_rule_1_1_1_2
|
|
||||||
tags:
|
tags:
|
||||||
- level1-server
|
- level1-server
|
||||||
- level1-workstation
|
- level1-workstation
|
||||||
|
|
@ -62,15 +60,13 @@
|
||||||
mode: '0600'
|
mode: '0600'
|
||||||
|
|
||||||
- name: "1.1.1.2 | PATCH | Ensure freevxfs kernel module is not available | Disable freevxfs"
|
- name: "1.1.1.2 | PATCH | Ensure freevxfs kernel module is not available | Disable freevxfs"
|
||||||
when:
|
when: not system_is_container
|
||||||
- not system_is_container
|
|
||||||
community.general.modprobe:
|
community.general.modprobe:
|
||||||
name: freevxfs
|
name: freevxfs
|
||||||
state: absent
|
state: absent
|
||||||
|
|
||||||
- name: "1.1.1.3 | PATCH | Ensure hfs kernel module is not available"
|
- name: "1.1.1.3 | PATCH | Ensure hfs kernel module is not available"
|
||||||
when:
|
when: rhel9cis_rule_1_1_1_3
|
||||||
- rhel9cis_rule_1_1_1_3
|
|
||||||
tags:
|
tags:
|
||||||
- level1-server
|
- level1-server
|
||||||
- level1-workstation
|
- level1-workstation
|
||||||
|
|
@ -96,15 +92,13 @@
|
||||||
mode: '0600'
|
mode: '0600'
|
||||||
|
|
||||||
- name: "1.1.1.3 | PATCH | Ensure hfs kernel module is not available | Disable hfs"
|
- name: "1.1.1.3 | PATCH | Ensure hfs kernel module is not available | Disable hfs"
|
||||||
when:
|
when: not system_is_container
|
||||||
- not system_is_container
|
|
||||||
community.general.modprobe:
|
community.general.modprobe:
|
||||||
name: hfs
|
name: hfs
|
||||||
state: absent
|
state: absent
|
||||||
|
|
||||||
- name: "1.1.1.4 | PATCH | Ensure hfsplus kernel module is not available"
|
- name: "1.1.1.4 | PATCH | Ensure hfsplus kernel module is not available"
|
||||||
when:
|
when: rhel9cis_rule_1_1_1_4
|
||||||
- rhel9cis_rule_1_1_1_4
|
|
||||||
tags:
|
tags:
|
||||||
- level1-server
|
- level1-server
|
||||||
- level1-workstation
|
- level1-workstation
|
||||||
|
|
@ -130,15 +124,13 @@
|
||||||
mode: '0600'
|
mode: '0600'
|
||||||
|
|
||||||
- name: "1.1.1.4 | PATCH | Ensure hfsplus kernel module is not available | Disable hfsplus"
|
- name: "1.1.1.4 | PATCH | Ensure hfsplus kernel module is not available | Disable hfsplus"
|
||||||
when:
|
when: not system_is_container
|
||||||
- not system_is_container
|
|
||||||
community.general.modprobe:
|
community.general.modprobe:
|
||||||
name: hfsplus
|
name: hfsplus
|
||||||
state: absent
|
state: absent
|
||||||
|
|
||||||
- name: "1.1.1.5 | PATCH | Ensure jffs2 kernel module is not available"
|
- name: "1.1.1.5 | PATCH | Ensure jffs2 kernel module is not available"
|
||||||
when:
|
when: rhel9cis_rule_1_1_1_5
|
||||||
- rhel9cis_rule_1_1_1_5
|
|
||||||
tags:
|
tags:
|
||||||
- level1-server
|
- level1-server
|
||||||
- level1-workstation
|
- level1-workstation
|
||||||
|
|
@ -164,15 +156,13 @@
|
||||||
mode: '0600'
|
mode: '0600'
|
||||||
|
|
||||||
- name: "1.1.1.5 | PATCH | Ensure jffs2 kernel module is not available | Disable jffs2"
|
- name: "1.1.1.5 | PATCH | Ensure jffs2 kernel module is not available | Disable jffs2"
|
||||||
when:
|
when: not system_is_container
|
||||||
- not system_is_container
|
|
||||||
community.general.modprobe:
|
community.general.modprobe:
|
||||||
name: jffs2
|
name: jffs2
|
||||||
state: absent
|
state: absent
|
||||||
|
|
||||||
- name: "1.1.1.6 | PATCH | Ensure squashfs kernel module is not available"
|
- name: "1.1.1.6 | PATCH | Ensure squashfs kernel module is not available"
|
||||||
when:
|
when: rhel9cis_rule_1_1_1_6
|
||||||
- rhel9cis_rule_1_1_1_6
|
|
||||||
tags:
|
tags:
|
||||||
- level2-server
|
- level2-server
|
||||||
- level2-workstation
|
- level2-workstation
|
||||||
|
|
@ -198,15 +188,13 @@
|
||||||
mode: '0600'
|
mode: '0600'
|
||||||
|
|
||||||
- name: "1.1.1.6 | PATCH | Ensure squashfs kernel module is not available | Disable squashfs"
|
- name: "1.1.1.6 | PATCH | Ensure squashfs kernel module is not available | Disable squashfs"
|
||||||
when:
|
when: not system_is_container
|
||||||
- not system_is_container
|
|
||||||
community.general.modprobe:
|
community.general.modprobe:
|
||||||
name: squashfs
|
name: squashfs
|
||||||
state: absent
|
state: absent
|
||||||
|
|
||||||
- name: "1.1.1.7 | PATCH | Ensure udf kernel module is not available"
|
- name: "1.1.1.7 | PATCH | Ensure udf kernel module is not available"
|
||||||
when:
|
when: rhel9cis_rule_1_1_1_7
|
||||||
- rhel9cis_rule_1_1_1_7
|
|
||||||
tags:
|
tags:
|
||||||
- level2-server
|
- level2-server
|
||||||
- level2-workstation
|
- level2-workstation
|
||||||
|
|
@ -232,15 +220,13 @@
|
||||||
mode: '0600'
|
mode: '0600'
|
||||||
|
|
||||||
- name: "1.1.1.7 | PATCH | Ensure udf kernel module is not available | Disable udf"
|
- name: "1.1.1.7 | PATCH | Ensure udf kernel module is not available | Disable udf"
|
||||||
when:
|
when: not system_is_container
|
||||||
- not system_is_container
|
|
||||||
community.general.modprobe:
|
community.general.modprobe:
|
||||||
name: udf
|
name: udf
|
||||||
state: absent
|
state: absent
|
||||||
|
|
||||||
- name: "1.1.1.8 | PATCH | Ensure usb-storage kernel module is not available"
|
- name: "1.1.1.8 | PATCH | Ensure usb-storage kernel module is not available"
|
||||||
when:
|
when: rhel9cis_rule_1_1_1_8
|
||||||
- rhel9cis_rule_1_1_1_8
|
|
||||||
tags:
|
tags:
|
||||||
- level1-server
|
- level1-server
|
||||||
- level2-workstation
|
- level2-workstation
|
||||||
|
|
@ -266,15 +252,13 @@
|
||||||
mode: '0600'
|
mode: '0600'
|
||||||
|
|
||||||
- name: "1.1.1.8 | PATCH | Ensure usb-storage kernel module is not available | Disable usb"
|
- name: "1.1.1.8 | PATCH | Ensure usb-storage kernel module is not available | Disable usb"
|
||||||
when:
|
when: not system_is_container
|
||||||
- not system_is_container
|
|
||||||
community.general.modprobe:
|
community.general.modprobe:
|
||||||
name: usb-storage
|
name: usb-storage
|
||||||
state: absent
|
state: absent
|
||||||
|
|
||||||
- name: "1.1.1.9 | PATCH | Ensure unused filesystems kernel modules are not available"
|
- name: "1.1.1.9 | PATCH | Ensure unused filesystems kernel modules are not available"
|
||||||
when:
|
when: rhel9cis_rule_1_1_1_9
|
||||||
- rhel9cis_rule_1_1_1_9
|
|
||||||
tags:
|
tags:
|
||||||
- level1-server
|
- level1-server
|
||||||
- level1-workstation
|
- level1-workstation
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue