Merge pull request #14 from alewando/umask_fix

Fix UMASK hardening
workflow failure expected until RH9 GA
This commit is contained in:
uk-bolly 2022-05-11 09:38:42 +01:00 committed by GitHub
commit d5cce24f00
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23

View file

@ -91,13 +91,13 @@
replace:
path: /etc/bashrc
regexp: '^(?i)(\s+UMASK|UMASK)\s0[0-2][0-6]'
replace: 'UMASK 027'
replace: '\1 027'
- name: "5.6.5 | PATCH | Ensure default user umask is 027 or more restrictive | Set umask for /etc/profile"
replace:
path: /etc/profile
regexp: '^(?i)(\s+UMASK|UMASK)\s0[0-2][0-6]'
replace: 'UMASK 027'
replace: '\1 027'
when:
- rhel9cis_rule_5_6_5
tags: