mirror of
https://github.com/ansible-lockdown/RHEL9-CIS.git
synced 2025-12-24 22:23:06 +00:00
Merge pull request #353 from ansible-lockdown/fix_5.2.4
Addresses #318 - Thank you @kodebach & @bgro
This commit is contained in:
commit
d8af4747d4
2 changed files with 9 additions and 8 deletions
12
Changelog.md
12
Changelog.md
|
|
@ -1,11 +1,13 @@
|
||||||
# Changes to rhel9CIS
|
# Changes to rhel9CIS
|
||||||
|
|
||||||
## Based on CIS v2.0.0
|
## 2.0.2 - Based on CIS v2.0.0
|
||||||
|
|
||||||
Update to audit_only to allow fetching results
|
- Update to audit_only to allow fetching results
|
||||||
resolved false warning for fetch audit
|
- resolved false warning for fetch audit
|
||||||
fix root user check
|
- fix root user check
|
||||||
Improved documentation and variable compilation for crypto policies
|
- Improved documentation and variable compilation for crypto policies
|
||||||
|
- Addresses #318 - Thank you @kodebach & @bgro
|
||||||
|
- Improved logic for 5.2.4 to exclude rhel9cis_sudoers_exclude_nopasswd_list in pre-check tasks/main.yml
|
||||||
|
|
||||||
## 2.0.1 - Based on CIS v2.0.0
|
## 2.0.1 - Based on CIS v2.0.0
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -101,10 +101,9 @@
|
||||||
|
|
||||||
- name: "Check account is not locked for {{ ansible_env.SUDO_USER }} | Assert local account not locked" # noqa name[template]
|
- name: "Check account is not locked for {{ ansible_env.SUDO_USER }} | Assert local account not locked" # noqa name[template]
|
||||||
ansible.builtin.assert:
|
ansible.builtin.assert:
|
||||||
that:
|
that: (not prelim_ansible_user_password_set.stdout.startswith("!")) or (ansible_env.SUDO_USER in rhel9cis_sudoers_exclude_nopasswd_list)
|
||||||
- not prelim_ansible_user_password_set.stdout.startswith("!")
|
|
||||||
fail_msg: "You have {{ sudo_password_rule }} enabled but the user = {{ ansible_env.SUDO_USER }} is locked - It can break access"
|
fail_msg: "You have {{ sudo_password_rule }} enabled but the user = {{ ansible_env.SUDO_USER }} is locked - It can break access"
|
||||||
success_msg: "The local account is not locked for {{ ansible_env.SUDO_USER }} user"
|
success_msg: "The local account {{ ansible_env.SUDO_USER }} is not locked or included in the exception list for rule 5.2.4"
|
||||||
|
|
||||||
- name: "Check authselect profile is selected"
|
- name: "Check authselect profile is selected"
|
||||||
when: rhel9cis_allow_authselect_updates
|
when: rhel9cis_allow_authselect_updates
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue