Added vars for streams.

Signed-off-by: root@DERVISHx <nuno.carvalho@siemens.com>
Signed-off-by: Ionut Pruteanu <ionut.pruteanu@siemens.com>
This commit is contained in:
root@DERVISHx 2023-12-27 15:39:46 +00:00 committed by Ionut Pruteanu
parent a63d154a8d
commit e7fc328aaa
No known key found for this signature in database
GPG key ID: 95B7D43B702B3569
3 changed files with 13 additions and 1 deletions

View file

@ -898,7 +898,7 @@ rhel9cis_auditd_uid_exclude:
# This variable governs which logging service should be used, choosing between 'rsyslog'(CIS recommendation) # This variable governs which logging service should be used, choosing between 'rsyslog'(CIS recommendation)
# or 'journald'(only one is implemented) will trigger the execution of the associated subsection, as the-best # or 'journald'(only one is implemented) will trigger the execution of the associated subsection, as the-best
# practices are written wholly independent of each other. # practices are written wholly independent of each other.
rhel9cis_syslog: rsyslog rhel9cis_syslog: journald
## Control 4.2.1.5 | PATCH | Ensure logging is configured ## Control 4.2.1.5 | PATCH | Ensure logging is configured
# This variable governs if current Ansible role should manage syslog settings # This variable governs if current Ansible role should manage syslog settings
# in /etc/rsyslog.conf file, namely mail, news and misc(warn, messages) # in /etc/rsyslog.conf file, namely mail, news and misc(warn, messages)

View file

@ -5,3 +5,9 @@ os_gpg_key_pubkey_name: gpg-pubkey-b86b3716-61e69f29
os_gpg_key_pubkey_content: "AlmaLinux OS 9 <packager@almalinux.org> b86b3716" os_gpg_key_pubkey_content: "AlmaLinux OS 9 <packager@almalinux.org> b86b3716"
# disable repo_gpgcheck due to OS default repos # disable repo_gpgcheck due to OS default repos
rhel9cis_rule_enable_repogpg: false rhel9cis_rule_enable_repogpg: false
rhel9cis_sshd:
# This variable sets the maximum number of unresponsive "keep-alive" messages
# that can be sent from the server to the client before the connection is considered
# inactive and thus, closed.
clientalivecountmax: 3

View file

@ -3,3 +3,9 @@
os_gpg_key_pubkey_name: gpg-pubkey-350d275d-6279464b os_gpg_key_pubkey_name: gpg-pubkey-350d275d-6279464b
os_gpg_key_pubkey_content: "Rocky Enterprise Software Foundation - Release key 2022 <releng@rockylinux.org> 350d275d" os_gpg_key_pubkey_content: "Rocky Enterprise Software Foundation - Release key 2022 <releng@rockylinux.org> 350d275d"
rhel9cis_sshd:
# This variable sets the maximum number of unresponsive "keep-alive" messages
# that can be sent from the server to the client before the connection is considered
# inactive and thus, closed.
clientalivecountmax: 3