Commit graph

763 commits

Author SHA1 Message Date
uk-bolly
151896e113
Merge pull request #213 from ansible-lockdown/devel
Update to galaxy meta
2024-06-11 13:02:59 +01:00
uk-bolly
231c3c9092
Merge pull request #212 from ansible-lockdown/meta_update
updated due to galaxy limitation
2024-06-11 12:18:05 +01:00
Mark Bolwell
66317c2103
updated credits wording
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2024-06-11 09:16:44 +01:00
Mark Bolwell
2cbf7df01f
updated due to galaxy limitation
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2024-06-11 09:05:50 +01:00
uk-bolly
b77567384a
Merge pull request #211 from ansible-lockdown/pre-commit-ci-update-config
[pre-commit.ci] pre-commit autoupdate
2024-06-11 08:59:05 +01:00
pre-commit-ci[bot]
74a39d43b9
[pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/ansible-community/ansible-lint: v24.5.0 → v24.6.0](https://github.com/ansible-community/ansible-lint/compare/v24.5.0...v24.6.0)
2024-06-10 17:49:48 +00:00
uk-bolly
306eb59b88
Merge pull request #210 from ansible-lockdown/devel
Release to main
2024-06-10 12:49:41 +01:00
uk-bolly
f652ee449a
Merge pull request #209 from ansible-lockdown/June24_updates
June24 updates
2024-06-06 14:59:08 +01:00
Mark Bolwell
eeb76e2a37
updated
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2024-06-05 23:58:06 +01:00
Mark Bolwell
06e96ba769
improvements
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2024-06-05 23:57:18 +01:00
Mark Bolwell
49296c34a2
tidy up spacing
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2024-06-05 17:11:17 +01:00
Mark Bolwell
20e2986406
capture only configuratoin lines from rsyslog
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2024-06-05 17:10:22 +01:00
Mark Bolwell
5595097e78
Allowed force for command 5.4.2
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2024-06-05 09:52:51 +01:00
Mark Bolwell
60a9000dda
Address #191
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2024-06-05 09:46:14 +01:00
Mark Bolwell
bd7c4e3da2
improved tests based upon #190 thanks to @ipruteanu-sie
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2024-06-05 08:01:17 +01:00
Mark Bolwell
b279a9fb80
Added /dev/null to exclude in prelim check shell
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2024-06-05 08:00:02 +01:00
Mark Bolwell
21e0bc8387
added PR details #193 thanks to @brakkio86
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2024-06-04 17:53:12 +01:00
uk-bolly
8adae24b93
Merge pull request #208 from svennd/patch-1
2.4 : socket vs sockets (typo)
2024-06-04 17:26:59 +01:00
uk-bolly
b7261126d9
Merge pull request #207 from ansible-lockdown/pre-commit-ci-update-config
[pre-commit.ci] pre-commit autoupdate
2024-06-04 17:26:21 +01:00
uk-bolly
4c899bee33
Merge pull request #206 from svennd/devel
Typo
2024-06-04 17:25:54 +01:00
uk-bolly
f781b072a7
Merge pull request #199 from mark-tomich/devel
removing the async; the results of init are needed in the subsequent step
2024-06-04 17:25:10 +01:00
pre-commit-ci[bot]
4ca7b17c6e
[pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/Yelp/detect-secrets: v1.4.0 → v1.5.0](https://github.com/Yelp/detect-secrets/compare/v1.4.0...v1.5.0)
- [github.com/gitleaks/gitleaks: v8.18.2 → v8.18.3](https://github.com/gitleaks/gitleaks/compare/v8.18.2...v8.18.3)
- [github.com/ansible-community/ansible-lint: v24.2.2 → v24.5.0](https://github.com/ansible-community/ansible-lint/compare/v24.2.2...v24.5.0)
2024-06-03 17:46:46 +00:00
Svennd
2c09971cc2
2.4 : socket vs sockets
This looks for all active sockets, but the command is singular

Signed-off-by: Svennd <svenn.dhert@uantwerpen.be>
2024-05-22 10:28:56 +02:00
uk-bolly
7661bc0963
Merge pull request #205 from ansible-lockdown/devel
Release to main
2024-05-01 13:53:19 +01:00
Svennd
c567238d00
Merge pull request #1 from svennd/svennd-typo
typo
2024-04-30 22:15:38 +02:00
Svennd
f11d2cc3f0
typo
a small description typo

Signed-off-by: Svennd <svenn.dhert@uantwerpen.be>
2024-04-30 16:16:16 +02:00
uk-bolly
79e36d8736
updated assert statement (#204)
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2024-04-29 16:40:53 +01:00
pre-commit-ci[bot]
d8f9b30182
[pre-commit.ci] pre-commit autoupdate (#202)
updates:
- [github.com/ansible-community/ansible-lint: v24.2.1 → v24.2.2](https://github.com/ansible-community/ansible-lint/compare/v24.2.1...v24.2.2)

Co-authored-by: pre-commit-ci[bot] <66853113+pre-commit-ci[bot]@users.noreply.github.com>
2024-04-25 10:44:25 +01:00
pre-commit-ci[bot]
b5bea721f1
[pre-commit.ci] pre-commit autoupdate (#200)
updates:
- [github.com/pre-commit/pre-commit-hooks: v4.5.0 → v4.6.0](https://github.com/pre-commit/pre-commit-hooks/compare/v4.5.0...v4.6.0)

Co-authored-by: pre-commit-ci[bot] <66853113+pre-commit-ci[bot]@users.noreply.github.com>
2024-04-15 14:04:13 +01:00
uk-bolly
f8fcfe0e78
April_24 updates (#201)
* Issue #170, PR #181 thanks to @ipruteanu-sie

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* issue #182, PR #183 thansk to @ipruteanu-sie

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* PR #180 thanks to @ipruteanu-sie and @raabf

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* Addressed PR #165 thanks to @ipruteanu-sie

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* PT #184 addressed thansk to @ipruteanu-sie

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* updated credits

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* typo and ssh allow_deny comments

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* enable OS check

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* PR - #198 addressed thanks to @brakkio86

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* Addressed issue #190

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* Additional vars for issue #190

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* updated pre-commit version

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* consistent quotes around mode

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* moved audit added discoveries

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* removed unneeded vars

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* audit moved to prelim

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* tidy up

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* improved new variable usage

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* fixed logic 6.2.10

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* updated

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* addressed #197 thanks to @mark-tomich

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* updates for audit section

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* fixed naming

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* updated

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* added prelim to includes

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

---------

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2024-04-15 14:02:07 +01:00
Mark Tomich
835cd41c8a
removing the async because we need the results of the init in the subsequent step
Signed-off-by: Mark Tomich <tomichms@nih.gov>
2024-03-29 14:12:12 -04:00
pre-commit-ci[bot]
e87d637eb2
[pre-commit.ci] pre-commit autoupdate (#192)
updates:
- [github.com/ansible-community/ansible-lint: v24.2.0 → v24.2.1](https://github.com/ansible-community/ansible-lint/compare/v24.2.0...v24.2.1)

Co-authored-by: pre-commit-ci[bot] <66853113+pre-commit-ci[bot]@users.noreply.github.com>
2024-03-25 11:10:05 +00:00
RoboPickle
6eeae19517
Address issues in 4.1.1.2 and 4.1.1.3 including idempotent status (#188)
* Fixed issues with 4.1.1.2 and 4.1.1.3
Now handle multiple kernels and are idempotent

Signed-off-by: John Foster <robopickle@proton.me>

* Fixed issues with 4.1.1.2 and 4.1.1.3
Now handle multiple kernels and are idempotent

Removed debug messages

Signed-off-by: John Foster <robopickle@proton.me>

---------

Signed-off-by: John Foster <robopickle@proton.me>
2024-03-14 17:13:34 +00:00
uk-bolly
7d7b6132f4
March 24 to devel (#186)
* Issue #170, PR #181 thanks to @ipruteanu-sie

* issue #182, PR #183 thansk to @ipruteanu-sie

* PR #180 thanks to @ipruteanu-sie and @raabf

* Addressed PR #165 thanks to @ipruteanu-sie

* PT #184 addressed thansk to @ipruteanu-sie

* updated credits

* typo and ssh allow_deny comments

* enable OS check

---------

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2024-03-06 16:52:38 +00:00
uk-bolly
0f58436212
Gpg import for rhel servers (#185)
* change logic thanks to @rjacobs1990 see #175

* 1.2.1 force gpg import rhel

* fix missing facts

---------

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2024-03-06 09:10:06 +00:00
pre-commit-ci[bot]
0215412e9b
[pre-commit.ci] pre-commit autoupdate (#178)
updates:
- [github.com/adrienverge/yamllint.git: v1.34.0 → v1.35.1](https://github.com/adrienverge/yamllint.git/compare/v1.34.0...v1.35.1)

Co-authored-by: pre-commit-ci[bot] <66853113+pre-commit-ci[bot]@users.noreply.github.com>
2024-03-05 18:39:12 +00:00
uk-bolly
40bc7aa082
Feb24 updates (#179)
* change logic thanks to @rjacobs1990 see #175

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* thanks to @ipruteani-sie #134

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* Thanks to @stwongst #125

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* thanks to @sgomez86 #146

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* Added updates from #115

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* removed rp_filter in post added in error

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* updated yamllint precommit

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* updated fqcn fo json_query

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* updated

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* fix typo for virt type query

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

---------

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2024-02-20 15:43:43 +00:00
uk-bolly
06ec3de5c4
Merge pull request #175 from rjacobs1990/bugfix/fix-permissions-logfiles
fix: idempotency molecule issue fixed for logfiles #173
2024-02-19 14:16:21 +00:00
uk-bolly
96536cc908
Merge pull request #177 from RoboPickle/bugfix_5_3_4
Bugfix 5 3 4 against issue #176
2024-02-19 12:16:51 +00:00
John Foster
467434a56f
Added blank line between each named task for consistency.
Signed-off-by: John Foster <robopickle@proton.me>
2024-02-19 12:03:08 +00:00
uk-bolly
3313a1f2c3
Merge pull request #131 from siemens/siemens/feat/replacingVarAuditCopyPath
Replacing vars according to Audit needs
2024-02-19 11:53:01 +00:00
uk-bolly
03e2a28653
Merge pull request #174 from bbaassssiiee/bugfix/sshd
oscap scan found 2 issues in sshd configuration override files
2024-02-19 11:44:42 +00:00
uk-bolly
21f24b45a1
Merge pull request #169 from Illibur/patch-1
Update cis_6.1.x.yml
2024-02-19 11:37:29 +00:00
uk-bolly
f9dbbee1ec
Merge pull request #167 from ansible-lockdown/pre-commit-ci-update-config
[pre-commit.ci] pre-commit autoupdate
2024-02-19 11:35:19 +00:00
uk-bolly
e3f5522824
Merge pull request #166 from siemens/siemens/feat/BgrubbyUsageForParams
Siemens/feat/bgrubby usage for params
2024-02-19 11:34:52 +00:00
uk-bolly
cc6522f276
Merge pull request #164 from siemens/siemens/feat/Refactor_Document_main_variables
Using a patch to refactor doc-extension
2024-02-19 11:29:34 +00:00
uk-bolly
488a4d5bff
Merge pull request #150 from numericillustration/devel
fixing some mismatched tags and tasks in 5.6.1.x
2024-02-19 11:27:29 +00:00
John Foster
e100b02f44
Updated cis_6.1.x.yml to avoid deprecation warning as per Illibur's
findings in issue #168. Changed vars on line 233 to use dictionary.

Signed-off-by: John Foster <robopickle@proton.me>
2024-02-16 15:06:27 +00:00
John Foster
0e89fedfca
Adjusted tasks/main.yml indentation after running precommit checks
Signed-off-by: John Foster <robopickle@proton.me>
2024-02-15 10:17:41 +00:00
Michael Hicks
1c7990cecd
fixing some mismatched tags and tasks in 5.6.1.x
Signed-off-by: Michael Hicks <nooneofconsequence@gmail.com>
2024-02-14 13:39:15 -08:00