Commit graph

1188 commits

Author SHA1 Message Date
Mark Bolwell
cb475d3368
fixed typo on post audit file name
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2025-05-28 16:10:28 +01:00
Mark Bolwell
260005415c
Aligned with public
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2025-05-28 15:58:54 +01:00
Mark Bolwell
7673c2ff00
Added home directory discovery
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2025-05-28 15:53:41 +01:00
Mark Bolwell
97abfaf9f8
updated passwd variable
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2025-05-28 15:41:12 +01:00
Mark Bolwell
f740d89b54
Added user home discovery
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2025-05-28 15:36:39 +01:00
Mark Bolwell
210535bf4f
updated loop var name
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2025-05-28 15:36:04 +01:00
Mark Bolwell
c4070c341b
Updated logic on 7.2.9 tasks
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2025-05-28 15:35:34 +01:00
Mark Bolwell
5dc2541731
Updated passwd variable name
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2025-05-28 14:57:29 +01:00
Mark Bolwell
f29fc9088c
fixed var naming
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2025-05-28 10:53:32 +01:00
Mark Bolwell
a1126618a7
Added names
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2025-05-28 10:52:32 +01:00
Mark Bolwell
d136bfa381
Updated variable naming for interactive_users
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2025-05-28 10:22:30 +01:00
uk-bolly
96d054b0d2
Merge pull request #338 from polski-g/groupgroup_typo
Fix typo in variable name discovered_group_check
2025-05-28 10:02:28 +01:00
uk-bolly
4b4033e072
Merge pull request #337 from polski-g/network_manager_package_name
Variablize network-manager package name
2025-05-28 10:01:44 +01:00
uk-bolly
9c69d1f9e0
Merge pull request #336 from polski-g/sshd_redhat_cfg_exists
Check for existence of sshd_config.d/50-redhat.conf
2025-05-28 10:00:57 +01:00
Fred W.
e7e1f70494
Merge pull request #339 from ansible-lockdown/pre-commit-ci-update-config
[pre-commit.ci] pre-commit autoupdate
2025-05-27 13:11:13 -04:00
pre-commit-ci[bot]
68579ae85e
[pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/ansible-community/ansible-lint: v25.4.0 → v25.5.0](https://github.com/ansible-community/ansible-lint/compare/v25.4.0...v25.5.0)
2025-05-26 17:23:15 +00:00
Fred W.
029eb6768d
Merge pull request #29 from ansible-lockdown/benchmark_v2.0.0
may25_issues v2.0.0 release to latest
2025-05-23 14:04:54 -04:00
polski_g
fb9577f7d9
Fix typo in variable name discovered_group_check
Signed-off-by: polski-g <polski_g@sent.at>
2025-05-23 12:34:44 -04:00
polski_g
4e49532e20
Variablize network-manager package name
Signed-off-by: polski-g <polski_g@sent.at>
2025-05-23 12:33:55 -04:00
polski_g
f564135e72
Check for existence of sshd_config.d/50-redhat.conf before trying to modify it
Signed-off-by: polski-g <polski_g@sent.at>
2025-05-23 12:32:02 -04:00
uk-bolly
9ee1498c98
Merge pull request #332 from ansible-lockdown/may25_issues
May25 issues
2025-05-23 16:56:52 +01:00
uk-bolly
73c84de639
Merge pull request #28 from ansible-lockdown/may25_issues
May25 issues
2025-05-23 16:33:53 +01:00
Frederick Witty
a16b6b96bc
Fix for #325 thank you @mindrb
Signed-off-by: Frederick Witty <frederickw@mindpointgroup.com>
2025-05-23 11:14:58 -04:00
Mark Bolwell
f83e5a69a2
interactive users ilogic improvements thanks to @polski-g
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2025-05-23 16:05:01 +01:00
Frederick Witty
0e61e796c6
Fix for #325 thank you @mindrb
Signed-off-by: Frederick Witty <frederickw@mindpointgroup.com>
2025-05-23 11:00:13 -04:00
Mark Bolwell
cc48a0d0b5
Interactive user discovery improve thanks to @polski-g
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2025-05-23 15:53:03 +01:00
Mark Bolwell
4357f132a9
improved test for passwd entries
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2025-05-23 15:50:41 +01:00
Mark Bolwell
daf5a3f462
changed command to shell for grep
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2025-05-23 15:01:16 +01:00
Mark Bolwell
c23bce5c75
added check mode logic
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2025-05-23 14:35:50 +01:00
Mark Bolwell
15bf03c754
added check mode logic
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2025-05-23 14:34:30 +01:00
Mark Bolwell
b9a59b9adc
added check_mode logic
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2025-05-23 14:30:30 +01:00
Mark Bolwell
2b37d0d732
added check_mode logic
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2025-05-23 14:30:17 +01:00
Mark Bolwell
8d5a32bc39
added rhel9cis_rsyslog_ansiblemanage conditional
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2025-05-23 14:25:42 +01:00
Mark Bolwell
de45131085
added rhel9cis_rsyslog_ansiblemanage conditional
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2025-05-23 14:25:22 +01:00
Mark Bolwell
e9babc8e3b
added ignore comments in file
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2025-05-23 14:22:49 +01:00
Mark Bolwell
4948d3cb09
added ignore comments in file
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2025-05-23 14:22:30 +01:00
uk-bolly
90374036c4
Merge pull request #326 from ansible-lockdown/pre-commit-ci-update-config
[pre-commit.ci] pre-commit autoupdate
2025-05-21 17:38:53 +01:00
pre-commit-ci[bot]
5e2e4db20e
[pre-commit.ci] pre-commit autoupdate
updates:
- [github.com/gitleaks/gitleaks: v8.24.3 → v8.26.0](https://github.com/gitleaks/gitleaks/compare/v8.24.3...v8.26.0)
- [github.com/ansible-community/ansible-lint: v25.2.1 → v25.4.0](https://github.com/ansible-community/ansible-lint/compare/v25.2.1...v25.4.0)
- [github.com/adrienverge/yamllint.git: v1.37.0 → v1.37.1](https://github.com/adrienverge/yamllint.git/compare/v1.37.0...v1.37.1)
2025-05-19 17:24:24 +00:00
Fred W.
bd60c0f554
Merge pull request #27 from ansible-lockdown/benchmark_v2.0.0
May 15th 2025 QA Fixes from Benchmark v2.0.0
2025-05-15 17:06:53 -04:00
Frederick Witty
23b2909073
QA Fixes
Signed-off-by: Frederick Witty <frederickw@mindpointgroup.com>
2025-05-15 16:48:44 -04:00
Fred W.
ee5f604a66
Merge pull request #26 from ansible-lockdown/latest
May 2025 Alignment to latest
2025-05-09 15:31:23 -04:00
Fred W.
1d266e61a7
Merge pull request #25 from ansible-lockdown/benchmark_v2.0.0
Benchmark v2.0.0
2025-05-09 15:12:17 -04:00
Fred W.
2c35f64f38
Merge pull request #24 from ansible-lockdown/devel
May 2025 devel to latest alignment
2025-05-09 14:51:13 -04:00
Fred W.
15cb6db6bf
Merge pull request #324 from ansible-lockdown/fix_rhel9cis_warning_banner
Fix for #322 thank @mindrb
2025-04-25 14:58:15 -04:00
Frederick Witty
48c05f038f
Fix for #322 thank @mindrb
Signed-off-by: Frederick Witty <frederickw@mindpointgroup.com>
2025-04-25 14:36:58 -04:00
Fred W.
612f416fc8
Merge pull request #323 from ansible-lockdown/fix_j2_sshd_weakciphers
Fix for #320 thank you @kodebach
2025-04-25 13:07:07 -04:00
Frederick Witty
dd909b48c8
Fix for #320 thank you @kodebach
Signed-off-by: Frederick Witty <frederickw@mindpointgroup.com>
2025-04-25 11:47:17 -04:00
Fred W.
c8e410928e
Merge pull request #321 from ansible-lockdown/2025update
2025 Update - April Typo Fixes + Logic update on rhel9cis_discover_int_uid
2025-04-23 17:33:16 -04:00
Frederick Witty
e27e413f94
Update URL in defaults/main
Signed-off-by: Frederick Witty <frederickw@mindpointgroup.com>
2025-04-23 16:04:16 -04:00
Frederick Witty
42024903e3
revamp set facts premlim_ max_int_uid and prelim_min_int_uid
Signed-off-by: Frederick Witty <frederickw@mindpointgroup.com>
2025-04-23 12:47:22 -04:00