Commit graph

105 commits

Author SHA1 Message Date
Adam Lewandowski
b9a3e3d2c6 Fix UMASK hardening
Signed-off-by: Adam Lewandowski <adam.lewandowski@plxis.com>
2022-05-09 14:12:41 -04:00
uk-bolly
e93d1ca735
Merge pull request #11 from ansible-lockdown/audit_vars
Add the ability to pass/change environment variable- current workflow failure expected
2022-05-04 16:32:07 +01:00
Mark Bolwell
3fc813361f
fixed typo
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2022-05-03 16:34:31 +01:00
Mark Bolwell
627f6e291d
updated environment options
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2022-05-03 10:22:00 +01:00
uk-bolly
33cfc54a5e
Merge pull request #9 from ansible-lockdown/lint
linting
2022-04-27 09:09:11 +01:00
Mark Bolwell
91600af889
yamllint
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2022-04-26 16:01:56 +01:00
uk-bolly
8361791c51
Merge pull request #8 from ansible-lockdown/rh8_2.0
Rh8 2.0
2022-04-26 15:58:05 +01:00
Mark Bolwell
32f5817007
added missing test to 3.3.7
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2022-04-26 12:01:20 +01:00
Mark Bolwell
83f0fb30ec
updated regex
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2022-04-26 12:01:06 +01:00
Mark Bolwell
e807498ed8
updated for correct service name
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2022-04-25 18:32:33 +01:00
Mark Bolwell
2c9587e666
updated for rh9 only
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2022-04-25 18:30:43 +01:00
Mark Bolwell
9a1ab79199
updated test
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2022-04-25 18:29:53 +01:00
Mark Bolwell
a8602689b8
updated issues and added improvements
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2022-04-25 16:58:11 +01:00
Mark Bolwell
49ab8c6f9f
updates for rh9
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2022-04-11 17:40:50 +01:00
Mark Bolwell
f66d271cee
controlid updates
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2022-04-11 17:39:30 +01:00
Mark Bolwell
2a421fcea6
logrotate changes reflected
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2022-04-11 17:39:13 +01:00
Mark Bolwell
4bd971fdcd
selinux updates
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2022-04-11 17:38:26 +01:00
Mark Bolwell
08e48fbe83
updated grub controls
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2022-04-11 17:38:01 +01:00
Mark Bolwell
9c519482a8
fixed typo
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2022-04-07 10:04:46 +01:00
Mark Bolwell
b8bb7912a1
removed iptables - not valid in rh9
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2022-04-06 17:29:57 +01:00
Mark Bolwell
82d1d18504
consistent lineinfile usage
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2022-04-06 16:58:03 +01:00
Mark Bolwell
02d686f920
removed default state
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2022-04-06 16:38:24 +01:00
Mark Bolwell
e27e5276e4
updated
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2022-04-06 16:32:53 +01:00
Mark Bolwell
ae6b6866e0
fix typo
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2022-04-06 16:32:36 +01:00
Mark Bolwell
e4275b2131
updated conditional
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2022-04-06 16:32:25 +01:00
Mark Bolwell
9c771e03e4
use new var name
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2022-04-06 16:32:14 +01:00
Mark Bolwell
7374c37510
updates var naming
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2022-04-06 16:31:57 +01:00
Mark Bolwell
c451f15546
audit vars
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2022-04-06 15:42:05 +01:00
Mark Bolwell
783c45d622
changed logic
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2022-04-05 16:56:27 +01:00
Mark Bolwell
21bd88bdac
fixed control
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2022-04-05 16:56:12 +01:00
Mark Bolwell
0b684a5d43
fix typo
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2022-04-05 16:56:02 +01:00
Mark Bolwell
e9d212437a
firewall pkgs to masked as default
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2022-04-05 13:07:36 +01:00
Mark Bolwell
bb7869adad
fixed 4.2.1.5 cron settings
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2022-04-05 13:06:46 +01:00
Mark Bolwell
13a6746997
lint
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2022-04-05 10:24:47 +01:00
Mark Bolwell
4e873bc0d6
added nfsnobody
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2022-04-05 10:09:06 +01:00
Mark Bolwell
d5065c1a82
lint
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2022-04-05 10:08:53 +01:00
Mark Bolwell
2bf95bf3da
default mask nftable for firewalld
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2022-04-05 10:08:42 +01:00
Mark Bolwell
32c409cb48
reorder 3.4.1.2
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2022-04-05 10:08:21 +01:00
Mark Bolwell
96abe45eb2
fix template path
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2022-04-05 10:08:06 +01:00
Mark Bolwell
0ef9e990cc
tidy and fix titles
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2022-04-05 08:48:53 +01:00
Mark Bolwell
d9b807c325
change lineinfile to path
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2022-04-05 08:45:11 +01:00
Mark Bolwell
3d5fd41ed8
pam vars
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2022-04-04 19:31:02 +01:00
Mark Bolwell
223254b5c9
rewrite
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2022-04-04 19:30:52 +01:00
Mark Bolwell
b3a6f89ae0
lint
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2022-04-04 19:30:40 +01:00
Mark Bolwell
2eeccbdc69
fixed regex
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2022-04-04 19:30:14 +01:00
Mark Bolwell
9a0ac22331
fix tag typo
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2022-04-04 16:20:27 +01:00
Mark Bolwell
e03f7194ff
added validate
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2022-04-04 16:16:31 +01:00
Mark Bolwell
790db75501
added validate & typo fixes
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2022-04-04 16:12:47 +01:00
Mark Bolwell
ca24e923c4
updated template names
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2022-04-04 16:07:59 +01:00
Mark Bolwell
49760449d0
netwokr protocol template
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2022-04-04 15:15:54 +01:00