mirror of
https://github.com/ansible-lockdown/RHEL9-CIS.git
synced 2025-12-24 14:23:05 +00:00
15 lines
426 B
YAML
15 lines
426 B
YAML
---
|
|
|
|
- name: "1.11 | L2 | PATCH | Ensure system-wide crypto policy is FUTURE or FIPS"
|
|
shell: |
|
|
update-crypto-policies --set "{{ rhel9cis_crypto_policy }}"
|
|
update-crypto-policies
|
|
when:
|
|
- rhel9cis_rule_1_11
|
|
- system_wide_crypto_policy['stdout'] not in rhel9cis_allowed_crypto_policies
|
|
tags:
|
|
- level2-server
|
|
- level2-workstation
|
|
- not system_is_ec2
|
|
- patch
|
|
- rule_1.11
|