2023-03-10 15:19:52 +00:00
|
|
|
## Ansible controlled file
|
2023-08-08 18:53:23 +01:00
|
|
|
# Added as part of ansible-lockdown CIS baseline
|
2024-12-04 11:31:42 +00:00
|
|
|
# provided by Mindpoint Group - A Tyto Athene Company
|
2023-03-10 15:19:52 +00:00
|
|
|
### YOUR CHANGES WILL BE LOST!
|
2022-06-22 09:53:27 +01:00
|
|
|
|
2022-03-30 16:18:11 +01:00
|
|
|
# This template will set all of the auditd configurations via a handler in the role in one task instead of individually
|
2024-08-07 10:30:08 +01:00
|
|
|
{% if rhel9cis_rule_6_3_3_1 %}
|
2022-01-07 09:06:18 +00:00
|
|
|
-w /etc/sudoers -p wa -k scope
|
2022-04-01 15:26:13 +01:00
|
|
|
-w /etc/sudoers.d -p wa -k scope
|
2022-01-07 09:06:18 +00:00
|
|
|
{% endif %}
|
2024-08-07 10:30:08 +01:00
|
|
|
{% if rhel9cis_rule_6_3_3_2 %}
|
2025-01-29 13:54:13 +00:00
|
|
|
{% set syscalls = ["execve"] %}
|
2025-10-16 15:24:49 +01:00
|
|
|
{% set arch_syscalls = syscalls | select("in", supported_syscalls) | list %}
|
2025-01-29 13:54:13 +00:00
|
|
|
-a always,exit -F arch=b64 -C euid!=uid -F auid!=unset -S {{ arch_syscalls|join(',') }} -k user_emulation
|
|
|
|
|
-a always,exit -F arch=b32 -C euid!=uid -F auid!=unset -S {{ arch_syscalls|join(',') }} -k user_emulation
|
2022-01-07 09:06:18 +00:00
|
|
|
{% endif %}
|
2024-08-07 10:30:08 +01:00
|
|
|
{% if rhel9cis_rule_6_3_3_3 %}
|
2022-04-01 15:26:13 +01:00
|
|
|
-w {{ rhel9cis_sudolog_location }} -p wa -k sudo_log_file
|
2022-01-07 09:06:18 +00:00
|
|
|
{% endif %}
|
2024-08-07 10:30:08 +01:00
|
|
|
{% if rhel9cis_rule_6_3_3_4 %}
|
2025-02-26 11:27:36 +00:00
|
|
|
{% set syscalls = ["adjtimex","settimeofday"] %}
|
2025-10-16 15:24:49 +01:00
|
|
|
{% set arch_syscalls = syscalls | select("in", supported_syscalls) | list %}
|
2025-01-29 13:54:13 +00:00
|
|
|
-a always,exit -F arch=b64 -S {{ arch_syscalls|join(',') }} -k time-change
|
|
|
|
|
-a always,exit -F arch=b32 -S {{ arch_syscalls|join(',') }} -k time-change
|
2025-02-26 11:27:36 +00:00
|
|
|
{% set syscalls = ["clock_settime"] %}
|
2025-10-16 15:24:49 +01:00
|
|
|
{% set arch_syscalls = syscalls | select("in", supported_syscalls) | list %}
|
2025-02-26 12:26:58 +00:00
|
|
|
-a always,exit -F arch=b32 -S {{ arch_syscalls|join(',') }} -F a0=0x0 -k time-change
|
2025-02-26 11:27:36 +00:00
|
|
|
-a always,exit -F arch=b64 -S {{ arch_syscalls|join(',') }} -F a0=0x0 -k time-change
|
2022-03-30 16:18:11 +01:00
|
|
|
-w /etc/localtime -p wa -k time-change
|
2022-01-07 09:06:18 +00:00
|
|
|
{% endif %}
|
2024-08-07 10:30:08 +01:00
|
|
|
{% if rhel9cis_rule_6_3_3_5 %}
|
2025-01-29 13:54:13 +00:00
|
|
|
{% set syscalls = ["sethostname","setdomainname"] %}
|
2025-10-16 15:24:49 +01:00
|
|
|
{% set arch_syscalls = syscalls | select("in", supported_syscalls) | list %}
|
2025-02-26 12:26:58 +00:00
|
|
|
-a always,exit -F arch=b64 -S {{ arch_syscalls|join(',') }} -k system-locale
|
|
|
|
|
-a always,exit -F arch=b32 -S {{ arch_syscalls|join(',') }} -k system-locale
|
2022-01-07 09:06:18 +00:00
|
|
|
-w /etc/issue -p wa -k system-locale
|
|
|
|
|
-w /etc/issue.net -p wa -k system-locale
|
|
|
|
|
-w /etc/hosts -p wa -k system-locale
|
2025-07-04 13:50:05 +03:00
|
|
|
-w /etc/hostname -p wa -k system-locale
|
2022-01-07 09:06:18 +00:00
|
|
|
-w /etc/sysconfig/network -p wa -k system-locale
|
2022-03-30 16:18:11 +01:00
|
|
|
-w /etc/sysconfig/network-scripts -p wa -k system-locale
|
2025-06-26 13:29:42 +03:00
|
|
|
-w /etc/NetworkManager -p wa -k system-locale
|
2022-01-07 09:06:18 +00:00
|
|
|
{% endif %}
|
2024-08-07 10:30:08 +01:00
|
|
|
{% if rhel9cis_rule_6_3_3_6 %}
|
2024-11-04 18:39:01 +00:00
|
|
|
{% for proc in discovered_priv_procs.stdout_lines -%}
|
2024-08-07 10:30:08 +01:00
|
|
|
-a always,exit -F path={{ proc }} -F perm=x -F auid>={{ prelim_min_int_uid }} -F auid!=unset -k privileged
|
2022-03-30 16:18:11 +01:00
|
|
|
{% endfor %}
|
|
|
|
|
{% endif %}
|
2024-08-07 10:30:08 +01:00
|
|
|
{% if rhel9cis_rule_6_3_3_7 %}
|
2025-01-29 13:54:13 +00:00
|
|
|
{% set syscalls = ["creat","open","openat","truncate","ftruncate"] %}
|
2025-10-16 15:24:49 +01:00
|
|
|
{% set arch_syscalls = syscalls | select("in", supported_syscalls) | list %}
|
2025-01-30 10:19:42 +00:00
|
|
|
-a always,exit -F arch=b64 -S {{ arch_syscalls|join(',') }} -F exit=-EACCES -F auid>={{ prelim_min_int_uid }} -F auid!=unset -k access
|
|
|
|
|
-a always,exit -F arch=b64 -S {{ arch_syscalls|join(',') }} -F exit=-EPERM -F auid>={{ prelim_min_int_uid }} -F auid!=unset -k access
|
|
|
|
|
-a always,exit -F arch=b32 -S {{ arch_syscalls|join(',') }} -F exit=-EACCES -F auid>={{ prelim_min_int_uid }} -F auid!=unset -k access
|
|
|
|
|
-a always,exit -F arch=b32 -S {{ arch_syscalls|join(',') }} -F exit=-EPERM -F auid>={{ prelim_min_int_uid }} -F auid!=unset -k access
|
2022-03-30 16:18:11 +01:00
|
|
|
{% endif %}
|
2024-08-07 10:30:08 +01:00
|
|
|
{% if rhel9cis_rule_6_3_3_8 %}
|
2022-01-07 09:06:18 +00:00
|
|
|
-w /etc/group -p wa -k identity
|
|
|
|
|
-w /etc/passwd -p wa -k identity
|
|
|
|
|
-w /etc/gshadow -p wa -k identity
|
|
|
|
|
-w /etc/shadow -p wa -k identity
|
|
|
|
|
-w /etc/security/opasswd -p wa -k identity
|
2024-08-09 13:13:17 +01:00
|
|
|
-w /etc/nsswitch.conf -p wa -k identity
|
|
|
|
|
-w /etc/pam.conf -p wa -k identity
|
|
|
|
|
-w /etc/pam.d -p wa -k identity
|
2022-01-07 09:06:18 +00:00
|
|
|
{% endif %}
|
2024-08-07 10:30:08 +01:00
|
|
|
{% if rhel9cis_rule_6_3_3_9 %}
|
2025-01-29 13:54:13 +00:00
|
|
|
{% set syscalls = ["chmod","fchmod","fchmodat"] %}
|
2025-10-16 15:24:49 +01:00
|
|
|
{% set arch_syscalls = syscalls | select("in", supported_syscalls) | list %}
|
2025-01-30 10:19:42 +00:00
|
|
|
-a always,exit -F arch=b64 -S {{ arch_syscalls|join(',') }} -F auid>={{ prelim_min_int_uid }} -F auid!=unset -k perm_mod
|
2025-01-29 13:54:13 +00:00
|
|
|
{% set syscalls = ["chown","fchown","lchown","fchownat"] %}
|
2025-10-16 15:24:49 +01:00
|
|
|
{% set arch_syscalls = syscalls | select("in", supported_syscalls) | list %}
|
2025-01-30 10:19:42 +00:00
|
|
|
-a always,exit -F arch=b64 -S {{ arch_syscalls|join(',') }} -F auid>={{ prelim_min_int_uid }} -F auid!=unset -k perm_mod
|
2025-01-29 13:54:13 +00:00
|
|
|
{% set syscalls = ["setxattr","lsetxattr","fsetxattr","removexattr","lremovexattr","fremovexattr"] %}
|
2025-10-16 15:24:49 +01:00
|
|
|
{% set arch_syscalls = syscalls | select("in", supported_syscalls) | list %}
|
2025-01-30 10:19:42 +00:00
|
|
|
-a always,exit -F arch=b64 -S {{ arch_syscalls|join(',') }} -F auid>={{ prelim_min_int_uid }} -F auid!=unset -k perm_mod
|
2025-01-29 13:54:13 +00:00
|
|
|
{% set syscalls = ["chmod","fchmod","fchmodat"] %}
|
2025-10-16 15:24:49 +01:00
|
|
|
{% set arch_syscalls = syscalls | select("in", supported_syscalls) | list %}
|
2025-01-30 10:19:42 +00:00
|
|
|
-a always,exit -F arch=b32 -S {{ arch_syscalls|join(',') }} -F auid>={{ prelim_min_int_uid }} -F auid!=unset -k perm_mod
|
2025-01-29 13:54:13 +00:00
|
|
|
{% set syscalls = ["chown","fchown","lchown","fchownat"] %}
|
2025-10-16 15:24:49 +01:00
|
|
|
{% set arch_syscalls = syscalls | select("in", supported_syscalls) | list %}
|
2025-01-30 10:19:42 +00:00
|
|
|
-a always,exit -F arch=b32 -S {{ arch_syscalls|join(',') }} -F auid>={{ prelim_min_int_uid }} -F auid!=unset -k perm_mod
|
2025-01-29 13:54:13 +00:00
|
|
|
{% set syscalls = ["setxattr","lsetxattr","fsetxattr","removexattr","lremovexattr","fremovexattr"] %}
|
2025-10-16 15:24:49 +01:00
|
|
|
{% set arch_syscalls = syscalls | select("in", supported_syscalls) | list %}
|
2025-01-30 10:19:42 +00:00
|
|
|
-a always,exit -F arch=b32 -S {{ arch_syscalls|join(',') }} -F auid>={{ prelim_min_int_uid }} -F auid!=unset -k perm_mod
|
2022-01-07 09:06:18 +00:00
|
|
|
{% endif %}
|
2024-08-07 10:30:08 +01:00
|
|
|
{% if rhel9cis_rule_6_3_3_10 %}
|
2025-01-29 13:54:13 +00:00
|
|
|
{% set syscalls = ["mount"] %}
|
2025-10-16 15:24:49 +01:00
|
|
|
{% set arch_syscalls = syscalls | select("in", supported_syscalls) | list %}
|
2025-01-30 10:19:42 +00:00
|
|
|
-a always,exit -F arch=b64 -S {{ arch_syscalls|join(',') }} -F auid>={{ prelim_min_int_uid }} -F auid!=unset -k mounts
|
|
|
|
|
-a always,exit -F arch=b32 -S {{ arch_syscalls|join(',') }} -F auid>={{ prelim_min_int_uid }} -F auid!=unset -k mounts
|
2025-01-29 13:54:13 +00:00
|
|
|
{% endif %}
|
2024-08-07 10:30:08 +01:00
|
|
|
{% if rhel9cis_rule_6_3_3_11 %}
|
2022-03-30 16:18:11 +01:00
|
|
|
-w /var/run/utmp -p wa -k session
|
|
|
|
|
-w /var/log/wtmp -p wa -k session
|
|
|
|
|
-w /var/log/btmp -p wa -k session
|
|
|
|
|
{% endif %}
|
2024-08-07 10:30:08 +01:00
|
|
|
{% if rhel9cis_rule_6_3_3_12 %}
|
2022-03-30 16:18:11 +01:00
|
|
|
-w /var/log/lastlog -p wa -k logins
|
|
|
|
|
-w /var/run/faillock -p wa -k logins
|
|
|
|
|
{% endif %}
|
2024-08-07 10:30:08 +01:00
|
|
|
{% if rhel9cis_rule_6_3_3_13 %}
|
2025-01-29 13:54:13 +00:00
|
|
|
{% set syscalls = ["unlink","unlinkat","rename","renameat"] %}
|
2025-10-16 15:24:49 +01:00
|
|
|
{% set arch_syscalls = syscalls | select("in", supported_syscalls) | list %}
|
2025-01-30 10:19:42 +00:00
|
|
|
-a always,exit -F arch=b64 -S {{ arch_syscalls|join(',') }} -F auid>={{ prelim_min_int_uid }} -F auid!=unset -k delete
|
|
|
|
|
-a always,exit -F arch=b32 -S {{ arch_syscalls|join(',') }} -F auid>={{ prelim_min_int_uid }} -F auid!=unset -k delete
|
2022-03-30 16:18:11 +01:00
|
|
|
{% endif %}
|
2024-08-07 10:30:08 +01:00
|
|
|
{% if rhel9cis_rule_6_3_3_14 %}
|
2022-04-01 15:26:13 +01:00
|
|
|
-w /etc/selinux -p wa -k MAC-policy
|
|
|
|
|
-w /usr/share/selinux -p wa -k MAC-policy
|
2022-03-30 16:18:11 +01:00
|
|
|
{% endif %}
|
2024-08-07 10:30:08 +01:00
|
|
|
{% if rhel9cis_rule_6_3_3_15 %}
|
|
|
|
|
-a always,exit -F path=/usr/bin/chcon -F perm=x -F auid>={{ prelim_min_int_uid }} -F auid!=unset -k perm_chng
|
2022-03-30 16:18:11 +01:00
|
|
|
{% endif %}
|
2024-08-07 10:30:08 +01:00
|
|
|
{% if rhel9cis_rule_6_3_3_16 %}
|
|
|
|
|
-a always,exit -F path=/usr/bin/setfacl -F perm=x -F auid>={{ prelim_min_int_uid }} -F auid!=unset -k perm_chng
|
2022-01-07 09:06:18 +00:00
|
|
|
{% endif %}
|
2024-08-07 10:30:08 +01:00
|
|
|
{% if rhel9cis_rule_6_3_3_17 %}
|
2025-02-26 12:26:58 +00:00
|
|
|
-a always,exit -F path=/usr/bin/chacl -F perm=x -F auid>={{ prelim_min_int_uid }} -F auid!=unset -k perm_chng
|
2022-01-07 09:06:18 +00:00
|
|
|
{% endif %}
|
2024-08-07 10:30:08 +01:00
|
|
|
{% if rhel9cis_rule_6_3_3_18 %}
|
|
|
|
|
-a always,exit -F path=/usr/sbin/usermod -F perm=x -F auid>={{ prelim_min_int_uid }} -F auid!=unset -k usermod
|
2022-01-07 09:06:18 +00:00
|
|
|
{% endif %}
|
2024-08-07 10:30:08 +01:00
|
|
|
{% if rhel9cis_rule_6_3_3_19 %}
|
2025-01-30 10:19:42 +00:00
|
|
|
-a always,exit -F path=/usr/bin/kmod -F perm=x -F auid>={{ prelim_min_int_uid }} -F auid!=unset -k kernel_modules
|
2025-01-29 13:54:13 +00:00
|
|
|
{% set syscalls = ["init_module","finit_module","delete_module","create_module","query_module"] %}
|
2025-10-16 15:24:49 +01:00
|
|
|
{% set arch_syscalls = syscalls | select("in", supported_syscalls) | list %}
|
2025-01-30 10:19:42 +00:00
|
|
|
-a always,exit -F arch=b64 -S {{ arch_syscalls|join(',') }} -F auid>={{ prelim_min_int_uid }} -F auid!=unset -k kernel_modules
|
2022-01-07 09:06:18 +00:00
|
|
|
{% endif %}
|
2024-08-07 10:30:08 +01:00
|
|
|
{% if rhel9cis_rule_6_3_3_20 %}
|
2022-01-07 09:06:18 +00:00
|
|
|
-e 2
|
2022-04-01 15:26:13 +01:00
|
|
|
|
2022-01-07 09:06:18 +00:00
|
|
|
{% endif %}
|