2022-01-07 09:06:18 +00:00
|
|
|
---
|
|
|
|
|
|
2023-01-09 16:29:47 +00:00
|
|
|
- name: "1.1.9 | PATCH | Disable USB Storage"
|
2022-01-07 09:06:18 +00:00
|
|
|
block:
|
2023-01-09 16:29:47 +00:00
|
|
|
- name: "1.1.9 | PATCH | Disable USB Storage | Edit modprobe config"
|
|
|
|
|
ansible.builtin.lineinfile:
|
2022-04-06 16:58:03 +01:00
|
|
|
path: /etc/modprobe.d/CIS.conf
|
2022-01-07 09:06:18 +00:00
|
|
|
regexp: "^(#)?install usb-storage(\\s|$)"
|
|
|
|
|
line: "install usb-storage /bin/true"
|
2022-09-16 11:10:31 +01:00
|
|
|
create: true
|
2022-01-07 09:06:18 +00:00
|
|
|
owner: root
|
|
|
|
|
group: root
|
|
|
|
|
mode: 0600
|
|
|
|
|
|
2023-01-09 16:29:47 +00:00
|
|
|
- name: "1.1.9 | PATCH | Disable USB Storage | Edit modprobe config"
|
2023-04-10 13:48:47 -04:00
|
|
|
community.general.modprobe:
|
2022-01-07 09:06:18 +00:00
|
|
|
name: usb-storage
|
|
|
|
|
state: absent
|
2023-06-06 14:36:51 +01:00
|
|
|
when: not system_is_container
|
2023-01-19 10:07:14 +00:00
|
|
|
|
|
|
|
|
- name: "1.1.9 | PATCH | Disable USB Storage | blacklist"
|
2023-01-19 13:12:33 +00:00
|
|
|
ansible.builtin.lineinfile:
|
2023-01-19 10:07:14 +00:00
|
|
|
path: /etc/modprobe.d/blacklist.conf
|
|
|
|
|
regexp: "^(#)?blacklist usb-storage(\\s|$)"
|
|
|
|
|
line: "blacklist usb-storage"
|
|
|
|
|
create: true
|
|
|
|
|
mode: 0600
|
2022-01-07 09:06:18 +00:00
|
|
|
when:
|
2023-01-09 16:29:47 +00:00
|
|
|
- rhel9cis_rule_1_1_9
|
2022-01-07 09:06:18 +00:00
|
|
|
tags:
|
|
|
|
|
- level1-server
|
|
|
|
|
- level2-workstation
|
|
|
|
|
- patch
|
|
|
|
|
- mounts
|
|
|
|
|
- removable_storage
|
2023-01-09 16:29:47 +00:00
|
|
|
- rule_1.1.9
|