forked from ansible-lockdown/RHEL9-CIS
5.3.2.2: fix regex failing to match whitespace
Fixed yamllint (colons) issues Signed-off-by: polski-g <polski_g@sent.at>
This commit is contained in:
parent
39c7dfa187
commit
2557470054
1 changed files with 18 additions and 6 deletions
|
|
@ -91,9 +91,15 @@
|
|||
insertafter: "{{ item.after | default(omit) }}"
|
||||
line: "{{ item.line }}"
|
||||
loop:
|
||||
- { regexp: auth\s*required\s*pam_faillock.so preauth, after: auth\s*required\s*pam_env.so, line: "auth required pam_faillock.so preauth silent deny=3 unlock_timeout={{ rhel9cis_pam_faillock_unlock_time }}" }
|
||||
- { regexp: auth\s*required\s*pam_faillock.so authfail, before: auth\s*required\s*pam_deny.so, line: "auth required pam_faillock.so authfail silent deny=3 unlock_timeout={{ rhel9cis_pam_faillock_unlock_time }}" }
|
||||
- { regexp: account\s*required\s*pam_faillock.so, before: account\s*required\s*pam_unix.so, line: "account required pam_faillock.so" }
|
||||
- regexp: "auth\\s+required\\s+pam_faillock.so\\s+preauth"
|
||||
after: "auth\\s+required\\s+pam_env.so" # yamllint disable-line rule:colons
|
||||
line: "auth required pam_faillock.so preauth silent deny=3 unlock_timeout={{ rhel9cis_pam_faillock_unlock_time }}" # yamllint disable-line rule:colons
|
||||
- regexp: "auth\\s+required\\s+pam_faillock.so\\s+authfail"
|
||||
before: "auth\\s+required\\s+pam_deny.so"
|
||||
line: "auth required pam_faillock.so authfail silent deny=3 unlock_timeout={{ rhel9cis_pam_faillock_unlock_time }}" # yamllint disable-line rule:colons
|
||||
- regexp: "account\\s+required\\s+pam_faillock.so"
|
||||
before: "account\\s+required\\s+pam_unix.so"
|
||||
line: "account required pam_faillock.so" # yamllint disable-line rule:colons
|
||||
|
||||
- name: "5.3.2.2 | AUDIT | Ensure pam_faillock module is enabled | Add lines password-auth"
|
||||
when: not rhel9cis_allow_authselect_updates
|
||||
|
|
@ -104,9 +110,15 @@
|
|||
insertafter: "{{ item.after | default(omit) }}"
|
||||
line: "{{ item.line }}"
|
||||
loop:
|
||||
- { regexp: auth\s*required\s*pam_faillock.so preauth, after: auth\s*required\s*pam_env.so, line: "auth required pam_faillock.so preauth silent deny=3 unlock_timeout={{ rhel9cis_pam_faillock_unlock_time }}" }
|
||||
- { regexp: auth\s*required\s*pam_faillock.so authfail, before: auth\s*required\s*pam_deny.so, line: "auth required pam_faillock.so authfail silent deny=3 unlock_timeout={{ rhel9cis_pam_faillock_unlock_time }}" }
|
||||
- { regexp: account\s*required\s*pam_faillock.so, before: account\s*required\s*pam_unix.so, line: "account required pam_faillock.so" }
|
||||
- regexp: "auth\\s+required\\s+pam_faillock.so\\s+preauth"
|
||||
after: "auth\\s+required\\s+pam_env.so" # yamllint disable-line rule:colons
|
||||
line: "auth required pam_faillock.so preauth silent deny=3 unlock_timeout={{ rhel9cis_pam_faillock_unlock_time }}" # yamllint disable-line rule:colons
|
||||
- regexp: "auth\\s+required\\s+pam_faillock.so\\s+authfail"
|
||||
before: "auth\\s+required\\s+pam_deny.so"
|
||||
line: "auth required pam_faillock.so authfail silent deny=3 unlock_timeout={{ rhel9cis_pam_faillock_unlock_time }}" # yamllint disable-line rule:colons
|
||||
- regexp: "account\\s+required\\s+pam_faillock.so"
|
||||
before: "account\\s+required\\s+pam_unix.so"
|
||||
line: "account required pam_faillock.so" # yamllint disable-line rule:colons
|
||||
|
||||
- name: "5.3.2.3 | PATCH | Ensure pam_pwquality module is enabled"
|
||||
when:
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue