4
0
Fork 0

fqcn updates

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
This commit is contained in:
Mark Bolwell 2023-01-19 13:12:33 +00:00
parent 4e1ee6f8e6
commit 4e8397b89e
No known key found for this signature in database
GPG key ID: 1DE02A772D0908F9
4 changed files with 7 additions and 10 deletions

View file

@ -11,7 +11,7 @@
mode: 0600
- name: "1.1.1.1 | PATCH | Ensure mounting of squashfs filesystems is disabled | blacklist"
lineinfile:
ansible.builtin.lineinfile:
path: /etc/modprobe.d/blacklist.conf
regexp: "^(#)?blacklist squashfs(\\s|$)"
line: "blacklist squashfs"
@ -19,7 +19,7 @@
mode: 0600
- name: "1.1.1.1 | PATCH | Ensure mounting of squashfs filesystems is disabled | Disable squashfs"
modprobe:
community.general.modprobe:
name: squashfs
state: absent
when: not system_is_container
@ -44,7 +44,7 @@
mode: 0600
- name: "1.1.1.2 | PATCH | Ensure mounting of udf filesystems is disabled | blacklist"
lineinfile:
ansible.builtin.lineinfile:
path: /etc/modprobe.d/blacklist.conf
regexp: "^(#)?blacklist udf(\\s|$)"
line: "blacklist udf"
@ -52,7 +52,7 @@
mode: 0600
- name: "1.1.1.2 | PATCH | Ensure mounting of udf filesystems is disable | Disable udf"
modprobe:
community.general.modprobe:
name: udf
state: absent
when: not system_is_container

View file

@ -1,8 +1,5 @@
---
- ansible.builtin.debug:
msg: "{{ mount_names }}"
- name: "1.1.7.1 | AUDIT | Ensure separate partition exists for /home"
block:
- name: "1.1.7.1 | AUDIT | Ensure separate partition exists for /home | Absent"

View file

@ -18,7 +18,7 @@
state: absent
- name: "1.1.9 | PATCH | Disable USB Storage | blacklist"
lineinfile:
ansible.builtin.lineinfile:
path: /etc/modprobe.d/blacklist.conf
regexp: "^(#)?blacklist usb-storage(\\s|$)"
line: "blacklist usb-storage"

View file

@ -70,7 +70,7 @@
- rule_1.8.3
- name: "1.8.4 | PATCH | Ensure GDM screen locks when the user is idle"
copy:
ansible.builtin.copy:
dest: /etc/dconf/db/local.d/00-screensaver
content: |
[org/gnome/desktop/session]
@ -90,7 +90,7 @@
- rule_1.8.4
- name: "1.8.5 PATCH | Ensure GDM screen locks cannot be overridden"
lineinfile:
ansible.builtin.lineinfile:
path: /etc/dconf/db/local.d/locks/session
create: true
line: /org/gnome/desktop/screensaver/lock-delay