diff --git a/tasks/section_5/cis_5.6.x.yml b/tasks/section_5/cis_5.6.x.yml index 420ce12..a9eaf75 100644 --- a/tasks/section_5/cis_5.6.x.yml +++ b/tasks/section_5/cis_5.6.x.yml @@ -90,14 +90,14 @@ - name: "5.6.5 | PATCH | Ensure default user umask is 027 or more restrictive | Set umask for /etc/bashrc" replace: path: /etc/bashrc - regexp: '(^\s+umask) 0[012][0-6]' - replace: '\1 027' + regexp: '^(\s+UMASK|UMASK)\s0[0-2][0-6]' + replace: 'UMASK 027' - name: "5.6.5 | PATCH | Ensure default user umask is 027 or more restrictive | Set umask for /etc/profile" replace: path: /etc/profile - regexp: '(^\s+umask) 0[012][0-6]' - replace: '\1 027' + regexp: '^(\s+UMASK|UMASK)\s0[0-2][0-6]' + replace: 'UMASK 027' when: - rhel9cis_rule_5_6_5 tags: