Mark Bolwell
|
2090cc4a45
|
not required file
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
|
2022-06-07 10:07:26 +01:00 |
|
Mark Bolwell
|
2c4718fb75
|
fix title
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
|
2022-06-07 10:07:19 +01:00 |
|
Mark Bolwell
|
93e3f7bf46
|
conditional and warning msg std
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
|
2022-05-11 11:20:12 +01:00 |
|
Mark Bolwell
|
2ecc61649e
|
Std Warning msg
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
|
2022-05-11 11:19:50 +01:00 |
|
Mark Bolwell
|
cbb5ff7cc2
|
Added git install to step
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
|
2022-05-11 11:19:33 +01:00 |
|
Mark Bolwell
|
9368c1e17e
|
updated for rh9
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
|
2022-05-11 09:57:44 +01:00 |
|
Mark Bolwell
|
5ce4b873d7
|
removed rh8 checks
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
|
2022-05-11 09:57:33 +01:00 |
|
Mark Bolwell
|
63c82f8305
|
Removed python 2/3 checks for rh7/8
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
|
2022-05-11 09:42:31 +01:00 |
|
uk-bolly
|
d5cce24f00
|
Merge pull request #14 from alewando/umask_fix
Fix UMASK hardening
workflow failure expected until RH9 GA
|
2022-05-11 09:38:42 +01:00 |
|
Adam Lewandowski
|
b9a3e3d2c6
|
Fix UMASK hardening
Signed-off-by: Adam Lewandowski <adam.lewandowski@plxis.com>
|
2022-05-09 14:12:41 -04:00 |
|
uk-bolly
|
0348777c0b
|
Merge pull request #12 from alewando/var_defaults
Add missing variable defaults for 'rhel9cis_pam_faillock'
adding a variable not breaking pipeline OK to approve
|
2022-05-06 16:39:09 +01:00 |
|
Adam Lewandowski
|
581eb70b48
|
Restore rhel9cis_pam_faillock.remember, as it is used by rules 5.5.3 and 5.5.4
Signed-off-by: Adam Lewandowski <adam.lewandowski@plxis.com>
|
2022-05-06 11:04:23 -04:00 |
|
Adam Lewandowski
|
62649cb6c5
|
Updated rhel9cis_pam_faillock defaults to only those needed for RHEL9
Signed-off-by: Adam Lewandowski <adam.lewandowski@plxis.com>
|
2022-05-06 11:04:23 -04:00 |
|
Adam Lewandowski
|
85afda6413
|
Add missing variable defaults for 'rhel9cis_pam_faillock'
Signed-off-by: Adam Lewandowski <adam.lewandowski@plxis.com>
|
2022-05-06 11:04:23 -04:00 |
|
uk-bolly
|
e93d1ca735
|
Merge pull request #11 from ansible-lockdown/audit_vars
Add the ability to pass/change environment variable- current workflow failure expected
|
2022-05-04 16:32:07 +01:00 |
|
Mark Bolwell
|
3fc813361f
|
fixed typo
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
|
2022-05-03 16:34:31 +01:00 |
|
Mark Bolwell
|
627f6e291d
|
updated environment options
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
|
2022-05-03 10:22:00 +01:00 |
|
uk-bolly
|
33cfc54a5e
|
Merge pull request #9 from ansible-lockdown/lint
linting
|
2022-04-27 09:09:11 +01:00 |
|
Mark Bolwell
|
91600af889
|
yamllint
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
|
2022-04-26 16:01:56 +01:00 |
|
uk-bolly
|
8361791c51
|
Merge pull request #8 from ansible-lockdown/rh8_2.0
Rh8 2.0
|
2022-04-26 15:58:05 +01:00 |
|
Mark Bolwell
|
32f5817007
|
added missing test to 3.3.7
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
|
2022-04-26 12:01:20 +01:00 |
|
Mark Bolwell
|
83f0fb30ec
|
updated regex
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
|
2022-04-26 12:01:06 +01:00 |
|
Mark Bolwell
|
e807498ed8
|
updated for correct service name
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
|
2022-04-25 18:32:33 +01:00 |
|
Mark Bolwell
|
2c9587e666
|
updated for rh9 only
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
|
2022-04-25 18:30:43 +01:00 |
|
Mark Bolwell
|
9a1ab79199
|
updated test
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
|
2022-04-25 18:29:53 +01:00 |
|
Mark Bolwell
|
a8602689b8
|
updated issues and added improvements
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
|
2022-04-25 16:58:11 +01:00 |
|
Mark Bolwell
|
49ab8c6f9f
|
updates for rh9
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
|
2022-04-11 17:40:50 +01:00 |
|
Mark Bolwell
|
f66d271cee
|
controlid updates
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
|
2022-04-11 17:39:30 +01:00 |
|
Mark Bolwell
|
2a421fcea6
|
logrotate changes reflected
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
|
2022-04-11 17:39:13 +01:00 |
|
Mark Bolwell
|
4bd971fdcd
|
selinux updates
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
|
2022-04-11 17:38:26 +01:00 |
|
Mark Bolwell
|
08e48fbe83
|
updated grub controls
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
|
2022-04-11 17:38:01 +01:00 |
|
Mark Bolwell
|
9c519482a8
|
fixed typo
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
|
2022-04-07 10:04:46 +01:00 |
|
Mark Bolwell
|
b8bb7912a1
|
removed iptables - not valid in rh9
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
|
2022-04-06 17:29:57 +01:00 |
|
Mark Bolwell
|
82d1d18504
|
consistent lineinfile usage
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
|
2022-04-06 16:58:03 +01:00 |
|
Mark Bolwell
|
02d686f920
|
removed default state
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
|
2022-04-06 16:38:24 +01:00 |
|
Mark Bolwell
|
e27e5276e4
|
updated
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
|
2022-04-06 16:32:53 +01:00 |
|
Mark Bolwell
|
ae6b6866e0
|
fix typo
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
|
2022-04-06 16:32:36 +01:00 |
|
Mark Bolwell
|
e4275b2131
|
updated conditional
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
|
2022-04-06 16:32:25 +01:00 |
|
Mark Bolwell
|
9c771e03e4
|
use new var name
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
|
2022-04-06 16:32:14 +01:00 |
|
Mark Bolwell
|
7374c37510
|
updates var naming
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
|
2022-04-06 16:31:57 +01:00 |
|
Mark Bolwell
|
c451f15546
|
audit vars
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
|
2022-04-06 15:42:05 +01:00 |
|
Mark Bolwell
|
783c45d622
|
changed logic
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
|
2022-04-05 16:56:27 +01:00 |
|
Mark Bolwell
|
21bd88bdac
|
fixed control
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
|
2022-04-05 16:56:12 +01:00 |
|
Mark Bolwell
|
0b684a5d43
|
fix typo
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
|
2022-04-05 16:56:02 +01:00 |
|
Mark Bolwell
|
e9d212437a
|
firewall pkgs to masked as default
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
|
2022-04-05 13:07:36 +01:00 |
|
Mark Bolwell
|
bb7869adad
|
fixed 4.2.1.5 cron settings
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
|
2022-04-05 13:06:46 +01:00 |
|
Mark Bolwell
|
13a6746997
|
lint
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
|
2022-04-05 10:24:47 +01:00 |
|
Mark Bolwell
|
4e873bc0d6
|
added nfsnobody
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
|
2022-04-05 10:09:06 +01:00 |
|
Mark Bolwell
|
d5065c1a82
|
lint
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
|
2022-04-05 10:08:53 +01:00 |
|
Mark Bolwell
|
2bf95bf3da
|
default mask nftable for firewalld
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
|
2022-04-05 10:08:42 +01:00 |
|