4
0
Fork 0
Commit graph

77 commits

Author SHA1 Message Date
Mark Bolwell
8b58d71e4b
section1 v2 initial
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2024-07-19 17:01:23 +01:00
Mark Bolwell
62baec6d16
changed to default bootloader hash
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2024-07-12 12:37:45 +01:00
Svennd
f11d2cc3f0
typo
a small description typo

Signed-off-by: Svennd <svenn.dhert@uantwerpen.be>
2024-04-30 16:16:16 +02:00
uk-bolly
f8fcfe0e78
April_24 updates (#201)
* Issue #170, PR #181 thanks to @ipruteanu-sie

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* issue #182, PR #183 thansk to @ipruteanu-sie

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* PR #180 thanks to @ipruteanu-sie and @raabf

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* Addressed PR #165 thanks to @ipruteanu-sie

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* PT #184 addressed thansk to @ipruteanu-sie

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* updated credits

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* typo and ssh allow_deny comments

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* enable OS check

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* PR - #198 addressed thanks to @brakkio86

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* Addressed issue #190

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* Additional vars for issue #190

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* updated pre-commit version

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* consistent quotes around mode

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* moved audit added discoveries

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* removed unneeded vars

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* audit moved to prelim

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* tidy up

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* improved new variable usage

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* fixed logic 6.2.10

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* updated

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* addressed #197 thanks to @mark-tomich

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* updates for audit section

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* fixed naming

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* updated

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* added prelim to includes

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

---------

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2024-04-15 14:02:07 +01:00
uk-bolly
7d7b6132f4
March 24 to devel (#186)
* Issue #170, PR #181 thanks to @ipruteanu-sie

* issue #182, PR #183 thansk to @ipruteanu-sie

* PR #180 thanks to @ipruteanu-sie and @raabf

* Addressed PR #165 thanks to @ipruteanu-sie

* PT #184 addressed thansk to @ipruteanu-sie

* updated credits

* typo and ssh allow_deny comments

* enable OS check

---------

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2024-03-06 16:52:38 +00:00
uk-bolly
0f58436212
Gpg import for rhel servers (#185)
* change logic thanks to @rjacobs1990 see #175

* 1.2.1 force gpg import rhel

* fix missing facts

---------

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2024-03-06 09:10:06 +00:00
uk-bolly
40bc7aa082
Feb24 updates (#179)
* change logic thanks to @rjacobs1990 see #175

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* thanks to @ipruteani-sie #134

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* Thanks to @stwongst #125

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* thanks to @sgomez86 #146

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* Added updates from #115

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* removed rp_filter in post added in error

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* updated yamllint precommit

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* updated fqcn fo json_query

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* updated

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* fix typo for virt type query

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

---------

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2024-02-20 15:43:43 +00:00
Ionut Pruteanu
3581793d8e
Documenting also new added(space_left & admin_space_left)
Signed-off-by: Ionut Pruteanu <ionut.pruteanu@siemens.com>
2024-01-31 20:31:03 +02:00
Ionut Pruteanu
f2a2757d1b
Fixing yaml-lint errors
Signed-off-by: Ionut Pruteanu <ionut.pruteanu@siemens.com>
2024-01-31 20:30:25 +02:00
Ionut Pruteanu
a83678e9ce
Removing statement about SSH precedence vars.
Signed-off-by: Ionut Pruteanu <ionut.pruteanu@siemens.com>
2024-01-31 20:27:07 +02:00
Ionut Pruteanu
c70c23680a
Aplying patch to be used for extending-documentation
Signed-off-by: Ionut Pruteanu <ionut.pruteanu@siemens.com>
2024-01-31 10:26:10 +02:00
uk-bolly
df1aef8d31
Merge pull request #148 from siemens/siemens/feat/AuditVarsRefactoring
Siemens/feat/audit vars refactoring
2024-01-26 12:34:30 +00:00
Ionut Pruteanu
ca41b128cd
Defining some threshold for (audit_)space_left vars, as well as a bool which governs if extra params will be configured
Signed-off-by: Ionut Pruteanu <ionut.pruteanu@siemens.com>
2023-12-20 22:21:14 +02:00
Ionut Pruteanu
88ffe32137
Storing max_log_file under rhel9cis_auditd dict variable.
Signed-off-by: Ionut Pruteanu <ionut.pruteanu@siemens.com>
2023-12-20 21:58:49 +02:00
Marcin Dulinski
8b875ad228
Fixed chrony configuration options
Signed-off-by: Marcin Dulinski <martin@dulin.me.uk>
2023-11-22 09:17:15 +00:00
Mark Bolwell
8784941179
audit variables seperated
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2023-11-21 09:48:49 +00:00
Mark Bolwell
11071a66ab
added pragma allowed
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2023-09-21 15:36:05 +01:00
Mark Bolwell
f6fd7e02d3
git audit binary version updated
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2023-09-18 14:02:44 +01:00
Mark Bolwell
43a339c74f
new var rhel9cis_rhel_default_repo
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2023-09-07 14:23:12 +01:00
Mark Bolwell
18e59d32f1
more ansible_facst referenced #54
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2023-09-06 09:55:27 +01:00
Mark Bolwell
60e2ec5795
Added comment for os_check var
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2023-08-10 13:55:18 +01:00
Mark Bolwell
009c9fc498
updated audit vars naming, AMD & ARM binaries
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2023-07-28 15:16:50 +01:00
Mark Bolwell
e19402d613
updated comment
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2023-07-05 13:01:56 +01:00
Mark Bolwell
12c5d6e813
update comment
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2023-06-28 11:46:08 +01:00
Mark Bolwell
674d3417ff
rule_1.10 updates
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2023-06-06 14:36:38 +01:00
Jimmy Conner
626c76236a
Fix Policy Number for Grub Boot Password
Signed-off-by: Jimmy Conner <jconner@redhat.com>
2023-05-31 10:56:33 -05:00
Mark Bolwell
42b9dc9e89
Linting
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2023-03-20 15:16:15 +00:00
Mark Bolwell
868e74bbf4
issue 41 5.3.7 tasks
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2023-03-13 09:44:51 +00:00
Mark Bolwell
58d3bb4e41
updated var naming
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2023-03-01 09:17:38 +00:00
Mark Bolwell
a28c0531ee
align audit release
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2023-02-20 14:02:49 +00:00
Mark Bolwell
a14e9c5dbe
#30 thanks to @smatterchew sshd config file dropin ability
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2023-02-20 11:31:46 +00:00
Mark Bolwell
e5ce163fcf
new option to 6_2_16 not follow symlinks
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2023-02-14 08:54:21 +00:00
Mark Bolwell
bf83a6b84c
Add more safety around control 5.4.2
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2023-01-27 12:19:16 +00:00
Mark Bolwell
7d426bd497
Added # comment
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2023-01-26 16:03:17 +00:00
Mark Bolwell
032e73348a
removed vars not used any longer
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2023-01-23 17:01:27 +00:00
Mark Bolwell
fdf298328c
documented 1.2.4 for rhel
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2023-01-20 17:14:24 +00:00
Mark Bolwell
5eb72bc544
updated banner message
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2023-01-20 11:21:31 +00:00
Mark Bolwell
de88c96f24
section 1.8 alignment v1.0.0
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2023-01-20 10:29:50 +00:00
Mark Bolwell
499b67ceb2
Updated rsyslog server variable
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2023-01-19 14:51:30 +00:00
Mark Bolwell
999d7b5b1e
fix csv sugroup option updated
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2023-01-19 13:33:11 +00:00
Mark Bolwell
9e9e3abc43
changed default grub password
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2023-01-18 16:29:03 +00:00
Mark Bolwell
bc90630ca8
git add set bootloader & gossupdates
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2023-01-18 16:21:51 +00:00
Mark Bolwell
e17acee56d
fixed variables
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2023-01-13 13:59:15 +00:00
Mark Bolwell
0c279ad97d
new control 5.6.6 added
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2023-01-13 09:09:49 +00:00
Mark Bolwell
e62e5630b4
section 4 updates
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2023-01-12 11:38:53 +00:00
Mark Bolwell
1d96539637
Exentsion to auditd
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2022-10-14 12:29:06 +01:00
Mark Bolwell
4fe4346f35
updated audit filename
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2022-10-14 12:09:14 +01:00
Mark Bolwell
d3d819b0a0
changed default git_branch to devel
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2022-09-16 14:24:31 +01:00
Mark Bolwell
962319fcce
changed audit dir to opt
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2022-09-16 11:52:55 +01:00
Mark Bolwell
5ba2c41851
updated
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2022-07-26 11:13:29 +01:00