forked from ansible-lockdown/RHEL9-CIS
102 lines
2.2 KiB
YAML
102 lines
2.2 KiB
YAML
---
|
|
|
|
- name: "1.7.1 | PATCH | Ensure message of the day is configured properly"
|
|
when: rhel9cis_rule_1_7_1
|
|
tags:
|
|
- level1-server
|
|
- level1-workstation
|
|
- banner
|
|
- patch
|
|
- rule_1.7.1
|
|
- NIST800-53R5_CM-1
|
|
- NIST800-53R5_CM-3
|
|
- NIST800-53R5_CM-6
|
|
ansible.builtin.template:
|
|
src: etc/motd.j2
|
|
dest: /etc/motd
|
|
owner: root
|
|
group: root
|
|
mode: 'u-x,go-wx'
|
|
|
|
- name: "1.7.2 | PATCH | Ensure local login warning banner is configured properly"
|
|
when: rhel9cis_rule_1_7_2
|
|
tags:
|
|
- level1-server
|
|
- level1-workstation
|
|
- patch
|
|
- rule_1.7.2
|
|
- NIST800-53R5_CM-1
|
|
- NIST800-53R5_CM-3
|
|
- NIST800-53R5_CM-6
|
|
ansible.builtin.template:
|
|
src: etc/issue.j2
|
|
dest: /etc/issue
|
|
owner: root
|
|
group: root
|
|
mode: 'go-wx'
|
|
|
|
- name: "1.7.3 | PATCH | Ensure remote login warning banner is configured properly"
|
|
when: rhel9cis_rule_1_7_3
|
|
tags:
|
|
- level1-server
|
|
- level1-workstation
|
|
- banner
|
|
- patch
|
|
- rule_1.7.3
|
|
- NIST800-53R5_CM-1
|
|
- NIST800-53R5_CM-3
|
|
- NIST800-53R5_CM-6
|
|
ansible.builtin.template:
|
|
src: etc/issue.net.j2
|
|
dest: /etc/issue.net
|
|
owner: root
|
|
group: root
|
|
mode: 'go-wx'
|
|
|
|
- name: "1.7.4 | PATCH | Ensure permissions on /etc/motd are configured"
|
|
when: rhel9cis_rule_1_7_4
|
|
tags:
|
|
- level1-server
|
|
- level1-workstation
|
|
- perms
|
|
- patch
|
|
- rule_1.7.4
|
|
- NIST800-53R5_AC-3
|
|
- NIST800-53R5_MP-2
|
|
ansible.builtin.file:
|
|
path: /etc/motd
|
|
owner: root
|
|
group: root
|
|
mode: 'go-wx'
|
|
|
|
- name: "1.7.5 | PATCH | Ensure permissions on /etc/issue are configured"
|
|
when: rhel9cis_rule_1_7_5
|
|
tags:
|
|
- level1-server
|
|
- level1-workstation
|
|
- perms
|
|
- patch
|
|
- rule_1.7.5
|
|
- NIST800-53R5_AC-3
|
|
- NIST800-53R5_MP-2
|
|
ansible.builtin.file:
|
|
path: /etc/issue
|
|
owner: root
|
|
group: root
|
|
mode: 'go-wx'
|
|
|
|
- name: "1.7.6 | PATCH | Ensure permissions on /etc/issue.net are configured"
|
|
when: rhel9cis_rule_1_7_6
|
|
tags:
|
|
- level1-server
|
|
- level1-workstation
|
|
- perms
|
|
- patch
|
|
- rule_1.7.6
|
|
- NIST800-53R5_AC-3
|
|
- NIST800-53R5_MP-2
|
|
ansible.builtin.file:
|
|
path: /etc/issue.net
|
|
owner: root
|
|
group: root
|
|
mode: 'go-wx'
|