4
0
Fork 0
RHEL9-CIS/tasks/section_2/cis_2.1.x.yml
Mark Bolwell f0c4701dbd
updated controls
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2022-04-01 15:26:13 +01:00

42 lines
1 KiB
YAML

---
- name: "2.1.1 | PATCH | Ensure time synchronization is in use"
package:
name: chrony
state: present
when:
- rhel9cis_rule_2_1_1
- not system_is_container
tags:
- level1-server
- level1-workstation
- automated
- patch
- rule_2.1.1
- name: "2.1.2 | PATCH | Ensure chrony is configured"
block:
- name: "2.1.2 | PATCH | Ensure chrony is configured | Set configuration"
template:
src: etc/chrony.conf.j2
dest: /etc/chrony.conf
owner: root
group: root
mode: 0644
- name: "2.1.2 | PATCH | Ensure chrony is configured | modify /etc/sysconfig/chronyd | 1"
lineinfile:
dest: /etc/sysconfig/chronyd
regexp: "^(#)?OPTIONS"
line: "OPTIONS=\"-u chrony\""
state: present
create: yes
mode: 0644
when:
- rhel9cis_rule_2_1_2
- not system_is_container
tags:
- level1-server
- level1-workstation
- patch
- rule_2.1.2