Compare commits

...

5 Commits

Author SHA1 Message Date
rronneburger 90f0dccd75
Merge fe8c656c3c into 371a35d4bf 2025-04-14 11:41:20 -04:00
Fred W. 371a35d4bf
Merge pull request #35 from ansible-lockdown/tidy_up
updated fetch default settings and tidy
2025-04-14 11:39:49 -04:00
Mark Bolwell b4239f6aef
improve notes for fetch
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2025-04-14 11:55:35 +01:00
Mark Bolwell 86a14fdc78
updated fetch default settings and tidy
Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
2025-04-14 11:53:22 +01:00
Ralf Ronneburger fe8c656c3c make sure audit_log_dir exists, make sure shell_session_file does not contain readonly twice (leading to error messages upon login) 2025-02-28 18:09:13 +01:00
4 changed files with 25 additions and 1 deletions

View File

@ -107,7 +107,9 @@ audit_conf_dest: "/opt"
audit_log_dir: '/opt'
# Method of getting,uploading the summary files
## Ensure access and permissions are avaiable for these to occur.
## Enable the collection of audit files
fetch_audit_output: false
## Ensure access and permissions are available for these to occur.
## options are
# fetch - fetches from server and moves to location on the ansible controller (could be a mount point available to controller)
# copy - copies file to a location available to the managed node

View File

@ -202,6 +202,7 @@
tags: always
ansible.builtin.import_tasks:
file: fetch_audit_output.yml
- name: Show Audit Summary
when: run_audit
tags: run_audit

View File

@ -12,6 +12,12 @@
mode: 'go-w'
state: directory
- name: Pre Audit Setup | Ensure existence of {{ audit_log_dir }}
ansible.builtin.file:
path: "{{ audit_log_dir }}"
mode: 'go-w'
state: directory
- name: Pre Audit Setup | If using git for content set up
when: audit_content == 'git'
block:

View File

@ -19,6 +19,21 @@
regexp: nologin
replace: ""
- name: "5.4.3.2 | PATCH | Remove old content from {{ ubtu24cis_shell_session_file }} before adding new lines"
when:
- ubtu24cis_rule_5_4_3_2
tags:
- level1-server
- level1-workstation
- patch
- shell
- rule_5.4.3.2
- NIST800-53R5_NA
ansible.builtin.replace:
path: "{{ ubtu24cis_shell_session_file }}"
regexp: '# Logout Timeout\nexport TMOUT=0\nreadonly TMOUT\n'
replace: '# Logout Timeout\n'
- name: "5.4.3.2 | PATCH | Ensure default user shell timeout is configured"
when:
- ubtu24cis_rule_5_4_3_2