Open jamescassell opened 6 years ago
@redhatrises thanks for the link. My RFE is more to automatically create that tailoring file based on the defaults of this (ansible-lockdown RHEL6-STIG) project.
This role needs to be updated to be more inline with the RHEL7 roles so that it has vars for each STIG rule/id. Once that is done it should be simple to create tailored vars files for different use cases.
The defaults chosen for this project sometimes fail the scap-security-guide checks. It would be nice to create a tailoring file for variables here that would allow ssg to pass its checks. Notably, the daemon umask settings and the audit failure actions do not pass the ssg default checks. (see https://github.com/OpenSCAP/scap-security-guide/issues/2755)