Closed tkolstee closed 3 years ago
There are a good number of differences between the two, but mostly the same with just different control numbers.
@KelfeinX has a fork working on updating to the RHEL 8 benchmark: https://github.com/KelfeinX/RHEL8-CIS
@benformosa @kelfeinX It would be nice if he could enable issues so some discussion on some things could take place.
One of the biggest issues I see with the RHEL8 benchmarks is the firewall (iptables vs. NFtables). It seems to me that the preferred way if NFtables, but the benchmark is incredibly vague and confusing. It almost seems like the benchmark should be sending users down two paths (NFtables OR iptables), but it almost seems like they want you to run both.
This would be nice.
Hello, I wanted to reach out and let you know that this issue is being closed. We have re-worked the role and want to start with a fresh issues list with this latest version. There was a post in the Ansible-Lockdown google group (https://groups.google.com/g/ansible-lockdown) with the details of the changes that are coming. Please checkout the thread titled RHEL 7 CIS and STIG Changes for all of the details, I also have the message pasted at below. Please as you use the latest version and open issue tickets as you find them, it is the best way for us to improve the role for everyone. Thank you for being part of the community and providing awareness of problems or advice on improvement. Reporting is a huge part of improving this project.
Hello, Thank you to everyone in the Ansible-Lockdown community who has contributed to RHEL7 STIG/CIS. Our team at MindPoint Group has been working with the entirety of the Ansible-Lockdown project, and we have some significant updates for both RHEL 7 STIG and CIS. With these updates, some larger changes have been made. I have these changes/updates outlined below. Testing:
The CIS Red Hat Enterprise Linux 8 Benchmark v 1.0.0 has been released. I was wondering if you had any plans to either create a new role or enhance this one to enforce both RHEL7 and RHEL8 benchmarks.