ansible-lockdown / RHEL8-CIS

Ansible role for Red Hat 8 CIS Baseline
https://ansible-lockdown.readthedocs.io/en/latest/
MIT License
263 stars 162 forks source link

ptrace scope is also set in /lib/sysctl.d/10-default-yama-scope.conf #365

Closed bbaassssiiee closed 6 months ago

bbaassssiiee commented 6 months ago

https://github.com/ansible-lockdown/RHEL8-CIS/blob/4d0dabaf36ed92a423bb779c1230ff1a8b21330c/tasks/section_1/cis_1.4.x.yml#L22

bbaassssiiee commented 6 months ago

OpenSCAP fails this control because 2 values are present. Proposed: Comment out any occurrences of kernel.yama.ptrace_scope from default config files