ansible-lockdown / RHEL9-CIS

Ansible role for Red Hat 9 CIS Baseline
https://ansible-lockdown.readthedocs.io
MIT License
113 stars 86 forks source link

Fixes for several issues with updated CIS-CAT assessor. #102

Closed brisky closed 10 months ago

brisky commented 11 months ago

Overall Review of Changes: These were fixes done after running CIS-CAT v4.34.0

Issue Fixes: [5.6.5 Ensure default user umask is 027 or more restrictive] [5.2.20 Ensure SSH Idle Timeout Interval is configured] [4.2.2.3/4 journald compress & persistent.] [3.3.7 Ensure Reverse Path Filtering is enabled]

Enhancements: No enhancements.

How has this been tested?: Tested using standalone default RHEL9 installation on virtualbox.

Signed-off-by: Nuno Carvalho briskypt@gmail.com ; nuno.carvalho@siemens.com

uk-bolly commented 11 months ago

hi @brisky

Thank you for taking the time to raise this PR. I do have a couple of questions around it . We generally do not change defaults/main.yml. These are defaults for the system and should be overridden by the use of other variables e.g. inventory/group_vars We have also found in many cases that many scanners are very restricted. I can see settings already exist in some cases but the scanner may not be seeing them or an alternative method in the documentation is being used.

Happy to go through in more details and ensure we are aligned, if you are on the discord channel i am easily found.

many thanks

uk-bolly

brisky commented 11 months ago

HI, yes also noticed that would be better to commit by feature instead of one bunch.

Will get this fixed and will update.

Thanks. Regards

Nuno Ricardo Carvalho

On Thu, Oct 12, 2023 at 3:36 PM uk-bolly @.***> wrote:

hi @brisky https://github.com/brisky

Thank you for taking the time to raise this PR. I do have a couple of questions around it . We generally do not change defaults/main.yml. These are defaults for the system and should be overridden by the use of other variables e.g. inventory/group_vars We have also found in many cases that many scanners are very restricted. I can see settings already exist in some cases but the scanner may not be seeing them or an alternative method in the documentation is being used.

Happy to go through in more details and ensure we are aligned, if you are on the discord channel i am easily found.

many thanks

uk-bolly

— Reply to this email directly, view it on GitHub https://github.com/ansible-lockdown/RHEL9-CIS/pull/102#issuecomment-1759740869, or unsubscribe https://github.com/notifications/unsubscribe-auth/ABDGF5J43WQSK6FV7RUPD7TX67573ANCNFSM6AAAAAA54C3XOQ . You are receiving this because you were mentioned.Message ID: @.***>