ansible-lockdown / RHEL9-CIS

Ansible role for Red Hat 9 CIS Baseline
https://ansible-lockdown.readthedocs.io
MIT License
119 stars 91 forks source link

Siemens/feat/bgrubby usage for params #166

Closed ipruteanu-sie closed 8 months ago

ipruteanu-sie commented 9 months ago

Copy of this PR

Overall Review of Changes: Grubby instead of /etc/default/grub->/boot/grub2/grub.cfg

Issue Fixes:

160

How has this been tested?: On EC2 instance, CIS is happy if grubby lists options(grubby --info=ALL | grep args) configured previously(grubby --update-kernel=ALL --args="audit_backlog_limit=8192)