fervidus / secure_linux_cis

Apache License 2.0
16 stars 33 forks source link

Create resource collector override to disable ip6tables #11

Closed canihavethisone closed 5 years ago

canihavethisone commented 5 years ago

…in class cis_3_3_3 when ipv6 disabled. Change default of ip6_enabled to false (ipv6 is now now opt-in). Update fixtures, changelog and metadata.

canihavethisone commented 5 years ago

also changed max_log_file default from 8 to 32 to adhere to expected value in Nessus scan

canihavethisone commented 5 years ago

no, the sysctl entries fail to apply if the Kernel parameter has been set first and a reboot occurs. I have actually put the sysctl entries back now as they apply as long as a reboot hasn't yet occurred, and Nessus looks for those entries. Refactoring I am doing is from running a Nessus L1 & L2 scan and reducing the number of fails.

canihavethisone commented 5 years ago

started running shellcheck over bash scripts and verifying functions

bryanjbelanger commented 5 years ago

Hey @canihavethisone , @dan-wittenberg and I are wondering if we will see you at PDX in October.

You planning on coming?

canihavethisone commented 5 years ago

No I won't make it this year.