Add handlers for CIS 1.1.12 & 1.1.18 #10
Closed
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
When conforming to CIS 1.1.17 (AUDIT | Ensure separate partition exists for /home) and CIS 1.1.11 (AUDIT | Ensure separate partition exists for /var/tmp) the ansible script errors due to the requested handler not being present
1.1.12 | PATCH | Ensure noexec option set on /var/tmp partition
ERROR! The requested handler 'remount var_tmp' was not found in either the main handlers list nor in the listening handlers list
1.1.18 | PATCH | Ensure nodev option set on /home partition
ERROR! The requested handler 'remount home' was not found in either the main handlers list nor in the listening handlers list
Overall Review of Changes:
I have added the handlers to pass this section of the CIS benchmark if partitions have been configured for these directories
How has this been tested?:
Tested on Amazon Linux 2 with partitions created via LVM