Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix https://github.com/ansible-lockdown/RHEL9-CIS/issues/58 #60

Merged
merged 2 commits into from
May 12, 2023

Conversation

jayolinares
Copy link
Contributor

Overall Review of Changes:
As per issue #58, setting faillock values from /etc/security/faillock.conf is not enough.
For the lockout policy to work, we need to add some parameters to the pam config files.

Issue Fixes:

How has this been tested?:
Yes, tested on my VM and the lockout is working.

Signed-off-by: Jay Olinares <[email protected]>
@uk-bolly uk-bolly self-requested a review May 11, 2023 15:14
@uk-bolly
Copy link
Member

hi @jayolinares

Thank you for taking the time to raise the issue and write and test this PR. Really appreciate the effort that it takes to go through and ensure it works as expected.
Initial testing looks positive. I have noted that the tags are missing for that rule also. If you could add the following

  tags:
      - level1-server
      - level1-workstation
      - patch
      - rule_5.5.2

many thanks

uk-bolly

Signed-off-by: Jay Olinares <[email protected]>
@jayolinares
Copy link
Contributor Author

Hi @uk-bolly,

Thanks for reviewing the PR.
Ok, tags have been added.

Copy link
Member

@uk-bolly uk-bolly left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

brilliant work

@uk-bolly uk-bolly merged commit aa2c44a into ansible-lockdown:devel May 12, 2023
@jayolinares jayolinares deleted the pamConfigs_faillock branch May 16, 2023 06:36
@uk-bolly uk-bolly mentioned this pull request Jun 6, 2023
uk-bolly added a commit that referenced this pull request Sep 6, 2023
Signed-off-by: Mark Bolwell <[email protected]>
ipruteanu-sie pushed a commit to siemens/RHEL9-CIS that referenced this pull request Jan 31, 2024
Signed-off-by: Mark Bolwell <[email protected]>
Signed-off-by: Ionut Pruteanu <[email protected]>
@uk-bolly uk-bolly mentioned this pull request Apr 30, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants