Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Rh8 2.0 #8

Merged
merged 69 commits into from
Apr 26, 2022
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
69 commits
Select commit Hold shift + click to select a range
c96271e
update section1_2
uk-bolly Mar 30, 2022
efdcb0b
section_1 updates
uk-bolly Mar 30, 2022
f808f30
updated
uk-bolly Mar 30, 2022
dc5f71d
removed not required files
uk-bolly Mar 30, 2022
8c79bfe
updated
uk-bolly Mar 30, 2022
c85e9ba
updated ipv6 rules
uk-bolly Mar 30, 2022
42410b4
added ipv6 rules template
uk-bolly Mar 30, 2022
e043274
updated netwokr sysctl rules
uk-bolly Mar 30, 2022
555e443
renamd updated
uk-bolly Mar 30, 2022
35db813
updated
uk-bolly Mar 30, 2022
d65bb7f
renamed and updated
uk-bolly Mar 30, 2022
398bc5b
renamed and updated
uk-bolly Mar 30, 2022
c6caa90
updated
uk-bolly Mar 30, 2022
19a2183
updates
uk-bolly Mar 30, 2022
f0c4701
updated controls
uk-bolly Apr 1, 2022
a7403f8
removed travis variable
uk-bolly Apr 1, 2022
2565df6
removed notauto var as not used
uk-bolly Apr 1, 2022
2d21f8a
tidy up vars
uk-bolly Apr 1, 2022
bfbcede
fixed tags
uk-bolly Apr 1, 2022
3978056
section 1 updates
uk-bolly Apr 4, 2022
4dfacd9
updated server/service vars
uk-bolly Apr 4, 2022
8b8aef2
updated masked options
uk-bolly Apr 4, 2022
fef891d
tidy up sysctl templates
uk-bolly Apr 4, 2022
b4eefdb
2.2.18 update
uk-bolly Apr 4, 2022
adcc647
masked or removal options
uk-bolly Apr 4, 2022
842b295
firewall pkg control - prefer log capture
uk-bolly Apr 4, 2022
4976044
netwokr protocol template
uk-bolly Apr 4, 2022
ca24e92
updated template names
uk-bolly Apr 4, 2022
790db75
added validate & typo fixes
uk-bolly Apr 4, 2022
e03f719
added validate
uk-bolly Apr 4, 2022
9a0ac22
fix tag typo
uk-bolly Apr 4, 2022
2eeccbd
fixed regex
uk-bolly Apr 4, 2022
b3a6f89
lint
uk-bolly Apr 4, 2022
223254b
rewrite
uk-bolly Apr 4, 2022
3d5fd41
pam vars
uk-bolly Apr 4, 2022
d9b807c
change lineinfile to path
uk-bolly Apr 5, 2022
0ef9e99
tidy and fix titles
uk-bolly Apr 5, 2022
96abe45
fix template path
uk-bolly Apr 5, 2022
32c409c
reorder 3.4.1.2
uk-bolly Apr 5, 2022
2bf95bf
default mask nftable for firewalld
uk-bolly Apr 5, 2022
d5065c1
lint
uk-bolly Apr 5, 2022
4e873bc
added nfsnobody
uk-bolly Apr 5, 2022
13a6746
lint
uk-bolly Apr 5, 2022
bb7869a
fixed 4.2.1.5 cron settings
uk-bolly Apr 5, 2022
e9d2124
firewall pkgs to masked as default
uk-bolly Apr 5, 2022
0b684a5
fix typo
uk-bolly Apr 5, 2022
21bd88b
fixed control
uk-bolly Apr 5, 2022
783c45d
changed logic
uk-bolly Apr 5, 2022
c451f15
audit vars
uk-bolly Apr 6, 2022
7374c37
updates var naming
uk-bolly Apr 6, 2022
9c771e0
use new var name
uk-bolly Apr 6, 2022
e4275b2
updated conditional
uk-bolly Apr 6, 2022
ae6b686
fix typo
uk-bolly Apr 6, 2022
e27e527
updated
uk-bolly Apr 6, 2022
02d686f
removed default state
uk-bolly Apr 6, 2022
82d1d18
consistent lineinfile usage
uk-bolly Apr 6, 2022
b8bb791
removed iptables - not valid in rh9
uk-bolly Apr 6, 2022
9c51948
fixed typo
uk-bolly Apr 7, 2022
08e48fb
updated grub controls
uk-bolly Apr 11, 2022
4bd971f
selinux updates
uk-bolly Apr 11, 2022
2a421fc
logrotate changes reflected
uk-bolly Apr 11, 2022
f66d271
controlid updates
uk-bolly Apr 11, 2022
49ab8c6
updates for rh9
uk-bolly Apr 11, 2022
a860268
updated issues and added improvements
uk-bolly Apr 25, 2022
9a1ab79
updated test
uk-bolly Apr 25, 2022
2c9587e
updated for rh9 only
uk-bolly Apr 25, 2022
e807498
updated for correct service name
uk-bolly Apr 25, 2022
83f0fb3
updated regex
uk-bolly Apr 26, 2022
32f5817
added missing test to 3.3.7
uk-bolly Apr 26, 2022
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
11 changes: 11 additions & 0 deletions Changelog.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,16 @@
# Changes to rhel9CIS

## 0.2

- not all controls work with rhel8 releases any longer
- selinux disabled 1.6.1.4
- logrotate - 4.3.x
- updated to rhel8cis v2.0 benchamrk requirements
- removed iptables firewall controls (not valid on rhel9)
- added more to logrotate 4.3.x - sure to logrotate now a seperate package
- grub path now standard to /boot/grub2/grub.cfg
- 1.6.1.4 from rh8 removed as selinux.cfg doesnt disable selinux any longer

## 0.1

- change to include statements
Expand Down
3 changes: 2 additions & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -11,8 +11,9 @@
![Release](https://img.shields.io/github/v/release/ansible-lockdown/RHEL9-CIS?style=plastic)

Configure RHEL 9 machine to be [CIS](https://www.cisecurity.org/cis-benchmarks/) compliant with RHEL8 settings (RHEL9 not yet released)
Based on v2.0.0 RHEL8

Based on [CIS RedHat Enterprise Linux 8 Benchmark v1.0.1 - 05-19-2021 ](https://www.cisecurity.org/cis-benchmarks/)
Based on [CIS RedHat Enterprise Linux 8 Benchmark v2.0.0. - 02-23-2022 ](https://www.cisecurity.org/cis-benchmarks/)

## Join us

Expand Down
Loading