Conversation
and add NOTICE file for code reuse Signed-off-by: Maik Stuebner <Maik.Stuebner@t-systems.com>
Signed-off-by: Maik Stuebner <Maik.Stuebner@t-systems.com>
schurzi
left a comment
There was a problem hiding this comment.
I think it would be very beneficial to split this one control into multiple separate controlls.
A good approach for this may be CIS DIL Benchmark, this way we could get meaningful descriptions, explaining the wy and what, and also reference the IDs there for further reading.
| its(:stdout) { should match '-w /var/log/audit/audit.log' } | ||
| its(:stdout) { should match '-w /etc/hosts -p wa -k system-locale' } | ||
| its(:stdout) { should match '-w /etc/ssh/sshd_config' } | ||
| if os.redhat? || os.name == 'amazon' || os.name == 'fedora' |
There was a problem hiding this comment.
can you please change this to use only_if, like
linux-baseline/controls/os_spec.rb
Lines 153 to 167 in 91a0aa9
| end | ||
| end | ||
|
|
||
| control 'os-15' do |
There was a problem hiding this comment.
I think audit is large enough to start an extra file for all the checks and maybe split this up a bit to give it usefull names and descriptions.
|
Hi schurzi, Should I copy them to a new file in this repo an change the the tests to the things I configure in dev-sec/ansible-collection-hardening#468 ? |
see Telekom 2021.07-01 SoC 3.65 Req32-37
Public Telekom Security - Requirements