mirror of
https://github.com/dev-sec/ansible-collection-hardening
synced 2024-11-10 09:14:18 +00:00
add passwd vars
This commit is contained in:
parent
41feffdc17
commit
e879831819
3 changed files with 14 additions and 5 deletions
|
@ -12,3 +12,8 @@ os_shadow_perms:
|
|||
owner: root
|
||||
group: shadow
|
||||
mode: '0640'
|
||||
|
||||
os_passwd_perms:
|
||||
owner: root
|
||||
group: root
|
||||
mode: '0644'
|
||||
|
|
|
@ -10,3 +10,8 @@ os_shadow_perms:
|
|||
owner: root
|
||||
group: root
|
||||
mode: '0600'
|
||||
|
||||
os_passwd_perms:
|
||||
owner: root
|
||||
group: root
|
||||
mode: '0644'
|
||||
|
|
|
@ -11,8 +11,7 @@ os_shadow_perms:
|
|||
group: root
|
||||
mode: '0600'
|
||||
|
||||
sysctl_rhel_config:
|
||||
# ExecShield protection against buffer overflows
|
||||
kernel.exec-shield: 1
|
||||
# Syncookies is used to prevent SYN-flooding attacks.
|
||||
net.ipv4.tcp_syncookies: 1
|
||||
os_passwd_perms:
|
||||
owner: root
|
||||
group: root
|
||||
mode: '0644'
|
||||
|
|
Loading…
Reference in a new issue