|
19 | 19 | # author: Dominik Richter |
20 | 20 | # author: Patrick Muench |
21 | 21 |
|
22 | | -login_defs_umask = input('login_defs_umask', value: os.redhat? ? '077' : '027', description: 'Default umask to set in login.defs') |
| 22 | +login_defs_umask = input('login_defs_umask', value: os.redhat? ? '077' : '027') |
23 | 23 |
|
24 | | -login_defs_passmaxdays = input('login_defs_passmaxdays', value: '60', description: 'Default password maxdays to set in login.defs') |
25 | | -login_defs_passmindays = input('login_defs_passmindays', value: '7', description: 'Default password mindays to set in login.defs') |
26 | | -login_defs_passwarnage = input('login_defs_passwarnage', value: '7', description: 'Default password warnage (days) to set in login.defs') |
| 24 | +login_defs_passmaxdays = input('login_defs_passmaxdays', value: '60') |
| 25 | +login_defs_passmindays = input('login_defs_passmindays', value: '7') |
| 26 | +login_defs_passwarnage = input('login_defs_passwarnage', value: '7') |
27 | 27 |
|
28 | 28 | shadow_group = 'root' |
29 | 29 | shadow_group = 'shadow' if os.debian? || os.suse? || os.name == 'alpine' |
|
35 | 35 |
|
36 | 36 | blacklist = input( |
37 | 37 | 'blacklist', |
38 | | - value: suid_blacklist.default, |
39 | | - description: 'blacklist of suid/sgid program on system' |
| 38 | + value: suid_blacklist.default |
40 | 39 | ) |
41 | 40 |
|
42 | 41 | cpuvulndir = '/sys/devices/system/cpu/vulnerabilities/' |
|
59 | 58 |
|
60 | 59 | mount_exec_blocklist = input( |
61 | 60 | 'mount_exec_blocklist', |
62 | | - value: ['/boot', '/dev', '/dev/shm', '/tmp', '/var/log', '/var/log/audit', '/var/tmp'], |
63 | | - description: 'List of mountpoints where \'noexec\' mount option should be set' |
| 61 | + value: ['/boot', '/dev', '/dev/shm', '/tmp', '/var/log', '/var/log/audit', '/var/tmp'] |
64 | 62 | ) |
65 | 63 |
|
66 | 64 | mount_suid_blocklist = input( |
67 | 65 | 'mount_suid_blocklist', |
68 | | - value: ['/boot', '/dev', '/dev/shm', '/home', '/run', '/tmp', '/var', '/var/log', '/var/log/audit', '/var/tmp'], |
69 | | - description: 'List of mountpoints where \'nosuid\' mount option should be set' |
| 66 | + value: ['/boot', '/dev', '/dev/shm', '/home', '/run', '/tmp', '/var', '/var/log', '/var/log/audit', '/var/tmp'] |
70 | 67 | ) |
71 | 68 |
|
72 | 69 | mount_dev_blocklist = input( |
73 | 70 | 'mount_dev_blocklist', |
74 | | - value: ['/boot', '/dev/shm', '/home', '/run', '/tmp', '/var', '/var/log', '/var/log/audit', '/var/tmp'], |
75 | | - description: 'List of mountpoints where \'nodev\' mount option should be set' |
| 71 | + value: ['/boot', '/dev/shm', '/home', '/run', '/tmp', '/var', '/var/log', '/var/log/audit', '/var/tmp'] |
76 | 72 | ) |
77 | 73 |
|
78 | 74 | control 'os-01' do |
|
0 commit comments