File tree Expand file tree Collapse file tree
shared/templates/sysctl/tests
tests/data/product_stability Expand file tree Collapse file tree Original file line number Diff line number Diff line change @@ -57,3 +57,4 @@ reference_uris:
5757journald_conf_dir_path : /etc/systemd/journald.conf.d
5858audit_watches_style : modern
5959rsyslog_cafile : /etc/pki/ca-trust/extracted/pem/tls-ca-bundle.pem
60+ sysctl_remediate_drop_in_file : true
Original file line number Diff line number Diff line change @@ -107,3 +107,4 @@ reference_uris:
107107 cis : ' https://www.cisecurity.org/benchmark/red_hat_linux/'
108108
109109journald_conf_dir_path : /etc/systemd/journald.conf.d
110+ sysctl_remediate_drop_in_file : true
Original file line number Diff line number Diff line change @@ -60,3 +60,4 @@ centos_pkg_version: "8483c65d"
6060centos_major_version : " 9"
6161
6262journald_conf_dir_path : /etc/systemd/journald.conf.d
63+ sysctl_remediate_drop_in_file : true
Original file line number Diff line number Diff line change 1+ #! /bin/bash
2+ {{% if SYSCTLVAL == " " %}}
3+ # variables = sysctl_{{{ SYSCTLID }}}_value={{{ SYSCTL_CORRECT_VALUE }}}
4+ {{% endif %}}
5+
6+ # Clean sysctl config directories
7+ {{% if " ubuntu" in product %}}
8+ rm -rf /usr/lib/sysctl.d/* /run/sysctl.d/* /etc/sysctl.d/* /etc/ufw/sysctl.conf
9+ {{% else %}}
10+ rm -rf /usr/lib/sysctl.d/* /run/sysctl.d/* /etc/sysctl.d/*
11+ {{% endif %}}
12+
13+ sed -i " /{{{ SYSCTLVAR }}}/d" /etc/sysctl.conf
14+
15+ echo " {{{ SYSCTLVAR }}} = {{{ SYSCTL_CORRECT_VALUE }}}" >> /etc/sysctl.d/duplicate.conf
16+
17+ sysctl -w {{{ SYSCTLVAR }}}=" {{{ SYSCTL_CORRECT_VALUE }}}"
Original file line number Diff line number Diff line change @@ -104,7 +104,7 @@ release_key_fingerprint: 567E347AD0044ADE55BA8A5F199E2F91FD431D51
104104rsyslog_cafile : /etc/pki/ca-trust/extracted/pem/tls-ca-bundle.pem
105105sshd_distributed_config : ' true'
106106sshd_runtime_check : ' false'
107- sysctl_remediate_drop_in_file : ' false '
107+ sysctl_remediate_drop_in_file : ' true '
108108target_oval_version :
109109- 5
110110- 11
Original file line number Diff line number Diff line change @@ -151,7 +151,7 @@ release_key_fingerprint: 567E347AD0044ADE55BA8A5F199E2F91FD431D51
151151rsyslog_cafile : /etc/pki/tls/cert.pem
152152sshd_distributed_config : ' false'
153153sshd_runtime_check : ' false'
154- sysctl_remediate_drop_in_file : ' false '
154+ sysctl_remediate_drop_in_file : ' true '
155155target_oval_version :
156156- 5
157157- 11
Original file line number Diff line number Diff line change @@ -108,7 +108,7 @@ release_key_fingerprint: 567E347AD0044ADE55BA8A5F199E2F91FD431D51
108108rsyslog_cafile : /etc/pki/tls/cert.pem
109109sshd_distributed_config : ' true'
110110sshd_runtime_check : ' false'
111- sysctl_remediate_drop_in_file : ' false '
111+ sysctl_remediate_drop_in_file : ' true '
112112target_oval_version :
113113- 5
114114- 11
You can’t perform that action at this time.
0 commit comments