Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

RFE: option to create ssg tailoring file #131

Open
jamescassell opened this issue Apr 16, 2018 · 2 comments
Open

RFE: option to create ssg tailoring file #131

jamescassell opened this issue Apr 16, 2018 · 2 comments

Comments

@jamescassell
Copy link
Collaborator

jamescassell commented Apr 16, 2018

The defaults chosen for this project sometimes fail the scap-security-guide checks. It would be nice to create a tailoring file for variables here that would allow ssg to pass its checks. Notably, the daemon umask settings and the audit failure actions do not pass the ssg default checks. (see ComplianceAsCode/content#2755)

@jamescassell
Copy link
Collaborator Author

@redhatrises thanks for the link. My RFE is more to automatically create that tailoring file based on the defaults of this (ansible-lockdown RHEL6-STIG) project.

@shepdelacreme
Copy link
Contributor

This role needs to be updated to be more inline with the RHEL7 roles so that it has vars for each STIG rule/id. Once that is done it should be simple to create tailored vars files for different use cases.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants