Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Apply CIS recommendations for sysctl parameters. This will apply following CIS compliance rules: - xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_accept_ra - xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_accept_redirects - xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_accept_source_route - xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_all_forwarding - xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_accept_ra - xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_accept_redirects - xccdf_org.ssgproject.content_rule_sysctl_net_ipv6_conf_default_accept_source_route - xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_accept_redirects - xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_accept_source_route - xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_log_martians - xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_rp_filter - xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_secure_redirects - xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_accept_redirects - xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_accept_source_route - xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_log_martians - xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_rp_filter - xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_secure_redirects - xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_icmp_echo_ignore_broadcasts - xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_icmp_ignore_bogus_error_responses - xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_tcp_syncookies - xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_all_send_redirects - xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_conf_default_send_redirects - xccdf_org.ssgproject.content_rule_sysctl_net_ipv4_ip_forward - xccdf_org.ssgproject.content_rule_sysctl_fs_suid_dumpable - xccdf_org.ssgproject.content_rule_sysctl_kernel_randomize_va_space Fixes #68 Related scylladb/scylla-pkg#2953 (cherry picked from commit d75951b)
- Loading branch information