Merge pull request #576 from danielkubat/auditd

auditd moved to separate tasks file
This commit is contained in:
Louis Abel 2020-12-13 10:44:35 -07:00 committed by GitHub
commit 3379f4d1eb
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
4 changed files with 38 additions and 38 deletions

View File

@ -16,8 +16,3 @@
- name: regenerate_auditd_rules
command: /sbin/augenrules
- name: restart_auditd
service:
name: auditd
state: restarted

View File

@ -33,6 +33,9 @@
- name: Configure PAM
import_tasks: tasks/authentication.yml
- name: Configure auditd
include: tasks/auditd.yml
post_tasks:
- name: Touching run file that ansible has ran here
file:

View File

@ -0,0 +1,35 @@
---
- name: Ensure auditd is installed
package:
name: audit
state: present
tags:
- harden
- name: Ensure auditd is enabled
service:
name: auditd
enabled: true
- name: Ensure auditd buffer is OK
replace:
path: /etc/audit/rules.d/audit.rules
regexp: '-b \d+'
replace: '-b {{ audit_buffer }}'
notify:
- regenerate_auditd_rules
tags:
- harden
- name: Ensure collection audit rules are available
template:
src: "etc/audit/rules.d/collection.rules.j2"
dest: "/etc/audit/rules.d/collection.rules"
owner: root
group: root
mode: '0600'
backup: true
notify:
- regenerate_auditd_rules
tags:
- harden

View File

@ -151,39 +151,6 @@
tags:
- harden
- name: Auditd
block:
- name: Ensure auditd is installed
package:
name: audit
state: present
tags:
- harden
- name: Ensure auditd buffer is OK
replace:
path: /etc/audit/rules.d/audit.rules
regexp: '-b \d+'
replace: '-b {{ audit_buffer }}'
notify:
- regenerate_auditd_rules
tags:
- harden
- name: Ensure collection audit rules are available
template:
src: "etc/audit/rules.d/collection.rules.j2"
dest: "/etc/audit/rules.d/collection.rules"
owner: root
group: root
mode: '0600'
backup: true
notify:
- regenerate_auditd_rules
- restart_auditd
tags:
- harden
- name: Disable Services
service:
name: "{{ item }}"