mirror of
https://github.com/rocky-linux/infrastructure
synced 2024-12-22 10:58:29 +00:00
auditd move to separate tasks file
This commit is contained in:
parent
cdd0e25232
commit
c8cb5ef4cf
@ -33,6 +33,9 @@
|
||||
- name: Configure PAM
|
||||
include: tasks/authentication.yml
|
||||
|
||||
- name: Configure auditd
|
||||
include: tasks/auditd.yml
|
||||
|
||||
post_tasks:
|
||||
- name: Touching run file that ansible has ran here
|
||||
file:
|
||||
|
36
ansible/playbooks/tasks/auditd.yml
Normal file
36
ansible/playbooks/tasks/auditd.yml
Normal file
@ -0,0 +1,36 @@
|
||||
---
|
||||
- name: Ensure auditd is installed
|
||||
package:
|
||||
name: audit
|
||||
state: present
|
||||
tags:
|
||||
- harden
|
||||
|
||||
- name: Ensure auditd is enabled
|
||||
service:
|
||||
name: auditd
|
||||
enabled: true
|
||||
|
||||
- name: Ensure auditd buffer is OK
|
||||
replace:
|
||||
path: /etc/audit/rules.d/audit.rules
|
||||
regexp: '-b \d+'
|
||||
replace: '-b {{ audit_buffer }}'
|
||||
notify:
|
||||
- regenerate_auditd_rules
|
||||
tags:
|
||||
- harden
|
||||
|
||||
- name: Ensure collection audit rules are available
|
||||
template:
|
||||
src: "etc/audit/rules.d/collection.rules.j2"
|
||||
dest: "/etc/audit/rules.d/collection.rules"
|
||||
owner: root
|
||||
group: root
|
||||
mode: '0600'
|
||||
backup: true
|
||||
notify:
|
||||
- regenerate_auditd_rules
|
||||
- restart_auditd
|
||||
tags:
|
||||
- harden
|
@ -151,39 +151,6 @@
|
||||
tags:
|
||||
- harden
|
||||
|
||||
- name: Auditd
|
||||
block:
|
||||
- name: Ensure auditd is installed
|
||||
package:
|
||||
name: audit
|
||||
state: present
|
||||
tags:
|
||||
- harden
|
||||
|
||||
- name: Ensure auditd buffer is OK
|
||||
replace:
|
||||
path: /etc/audit/rules.d/audit.rules
|
||||
regexp: '-b \d+'
|
||||
replace: '-b {{ audit_buffer }}'
|
||||
notify:
|
||||
- regenerate_auditd_rules
|
||||
tags:
|
||||
- harden
|
||||
|
||||
- name: Ensure collection audit rules are available
|
||||
template:
|
||||
src: "etc/audit/rules.d/collection.rules.j2"
|
||||
dest: "/etc/audit/rules.d/collection.rules"
|
||||
owner: root
|
||||
group: root
|
||||
mode: '0600'
|
||||
backup: true
|
||||
notify:
|
||||
- regenerate_auditd_rules
|
||||
- restart_auditd
|
||||
tags:
|
||||
- harden
|
||||
|
||||
- name: Disable Services
|
||||
service:
|
||||
name: "{{ item }}"
|
||||
|
Loading…
Reference in New Issue
Block a user