|
│ │ │ -001ed8a0: 436f 6d70 6c65 7869 7479 3a3c 2f74 683e Complexity: |
│ │ │ -001ed8b0: 3c74 643e 6c6f 773c 2f74 643e 3c2f 7472 low |
|---|
| Disrupt
│ │ │ -001ed8d0: 696f 6e3a 3c2f 7468 3e3c 7464 3e6c 6f77 ion: | low
│ │ │ -001ed8e0: 3c2f 7464 3e3c 2f74 723e 3c74 723e 3c74 |
|---|
Reboot:false
| Strateg
│ │ │ -001ed920: 793a 3c2f 7468 3e3c 7464 3e65 6e61 626c y: | enabl
│ │ │ -001ed930: 653c 2f74 643e 3c2f 7472 3e3c 2f74 6162 e |
|---|
-
│ │ │ -001ed950: 6e61 6d65 3a20 4761 7468 6572 2074 6865 name: Gather the
│ │ │ -001ed960: 2070 6163 6b61 6765 2066 6163 7473 0a20 package facts.
│ │ │ -001ed970: 2070 6163 6b61 6765 5f66 6163 7473 3a0a package_facts:.
│ │ │ -001ed980: 2020 2020 6d61 6e61 6765 723a 2061 7574 manager: aut
│ │ │ -001ed990: 6f0a 2020 7461 6773 3a0a 2020 2d20 4e49 o. tags:. - NI
│ │ │ -001ed9a0: 5354 2d38 3030 2d35 332d 4143 2d37 2861 ST-800-53-AC-7(a
│ │ │ -001ed9b0: 290a 2020 2d20 4e49 5354 2d38 3030 2d35 ). - NIST-800-5
│ │ │ -001ed9c0: 332d 4155 2d31 3228 3229 0a20 202d 204e 3-AU-12(2). - N
│ │ │ -001ed9d0: 4953 542d 3830 302d 3533 2d41 552d 3134 IST-800-53-AU-14
│ │ │ -001ed9e0: 0a20 202d 204e 4953 542d 3830 302d 3533 . - NIST-800-53
│ │ │ -001ed9f0: 2d41 552d 3228 6129 0a20 202d 204e 4953 -AU-2(a). - NIS
│ │ │ -001eda00: 542d 3830 302d 3533 2d41 552d 3728 3129 T-800-53-AU-7(1)
│ │ │ -001eda10: 0a20 202d 204e 4953 542d 3830 302d 3533 . - NIST-800-53
│ │ │ -001eda20: 2d41 552d 3728 3229 0a20 202d 204e 4953 -AU-7(2). - NIS
│ │ │ -001eda30: 542d 3830 302d 3533 2d43 4d2d 3628 6129 T-800-53-CM-6(a)
│ │ │ -001eda40: 0a20 202d 2050 4349 2d44 5353 2d52 6571 . - PCI-DSS-Req
│ │ │ -001eda50: 2d31 302e 310a 2020 2d20 5043 492d 4453 -10.1. - PCI-DS
│ │ │ -001eda60: 5376 342d 3130 2e32 0a20 202d 2050 4349 Sv4-10.2. - PCI
│ │ │ -001eda70: 2d44 5353 7634 2d31 302e 322e 310a 2020 -DSSv4-10.2.1.
│ │ │ -001eda80: 2d20 656e 6162 6c65 5f73 7472 6174 6567 - enable_strateg
│ │ │ -001eda90: 790a 2020 2d20 6c6f 775f 636f 6d70 6c65 y. - low_comple
│ │ │ -001edaa0: 7869 7479 0a20 202d 206c 6f77 5f64 6973 xity. - low_dis
│ │ │ -001edab0: 7275 7074 696f 6e0a 2020 2d20 6d65 6469 ruption. - medi
│ │ │ -001edac0: 756d 5f73 6576 6572 6974 790a 2020 2d20 um_severity. -
│ │ │ -001edad0: 6e6f 5f72 6562 6f6f 745f 6e65 6564 6564 no_reboot_needed
│ │ │ -001edae0: 0a20 202d 2070 6163 6b61 6765 5f61 7564 . - package_aud
│ │ │ -001edaf0: 6974 5f69 6e73 7461 6c6c 6564 0a0a 2d20 it_installed..-
│ │ │ -001edb00: 6e61 6d65 3a20 456e 7375 7265 2061 7564 name: Ensure aud
│ │ │ -001edb10: 6974 6420 6973 2069 6e73 7461 6c6c 6564 itd is installed
│ │ │ -001edb20: 0a20 2061 6e73 6962 6c65 2e62 7569 6c74 . ansible.built
│ │ │ -001edb30: 696e 2e70 6163 6b61 6765 3a0a 2020 2020 in.package:.
│ │ │ -001edb40: 6e61 6d65 3a20 6175 6469 7464 0a20 2020 name: auditd.
│ │ │ -001edb50: 2073 7461 7465 3a20 7072 6573 656e 740a state: present.
│ │ │ -001edb60: 2020 7768 656e 3a20 2722 6c69 6e75 782d when: '"linux-
│ │ │ -001edb70: 6261 7365 2220 696e 2061 6e73 6962 6c65 base" in ansible
│ │ │ -001edb80: 5f66 6163 7473 2e70 6163 6b61 6765 7327 _facts.packages'
│ │ │ -001edb90: 0a20 2074 6167 733a 0a20 202d 204e 4953 . tags:. - NIS
│ │ │ -001edba0: 542d 3830 302d 3533 2d41 432d 3728 6129 T-800-53-AC-7(a)
│ │ │ -001edbb0: 0a20 202d 204e 4953 542d 3830 302d 3533 . - NIST-800-53
│ │ │ -001edbc0: 2d41 552d 3132 2832 290a 2020 2d20 4e49 -AU-12(2). - NI
│ │ │ -001edbd0: 5354 2d38 3030 2d35 332d 4155 2d31 340a ST-800-53-AU-14.
│ │ │ -001edbe0: 2020 2d20 4e49 5354 2d38 3030 2d35 332d - NIST-800-53-
│ │ │ -001edbf0: 4155 2d32 2861 290a 2020 2d20 4e49 5354 AU-2(a). - NIST
│ │ │ -001edc00: 2d38 3030 2d35 332d 4155 2d37 2831 290a -800-53-AU-7(1).
│ │ │ -001edc10: 2020 2d20 4e49 5354 2d38 3030 2d35 332d - NIST-800-53-
│ │ │ -001edc20: 4155 2d37 2832 290a 2020 2d20 4e49 5354 AU-7(2). - NIST
│ │ │ -001edc30: 2d38 3030 2d35 332d 434d 2d36 2861 290a -800-53-CM-6(a).
│ │ │ -001edc40: 2020 2d20 5043 492d 4453 532d 5265 712d - PCI-DSS-Req-
│ │ │ -001edc50: 3130 2e31 0a20 202d 2050 4349 2d44 5353 10.1. - PCI-DSS
│ │ │ -001edc60: 7634 2d31 302e 320a 2020 2d20 5043 492d v4-10.2. - PCI-
│ │ │ -001edc70: 4453 5376 342d 3130 2e32 2e31 0a20 202d DSSv4-10.2.1. -
│ │ │ -001edc80: 2065 6e61 626c 655f 7374 7261 7465 6779 enable_strategy
│ │ │ -001edc90: 0a20 202d 206c 6f77 5f63 6f6d 706c 6578 . - low_complex
│ │ │ -001edca0: 6974 790a 2020 2d20 6c6f 775f 6469 7372 ity. - low_disr
│ │ │ -001edcb0: 7570 7469 6f6e 0a20 202d 206d 6564 6975 uption. - mediu
│ │ │ -001edcc0: 6d5f 7365 7665 7269 7479 0a20 202d 206e m_severity. - n
│ │ │ -001edcd0: 6f5f 7265 626f 6f74 5f6e 6565 6465 640a o_reboot_needed.
│ │ │ -001edce0: 2020 2d20 7061 636b 6167 655f 6175 6469 - package_audi
│ │ │ -001edcf0: 745f 696e 7374 616c 6c65 640a 3c2f 636f t_installed.
| Complexity: | low |
|---|
| Disrup
│ │ │ +001ed520: 7469 6f6e 3a3c 2f74 683e 3c74 643e 6c6f tion: | lo
│ │ │ +001ed530: 773c 2f74 643e 3c2f 7472 3e3c 7472 3e3c w |
|---|
<
│ │ │ +001ed540: 7468 3e52 6562 6f6f 743a 3c2f 7468 3e3c th>Reboot:<
│ │ │ +001ed550: 7464 3e66 616c 7365 3c2f 7464 3e3c 2f74 td>false
| Strate
│ │ │ +001ed570: 6779 3a3c 2f74 683e 3c74 643e 656e 6162 gy: | enab
│ │ │ +001ed580: 6c65 3c2f 7464 3e3c 2f74 723e 3c2f 7461 le |
|---|
-
│ │ │ +001ed5a0: 206e 616d 653a 2047 6174 6865 7220 7468 name: Gather th
│ │ │ +001ed5b0: 6520 7061 636b 6167 6520 6661 6374 730a e package facts.
│ │ │ +001ed5c0: 2020 7061 636b 6167 655f 6661 6374 733a package_facts:
│ │ │ +001ed5d0: 0a20 2020 206d 616e 6167 6572 3a20 6175 . manager: au
│ │ │ +001ed5e0: 746f 0a20 2074 6167 733a 0a20 202d 204e to. tags:. - N
│ │ │ +001ed5f0: 4953 542d 3830 302d 3533 2d41 432d 3728 IST-800-53-AC-7(
│ │ │ +001ed600: 6129 0a20 202d 204e 4953 542d 3830 302d a). - NIST-800-
│ │ │ +001ed610: 3533 2d41 552d 3132 2832 290a 2020 2d20 53-AU-12(2). -
│ │ │ +001ed620: 4e49 5354 2d38 3030 2d35 332d 4155 2d31 NIST-800-53-AU-1
│ │ │ +001ed630: 340a 2020 2d20 4e49 5354 2d38 3030 2d35 4. - NIST-800-5
│ │ │ +001ed640: 332d 4155 2d32 2861 290a 2020 2d20 4e49 3-AU-2(a). - NI
│ │ │ +001ed650: 5354 2d38 3030 2d35 332d 4155 2d37 2831 ST-800-53-AU-7(1
│ │ │ +001ed660: 290a 2020 2d20 4e49 5354 2d38 3030 2d35 ). - NIST-800-5
│ │ │ +001ed670: 332d 4155 2d37 2832 290a 2020 2d20 4e49 3-AU-7(2). - NI
│ │ │ +001ed680: 5354 2d38 3030 2d35 332d 434d 2d36 2861 ST-800-53-CM-6(a
│ │ │ +001ed690: 290a 2020 2d20 5043 492d 4453 532d 5265 ). - PCI-DSS-Re
│ │ │ +001ed6a0: 712d 3130 2e31 0a20 202d 2050 4349 2d44 q-10.1. - PCI-D
│ │ │ +001ed6b0: 5353 7634 2d31 302e 320a 2020 2d20 5043 SSv4-10.2. - PC
│ │ │ +001ed6c0: 492d 4453 5376 342d 3130 2e32 2e31 0a20 I-DSSv4-10.2.1.
│ │ │ +001ed6d0: 202d 2065 6e61 626c 655f 7374 7261 7465 - enable_strate
│ │ │ +001ed6e0: 6779 0a20 202d 206c 6f77 5f63 6f6d 706c gy. - low_compl
│ │ │ +001ed6f0: 6578 6974 790a 2020 2d20 6c6f 775f 6469 exity. - low_di
│ │ │ +001ed700: 7372 7570 7469 6f6e 0a20 202d 206d 6564 sruption. - med
│ │ │ +001ed710: 6975 6d5f 7365 7665 7269 7479 0a20 202d ium_severity. -
│ │ │ +001ed720: 206e 6f5f 7265 626f 6f74 5f6e 6565 6465 no_reboot_neede
│ │ │ +001ed730: 640a 2020 2d20 7061 636b 6167 655f 6175 d. - package_au
│ │ │ +001ed740: 6469 745f 696e 7374 616c 6c65 640a 0a2d dit_installed..-
│ │ │ +001ed750: 206e 616d 653a 2045 6e73 7572 6520 6175 name: Ensure au
│ │ │ +001ed760: 6469 7464 2069 7320 696e 7374 616c 6c65 ditd is installe
│ │ │ +001ed770: 640a 2020 616e 7369 626c 652e 6275 696c d. ansible.buil
│ │ │ +001ed780: 7469 6e2e 7061 636b 6167 653a 0a20 2020 tin.package:.
│ │ │ +001ed790: 206e 616d 653a 2061 7564 6974 640a 2020 name: auditd.
│ │ │ +001ed7a0: 2020 7374 6174 653a 2070 7265 7365 6e74 state: present
│ │ │ +001ed7b0: 0a20 2077 6865 6e3a 2027 226c 696e 7578 . when: '"linux
│ │ │ +001ed7c0: 2d62 6173 6522 2069 6e20 616e 7369 626c -base" in ansibl
│ │ │ +001ed7d0: 655f 6661 6374 732e 7061 636b 6167 6573 e_facts.packages
│ │ │ +001ed7e0: 270a 2020 7461 6773 3a0a 2020 2d20 4e49 '. tags:. - NI
│ │ │ +001ed7f0: 5354 2d38 3030 2d35 332d 4143 2d37 2861 ST-800-53-AC-7(a
│ │ │ +001ed800: 290a 2020 2d20 4e49 5354 2d38 3030 2d35 ). - NIST-800-5
│ │ │ +001ed810: 332d 4155 2d31 3228 3229 0a20 202d 204e 3-AU-12(2). - N
│ │ │ +001ed820: 4953 542d 3830 302d 3533 2d41 552d 3134 IST-800-53-AU-14
│ │ │ +001ed830: 0a20 202d 204e 4953 542d 3830 302d 3533 . - NIST-800-53
│ │ │ +001ed840: 2d41 552d 3228 6129 0a20 202d 204e 4953 -AU-2(a). - NIS
│ │ │ +001ed850: 542d 3830 302d 3533 2d41 552d 3728 3129 T-800-53-AU-7(1)
│ │ │ +001ed860: 0a20 202d 204e 4953 542d 3830 302d 3533 . - NIST-800-53
│ │ │ +001ed870: 2d41 552d 3728 3229 0a20 202d 204e 4953 -AU-7(2). - NIS
│ │ │ +001ed880: 542d 3830 302d 3533 2d43 4d2d 3628 6129 T-800-53-CM-6(a)
│ │ │ +001ed890: 0a20 202d 2050 4349 2d44 5353 2d52 6571 . - PCI-DSS-Req
│ │ │ +001ed8a0: 2d31 302e 310a 2020 2d20 5043 492d 4453 -10.1. - PCI-DS
│ │ │ +001ed8b0: 5376 342d 3130 2e32 0a20 202d 2050 4349 Sv4-10.2. - PCI
│ │ │ +001ed8c0: 2d44 5353 7634 2d31 302e 322e 310a 2020 -DSSv4-10.2.1.
│ │ │ +001ed8d0: 2d20 656e 6162 6c65 5f73 7472 6174 6567 - enable_strateg
│ │ │ +001ed8e0: 790a 2020 2d20 6c6f 775f 636f 6d70 6c65 y. - low_comple
│ │ │ +001ed8f0: 7869 7479 0a20 202d 206c 6f77 5f64 6973 xity. - low_dis
│ │ │ +001ed900: 7275 7074 696f 6e0a 2020 2d20 6d65 6469 ruption. - medi
│ │ │ +001ed910: 756d 5f73 6576 6572 6974 790a 2020 2d20 um_severity. -
│ │ │ +001ed920: 6e6f 5f72 6562 6f6f 745f 6e65 6564 6564 no_reboot_needed
│ │ │ +001ed930: 0a20 202d 2070 6163 6b61 6765 5f61 7564 . - package_aud
│ │ │ +001ed940: 6974 5f69 6e73 7461 6c6c 6564 0a3c 2f63 it_installed.
│ │ │ +001ed960: 3c61 2063 6c61 7373 3d22 6274 6e20 6274 Rem
│ │ │ +001eda00: 6564 6961 7469 6f6e 2050 7570 7065 7420 ediation Puppet
│ │ │ +001eda10: 736e 6970 7065 7420 e287 b23c 2f61 3e3c snippet ...<
│ │ │ +001eda20: 6272 3e3c 6469 7620 636c 6173 733d 2270 br>| Com
│ │ │ +001edaa0: 706c 6578 6974 793a 3c2f 7468 3e3c 7464 plexity: | low |
|---|
Disruption
│ │ │ +001edad0: 3a3c 2f74 683e 3c74 643e 6c6f 773c 2f74 : | low | | R
│ │ │ +001edaf0: 6562 6f6f 743a 3c2f 7468 3e3c 7464 3e66 eboot: | f
│ │ │ +001edb00: 616c 7365 3c2f 7464 3e3c 2f74 723e 3c74 alse |
|---|
Strategy:<
│ │ │ +001edb20: 2f74 683e 3c74 643e 656e 6162 6c65 3c2f /th> | enable
│ │ │ +001edb30: 7464 3e3c 2f74 723e 3c2f 7461 626c 653e td> |
│ │ │ +001edb40: 3c70 7265 3e3c 636f 6465 3e69 6e63 6c75
inclu
│ │ │ +001edb50: 6465 2069 6e73 7461 6c6c 5f61 7564 6974 de install_audit
│ │ │ +001edb60: 640a 0a63 6c61 7373 2069 6e73 7461 6c6c d..class install
│ │ │ +001edb70: 5f61 7564 6974 6420 7b0a 2020 7061 636b _auditd {. pack
│ │ │ +001edb80: 6167 6520 7b20 2761 7564 6974 6427 3a0a age { 'auditd':.
│ │ │ +001edb90: 2020 2020 656e 7375 7265 203d 2667 743b ensure =>
│ │ │ +001edba0: 2027 696e 7374 616c 6c65 6427 2c0a 2020 'installed',.
│ │ │ +001edbb0: 7d0a 7d0a 3c2f 636f 6465 3e3c 2f70 7265 }.}.
Remediation
│ │ │ +001edc70: 4f53 4275 696c 6420 426c 7565 7072 696e OSBuild Blueprin
│ │ │ +001edc80: 7420 736e 6970 7065 7420 e287 b23c 2f61 t snippet ...
│ │ │ +001edcd0: 0a5b 5b70 6163 6b61 6765 735d 5d0a 6e61 .[[packages]].na
│ │ │ +001edce0: 6d65 203d 2022 6175 6469 7464 220a 7665 me = "auditd".ve
│ │ │ +001edcf0: 7273 696f 6e20 3d20 222a 220a 3c2f 636f rsion = "*".
<
│ │ │ 001edd10: 6120 636c 6173 733d 2262 746e 2062 746e a class="btn btn
│ │ │ 001edd20: 2d73 7563 6365 7373 2220 6461 7461 2d74 -success" data-t
│ │ │ 001edd30: 6f67 676c 653d 2263 6f6c 6c61 7073 6522 oggle="collapse"
│ │ │ 001edd40: 2064 6174 612d 7461 7267 6574 3d22 2369 data-target="#i
│ │ │ 001edd50: 6436 3534 2220 7461 6269 6e64 6578 3d22 d654" tabindex="
│ │ │ 001edd60: 3022 2072 6f6c 653d 2262 7574 746f 6e22 0" role="button"
│ │ │ @@ -126867,193 +126867,193 @@
│ │ │ 001ef920: 6c6c 6170 7365 2220 6461 7461 2d74 6172 llapse" data-tar
│ │ │ 001ef930: 6765 743d 2223 6964 3635 3622 2074 6162 get="#id656" tab
│ │ │ 001ef940: 696e 6465 783d 2230 2220 726f 6c65 3d22 index="0" role="
│ │ │ 001ef950: 6275 7474 6f6e 2220 6172 6961 2d65 7870 button" aria-exp
│ │ │ 001ef960: 616e 6465 643d 2266 616c 7365 2220 7469 anded="false" ti
│ │ │ 001ef970: 746c 653d 2241 6374 6976 6174 6520 746f tle="Activate to
│ │ │ 001ef980: 2072 6576 6561 6c22 2068 7265 663d 2223 reveal" href="#
│ │ │ -001ef990: 2122 3e52 656d 6564 6961 7469 6f6e 204f !">Remediation O
│ │ │ -001ef9a0: 5342 7569 6c64 2042 6c75 6570 7269 6e74 SBuild Blueprint
│ │ │ -001ef9b0: 2073 6e69 7070 6574 20e2 87b2 3c2f 613e snippet ...
│ │ │ -001ef9c0: 3c62 723e 3c64 6976 2063 6c61 7373 3d22
.
│ │ │ -001efa00: 5b63 7573 746f 6d69 7a61 7469 6f6e 732e [customizations.
│ │ │ -001efa10: 7365 7276 6963 6573 5d0a 656e 6162 6c65 services].enable
│ │ │ -001efa20: 6420 3d20 5b22 6175 6469 7464 225d 0a3c d = ["auditd"].<
│ │ │ -001efa30: 2f63 6f64 653e 3c2f 7072 653e 3c2f 6469 /code>
R
│ │ │ -001efae0: 656d 6564 6961 7469 6f6e 2050 7570 7065 emediation Puppe
│ │ │ -001efaf0: 7420 736e 6970 7065 7420 e287 b23c 2f61 t snippet ...| C
│ │ │ -001efb80: 6f6d 706c 6578 6974 793a 3c2f 7468 3e3c omplexity: | <
│ │ │ -001efb90: 7464 3e6c 6f77 3c2f 7464 3e3c 2f74 723e td>low
│ │ │ -001efba0: 3c74 723e 3c74 683e 4469 7372 7570 7469 | Disrupti
│ │ │ -001efbb0: 6f6e 3a3c 2f74 683e 3c74 643e 6c6f 773c on: | low<
│ │ │ -001efbc0: 2f74 643e 3c2f 7472 3e3c 7472 3e3c 7468 /td> |
|---|
| Reboot: | false |
│ │ │ -001efbf0: 3c74 723e 3c74 683e 5374 7261 7465 6779 | Strategy
│ │ │ -001efc00: 3a3c 2f74 683e 3c74 643e 656e 6162 6c65 : | enable
│ │ │ -001efc10: 3c2f 7464 3e3c 2f74 723e 3c2f 7461 626c |
|---|
inc
│ │ │ -001efc30: 6c75 6465 2065 6e61 626c 655f 6175 6469 lude enable_audi
│ │ │ -001efc40: 7464 0a0a 636c 6173 7320 656e 6162 6c65 td..class enable
│ │ │ -001efc50: 5f61 7564 6974 6420 7b0a 2020 7365 7276 _auditd {. serv
│ │ │ -001efc60: 6963 6520 7b27 6175 6469 7464 273a 0a20 ice {'auditd':.
│ │ │ -001efc70: 2020 2065 6e61 626c 6520 3d26 6774 3b20 enable =>
│ │ │ -001efc80: 7472 7565 2c0a 2020 2020 656e 7375 7265 true,. ensure
│ │ │ -001efc90: 203d 2667 743b 2027 7275 6e6e 696e 6727 => 'running'
│ │ │ -001efca0: 2c0a 2020 7d0a 7d0a 3c2f 636f 6465 3e3c ,. }.}.<
│ │ │ -001efcb0: 2f70 7265 3e3c 2f64 6976 3e3c 6120 636c /pre>Remediat
│ │ │ -001efd60: 696f 6e20 416e 7369 626c 6520 736e 6970 ion Ansible snip
│ │ │ -001efd70: 7065 7420 e287 b23c 2f61 3e3c 6272 3e3c pet ...
<
│ │ │ -001efd80: 6469 7620 636c 6173 733d 2270 616e 656c div class="panel
│ │ │ -001efd90: 2d63 6f6c 6c61 7073 6520 636f 6c6c 6170 -collapse collap
│ │ │ -001efda0: 7365 2220 6964 3d22 6964 3635 3822 3e3c se" id="id658"><
│ │ │ -001efdb0: 7461 626c 6520 636c 6173 733d 2274 6162 table class="tab
│ │ │ -001efdc0: 6c65 2074 6162 6c65 2d73 7472 6970 6564 le table-striped
│ │ │ -001efdd0: 2074 6162 6c65 2d62 6f72 6465 7265 6420 table-bordered
│ │ │ -001efde0: 7461 626c 652d 636f 6e64 656e 7365 6422 table-condensed"
│ │ │ -001efdf0: 3e3c 7472 3e3c 7468 3e43 6f6d 706c 6578 >| Complex
│ │ │ -001efe00: 6974 793a 3c2f 7468 3e3c 7464 3e6c 6f77 ity: | low
│ │ │ -001efe10: 3c2f 7464 3e3c 2f74 723e 3c74 723e 3c74 |
|---|
Disruption:| low |
│ │ │ -001efe40: 7472 3e3c 7472 3e3c 7468 3e52 6562 6f6f tr>
| Reboo
│ │ │ -001efe50: 743a 3c2f 7468 3e3c 7464 3e66 616c 7365 t: | false
│ │ │ -001efe60: 3c2f 7464 3e3c 2f74 723e 3c74 723e 3c74 |
|---|
Strategy:
│ │ │ -001efe80: 3c74 643e 656e 6162 6c65 3c2f 7464 3e3c | enable | <
│ │ │ -001efe90: 2f74 723e 3c2f 7461 626c 653e 3c70 7265 /tr>
- name: G
│ │ │ -001efeb0: 6174 6865 7220 7468 6520 7061 636b 6167 ather the packag
│ │ │ -001efec0: 6520 6661 6374 730a 2020 7061 636b 6167 e facts. packag
│ │ │ -001efed0: 655f 6661 6374 733a 0a20 2020 206d 616e e_facts:. man
│ │ │ -001efee0: 6167 6572 3a20 6175 746f 0a20 2074 6167 ager: auto. tag
│ │ │ -001efef0: 733a 0a20 202d 2043 4a49 532d 352e 342e s:. - CJIS-5.4.
│ │ │ -001eff00: 312e 310a 2020 2d20 4e49 5354 2d38 3030 1.1. - NIST-800
│ │ │ -001eff10: 2d31 3731 2d33 2e33 2e31 0a20 202d 204e -171-3.3.1. - N
│ │ │ -001eff20: 4953 542d 3830 302d 3137 312d 332e 332e IST-800-171-3.3.
│ │ │ -001eff30: 320a 2020 2d20 4e49 5354 2d38 3030 2d31 2. - NIST-800-1
│ │ │ -001eff40: 3731 2d33 2e33 2e36 0a20 202d 204e 4953 71-3.3.6. - NIS
│ │ │ -001eff50: 542d 3830 302d 3533 2d41 432d 3228 6729 T-800-53-AC-2(g)
│ │ │ +001ef990: 2122 3e52 656d 6564 6961 7469 6f6e 2041 !">Remediation A
│ │ │ +001ef9a0: 6e73 6962 6c65 2073 6e69 7070 6574 20e2 nsible snippet .
│ │ │ +001ef9b0: 87b2 3c2f 613e 3c62 723e 3c64 6976 2063 ..
│ │ │ +001efa30: 3c74 683e 436f 6d70 6c65 7869 7479 3a3c | Complexity:<
│ │ │ +001efa40: 2f74 683e 3c74 643e 6c6f 773c 2f74 643e /th> | low |
│ │ │ +001efa50: 3c2f 7472 3e3c 7472 3e3c 7468 3e44 6973
| Dis
│ │ │ +001efa60: 7275 7074 696f 6e3a 3c2f 7468 3e3c 7464 ruption: | low |
|---|
Reboot: | false |
│ │ │ +001efaa0: 3c2f 7472 3e3c 7472 3e3c 7468 3e53 7472 | Str
│ │ │ +001efab0: 6174 6567 793a 3c2f 7468 3e3c 7464 3e65 ategy: | e
│ │ │ +001efac0: 6e61 626c 653c 2f74 643e 3c2f 7472 3e3c nable |
<
│ │ │ +001efad0: 2f74 6162 6c65 3e3c 7072 653e 3c63 6f64 /table>- name: Gather
│ │ │ +001efaf0: 2074 6865 2070 6163 6b61 6765 2066 6163 the package fac
│ │ │ +001efb00: 7473 0a20 2070 6163 6b61 6765 5f66 6163 ts. package_fac
│ │ │ +001efb10: 7473 3a0a 2020 2020 6d61 6e61 6765 723a ts:. manager:
│ │ │ +001efb20: 2061 7574 6f0a 2020 7461 6773 3a0a 2020 auto. tags:.
│ │ │ +001efb30: 2d20 434a 4953 2d35 2e34 2e31 2e31 0a20 - CJIS-5.4.1.1.
│ │ │ +001efb40: 202d 204e 4953 542d 3830 302d 3137 312d - NIST-800-171-
│ │ │ +001efb50: 332e 332e 310a 2020 2d20 4e49 5354 2d38 3.3.1. - NIST-8
│ │ │ +001efb60: 3030 2d31 3731 2d33 2e33 2e32 0a20 202d 00-171-3.3.2. -
│ │ │ +001efb70: 204e 4953 542d 3830 302d 3137 312d 332e NIST-800-171-3.
│ │ │ +001efb80: 332e 360a 2020 2d20 4e49 5354 2d38 3030 3.6. - NIST-800
│ │ │ +001efb90: 2d35 332d 4143 2d32 2867 290a 2020 2d20 -53-AC-2(g). -
│ │ │ +001efba0: 4e49 5354 2d38 3030 2d35 332d 4143 2d36 NIST-800-53-AC-6
│ │ │ +001efbb0: 2839 290a 2020 2d20 4e49 5354 2d38 3030 (9). - NIST-800
│ │ │ +001efbc0: 2d35 332d 4155 2d31 300a 2020 2d20 4e49 -53-AU-10. - NI
│ │ │ +001efbd0: 5354 2d38 3030 2d35 332d 4155 2d31 3228 ST-800-53-AU-12(
│ │ │ +001efbe0: 6329 0a20 202d 204e 4953 542d 3830 302d c). - NIST-800-
│ │ │ +001efbf0: 3533 2d41 552d 3134 2831 290a 2020 2d20 53-AU-14(1). -
│ │ │ +001efc00: 4e49 5354 2d38 3030 2d35 332d 4155 2d32 NIST-800-53-AU-2
│ │ │ +001efc10: 2864 290a 2020 2d20 4e49 5354 2d38 3030 (d). - NIST-800
│ │ │ +001efc20: 2d35 332d 4155 2d33 0a20 202d 204e 4953 -53-AU-3. - NIS
│ │ │ +001efc30: 542d 3830 302d 3533 2d43 4d2d 3628 6129 T-800-53-CM-6(a)
│ │ │ +001efc40: 0a20 202d 204e 4953 542d 3830 302d 3533 . - NIST-800-53
│ │ │ +001efc50: 2d53 492d 3428 3233 290a 2020 2d20 5043 -SI-4(23). - PC
│ │ │ +001efc60: 492d 4453 532d 5265 712d 3130 2e31 0a20 I-DSS-Req-10.1.
│ │ │ +001efc70: 202d 2050 4349 2d44 5353 7634 2d31 302e - PCI-DSSv4-10.
│ │ │ +001efc80: 320a 2020 2d20 5043 492d 4453 5376 342d 2. - PCI-DSSv4-
│ │ │ +001efc90: 3130 2e32 2e31 0a20 202d 2065 6e61 626c 10.2.1. - enabl
│ │ │ +001efca0: 655f 7374 7261 7465 6779 0a20 202d 206c e_strategy. - l
│ │ │ +001efcb0: 6f77 5f63 6f6d 706c 6578 6974 790a 2020 ow_complexity.
│ │ │ +001efcc0: 2d20 6c6f 775f 6469 7372 7570 7469 6f6e - low_disruption
│ │ │ +001efcd0: 0a20 202d 206d 6564 6975 6d5f 7365 7665 . - medium_seve
│ │ │ +001efce0: 7269 7479 0a20 202d 206e 6f5f 7265 626f rity. - no_rebo
│ │ │ +001efcf0: 6f74 5f6e 6565 6465 640a 2020 2d20 7365 ot_needed. - se
│ │ │ +001efd00: 7276 6963 655f 6175 6469 7464 5f65 6e61 rvice_auditd_ena
│ │ │ +001efd10: 626c 6564 0a0a 2d20 6e61 6d65 3a20 456e bled..- name: En
│ │ │ +001efd20: 6162 6c65 2061 7564 6974 6420 5365 7276 able auditd Serv
│ │ │ +001efd30: 6963 6520 2d20 456e 6162 6c65 2073 6572 ice - Enable ser
│ │ │ +001efd40: 7669 6365 2061 7564 6974 640a 2020 626c vice auditd. bl
│ │ │ +001efd50: 6f63 6b3a 0a0a 2020 2d20 6e61 6d65 3a20 ock:.. - name:
│ │ │ +001efd60: 4761 7468 6572 2074 6865 2070 6163 6b61 Gather the packa
│ │ │ +001efd70: 6765 2066 6163 7473 0a20 2020 2061 6e73 ge facts. ans
│ │ │ +001efd80: 6962 6c65 2e62 7569 6c74 696e 2e70 6163 ible.builtin.pac
│ │ │ +001efd90: 6b61 6765 5f66 6163 7473 3a0a 2020 2020 kage_facts:.
│ │ │ +001efda0: 2020 6d61 6e61 6765 723a 2061 7574 6f0a manager: auto.
│ │ │ +001efdb0: 0a20 202d 206e 616d 653a 2045 6e61 626c . - name: Enabl
│ │ │ +001efdc0: 6520 6175 6469 7464 2053 6572 7669 6365 e auditd Service
│ │ │ +001efdd0: 202d 2045 6e61 626c 6520 5365 7276 6963 - Enable Servic
│ │ │ +001efde0: 6520 6175 6469 7464 0a20 2020 2061 6e73 e auditd. ans
│ │ │ +001efdf0: 6962 6c65 2e62 7569 6c74 696e 2e73 7973 ible.builtin.sys
│ │ │ +001efe00: 7465 6d64 3a0a 2020 2020 2020 6e61 6d65 temd:. name
│ │ │ +001efe10: 3a20 6175 6469 7464 0a20 2020 2020 2065 : auditd. e
│ │ │ +001efe20: 6e61 626c 6564 3a20 7472 7565 0a20 2020 nabled: true.
│ │ │ +001efe30: 2020 2073 7461 7465 3a20 7374 6172 7465 state: starte
│ │ │ +001efe40: 640a 2020 2020 2020 6d61 736b 6564 3a20 d. masked:
│ │ │ +001efe50: 6661 6c73 650a 2020 2020 7768 656e 3a0a false. when:.
│ │ │ +001efe60: 2020 2020 2d20 2722 6175 6469 7464 2220 - '"auditd"
│ │ │ +001efe70: 696e 2061 6e73 6962 6c65 5f66 6163 7473 in ansible_facts
│ │ │ +001efe80: 2e70 6163 6b61 6765 7327 0a20 2074 6167 .packages'. tag
│ │ │ +001efe90: 733a 0a20 202d 2043 4a49 532d 352e 342e s:. - CJIS-5.4.
│ │ │ +001efea0: 312e 310a 2020 2d20 4e49 5354 2d38 3030 1.1. - NIST-800
│ │ │ +001efeb0: 2d31 3731 2d33 2e33 2e31 0a20 202d 204e -171-3.3.1. - N
│ │ │ +001efec0: 4953 542d 3830 302d 3137 312d 332e 332e IST-800-171-3.3.
│ │ │ +001efed0: 320a 2020 2d20 4e49 5354 2d38 3030 2d31 2. - NIST-800-1
│ │ │ +001efee0: 3731 2d33 2e33 2e36 0a20 202d 204e 4953 71-3.3.6. - NIS
│ │ │ +001efef0: 542d 3830 302d 3533 2d41 432d 3228 6729 T-800-53-AC-2(g)
│ │ │ +001eff00: 0a20 202d 204e 4953 542d 3830 302d 3533 . - NIST-800-53
│ │ │ +001eff10: 2d41 432d 3628 3929 0a20 202d 204e 4953 -AC-6(9). - NIS
│ │ │ +001eff20: 542d 3830 302d 3533 2d41 552d 3130 0a20 T-800-53-AU-10.
│ │ │ +001eff30: 202d 204e 4953 542d 3830 302d 3533 2d41 - NIST-800-53-A
│ │ │ +001eff40: 552d 3132 2863 290a 2020 2d20 4e49 5354 U-12(c). - NIST
│ │ │ +001eff50: 2d38 3030 2d35 332d 4155 2d31 3428 3129 -800-53-AU-14(1)
│ │ │ 001eff60: 0a20 202d 204e 4953 542d 3830 302d 3533 . - NIST-800-53
│ │ │ -001eff70: 2d41 432d 3628 3929 0a20 202d 204e 4953 -AC-6(9). - NIS
│ │ │ -001eff80: 542d 3830 302d 3533 2d41 552d 3130 0a20 T-800-53-AU-10.
│ │ │ -001eff90: 202d 204e 4953 542d 3830 302d 3533 2d41 - NIST-800-53-A
│ │ │ -001effa0: 552d 3132 2863 290a 2020 2d20 4e49 5354 U-12(c). - NIST
│ │ │ -001effb0: 2d38 3030 2d35 332d 4155 2d31 3428 3129 -800-53-AU-14(1)
│ │ │ -001effc0: 0a20 202d 204e 4953 542d 3830 302d 3533 . - NIST-800-53
│ │ │ -001effd0: 2d41 552d 3228 6429 0a20 202d 204e 4953 -AU-2(d). - NIS
│ │ │ -001effe0: 542d 3830 302d 3533 2d41 552d 330a 2020 T-800-53-AU-3.
│ │ │ -001efff0: 2d20 4e49 5354 2d38 3030 2d35 332d 434d - NIST-800-53-CM
│ │ │ -001f0000: 2d36 2861 290a 2020 2d20 4e49 5354 2d38 -6(a). - NIST-8
│ │ │ -001f0010: 3030 2d35 332d 5349 2d34 2832 3329 0a20 00-53-SI-4(23).
│ │ │ -001f0020: 202d 2050 4349 2d44 5353 2d52 6571 2d31 - PCI-DSS-Req-1
│ │ │ -001f0030: 302e 310a 2020 2d20 5043 492d 4453 5376 0.1. - PCI-DSSv
│ │ │ -001f0040: 342d 3130 2e32 0a20 202d 2050 4349 2d44 4-10.2. - PCI-D
│ │ │ -001f0050: 5353 7634 2d31 302e 322e 310a 2020 2d20 SSv4-10.2.1. -
│ │ │ -001f0060: 656e 6162 6c65 5f73 7472 6174 6567 790a enable_strategy.
│ │ │ -001f0070: 2020 2d20 6c6f 775f 636f 6d70 6c65 7869 - low_complexi
│ │ │ -001f0080: 7479 0a20 202d 206c 6f77 5f64 6973 7275 ty. - low_disru
│ │ │ -001f0090: 7074 696f 6e0a 2020 2d20 6d65 6469 756d ption. - medium
│ │ │ -001f00a0: 5f73 6576 6572 6974 790a 2020 2d20 6e6f _severity. - no
│ │ │ -001f00b0: 5f72 6562 6f6f 745f 6e65 6564 6564 0a20 _reboot_needed.
│ │ │ -001f00c0: 202d 2073 6572 7669 6365 5f61 7564 6974 - service_audit
│ │ │ -001f00d0: 645f 656e 6162 6c65 640a 0a2d 206e 616d d_enabled..- nam
│ │ │ -001f00e0: 653a 2045 6e61 626c 6520 6175 6469 7464 e: Enable auditd
│ │ │ -001f00f0: 2053 6572 7669 6365 202d 2045 6e61 626c Service - Enabl
│ │ │ -001f0100: 6520 7365 7276 6963 6520 6175 6469 7464 e service auditd
│ │ │ -001f0110: 0a20 2062 6c6f 636b 3a0a 0a20 202d 206e . block:.. - n
│ │ │ -001f0120: 616d 653a 2047 6174 6865 7220 7468 6520 ame: Gather the
│ │ │ -001f0130: 7061 636b 6167 6520 6661 6374 730a 2020 package facts.
│ │ │ -001f0140: 2020 616e 7369 626c 652e 6275 696c 7469 ansible.builti
│ │ │ -001f0150: 6e2e 7061 636b 6167 655f 6661 6374 733a n.package_facts:
│ │ │ -001f0160: 0a20 2020 2020 206d 616e 6167 6572 3a20 . manager:
│ │ │ -001f0170: 6175 746f 0a0a 2020 2d20 6e61 6d65 3a20 auto.. - name:
│ │ │ -001f0180: 456e 6162 6c65 2061 7564 6974 6420 5365 Enable auditd Se
│ │ │ -001f0190: 7276 6963 6520 2d20 456e 6162 6c65 2053 rvice - Enable S
│ │ │ -001f01a0: 6572 7669 6365 2061 7564 6974 640a 2020 ervice auditd.
│ │ │ -001f01b0: 2020 616e 7369 626c 652e 6275 696c 7469 ansible.builti
│ │ │ -001f01c0: 6e2e 7379 7374 656d 643a 0a20 2020 2020 n.systemd:.
│ │ │ -001f01d0: 206e 616d 653a 2061 7564 6974 640a 2020 name: auditd.
│ │ │ -001f01e0: 2020 2020 656e 6162 6c65 643a 2074 7275 enabled: tru
│ │ │ -001f01f0: 650a 2020 2020 2020 7374 6174 653a 2073 e. state: s
│ │ │ -001f0200: 7461 7274 6564 0a20 2020 2020 206d 6173 tarted. mas
│ │ │ -001f0210: 6b65 643a 2066 616c 7365 0a20 2020 2077 ked: false. w
│ │ │ -001f0220: 6865 6e3a 0a20 2020 202d 2027 2261 7564 hen:. - '"aud
│ │ │ -001f0230: 6974 6422 2069 6e20 616e 7369 626c 655f itd" in ansible_
│ │ │ -001f0240: 6661 6374 732e 7061 636b 6167 6573 270a facts.packages'.
│ │ │ -001f0250: 2020 7461 6773 3a0a 2020 2d20 434a 4953 tags:. - CJIS
│ │ │ -001f0260: 2d35 2e34 2e31 2e31 0a20 202d 204e 4953 -5.4.1.1. - NIS
│ │ │ -001f0270: 542d 3830 302d 3137 312d 332e 332e 310a T-800-171-3.3.1.
│ │ │ -001f0280: 2020 2d20 4e49 5354 2d38 3030 2d31 3731 - NIST-800-171
│ │ │ -001f0290: 2d33 2e33 2e32 0a20 202d 204e 4953 542d -3.3.2. - NIST-
│ │ │ -001f02a0: 3830 302d 3137 312d 332e 332e 360a 2020 800-171-3.3.6.
│ │ │ -001f02b0: 2d20 4e49 5354 2d38 3030 2d35 332d 4143 - NIST-800-53-AC
│ │ │ -001f02c0: 2d32 2867 290a 2020 2d20 4e49 5354 2d38 -2(g). - NIST-8
│ │ │ -001f02d0: 3030 2d35 332d 4143 2d36 2839 290a 2020 00-53-AC-6(9).
│ │ │ -001f02e0: 2d20 4e49 5354 2d38 3030 2d35 332d 4155 - NIST-800-53-AU
│ │ │ -001f02f0: 2d31 300a 2020 2d20 4e49 5354 2d38 3030 -10. - NIST-800
│ │ │ -001f0300: 2d35 332d 4155 2d31 3228 6329 0a20 202d -53-AU-12(c). -
│ │ │ -001f0310: 204e 4953 542d 3830 302d 3533 2d41 552d NIST-800-53-AU-
│ │ │ -001f0320: 3134 2831 290a 2020 2d20 4e49 5354 2d38 14(1). - NIST-8
│ │ │ -001f0330: 3030 2d35 332d 4155 2d32 2864 290a 2020 00-53-AU-2(d).
│ │ │ -001f0340: 2d20 4e49 5354 2d38 3030 2d35 332d 4155 - NIST-800-53-AU
│ │ │ -001f0350: 2d33 0a20 202d 204e 4953 542d 3830 302d -3. - NIST-800-
│ │ │ -001f0360: 3533 2d43 4d2d 3628 6129 0a20 202d 204e 53-CM-6(a). - N
│ │ │ -001f0370: 4953 542d 3830 302d 3533 2d53 492d 3428 IST-800-53-SI-4(
│ │ │ -001f0380: 3233 290a 2020 2d20 5043 492d 4453 532d 23). - PCI-DSS-
│ │ │ -001f0390: 5265 712d 3130 2e31 0a20 202d 2050 4349 Req-10.1. - PCI
│ │ │ -001f03a0: 2d44 5353 7634 2d31 302e 320a 2020 2d20 -DSSv4-10.2. -
│ │ │ -001f03b0: 5043 492d 4453 5376 342d 3130 2e32 2e31 PCI-DSSv4-10.2.1
│ │ │ -001f03c0: 0a20 202d 2065 6e61 626c 655f 7374 7261 . - enable_stra
│ │ │ -001f03d0: 7465 6779 0a20 202d 206c 6f77 5f63 6f6d tegy. - low_com
│ │ │ -001f03e0: 706c 6578 6974 790a 2020 2d20 6c6f 775f plexity. - low_
│ │ │ -001f03f0: 6469 7372 7570 7469 6f6e 0a20 202d 206d disruption. - m
│ │ │ -001f0400: 6564 6975 6d5f 7365 7665 7269 7479 0a20 edium_severity.
│ │ │ -001f0410: 202d 206e 6f5f 7265 626f 6f74 5f6e 6565 - no_reboot_nee
│ │ │ -001f0420: 6465 640a 2020 2d20 7365 7276 6963 655f ded. - service_
│ │ │ -001f0430: 6175 6469 7464 5f65 6e61 626c 6564 0a20 auditd_enabled.
│ │ │ -001f0440: 202d 2073 7065 6369 616c 5f73 6572 7669 - special_servi
│ │ │ -001f0450: 6365 5f62 6c6f 636b 0a20 2077 6865 6e3a ce_block. when:
│ │ │ -001f0460: 0a20 202d 2027 226c 696e 7578 2d62 6173 . - '"linux-bas
│ │ │ -001f0470: 6522 2069 6e20 616e 7369 626c 655f 6661 e" in ansible_fa
│ │ │ -001f0480: 6374 732e 7061 636b 6167 6573 270a 2020 cts.packages'.
│ │ │ -001f0490: 2d20 2722 6175 6469 7464 2220 696e 2061 - '"auditd" in a
│ │ │ -001f04a0: 6e73 6962 6c65 5f66 6163 7473 2e70 6163 nsible_facts.pac
│ │ │ -001f04b0: 6b61 6765 7327 0a3c 2f63 6f64 653e 3c2f kages'.
│ │ │ +001eff70: 2d41 552d 3228 6429 0a20 202d 204e 4953 -AU-2(d). - NIS
│ │ │ +001eff80: 542d 3830 302d 3533 2d41 552d 330a 2020 T-800-53-AU-3.
│ │ │ +001eff90: 2d20 4e49 5354 2d38 3030 2d35 332d 434d - NIST-800-53-CM
│ │ │ +001effa0: 2d36 2861 290a 2020 2d20 4e49 5354 2d38 -6(a). - NIST-8
│ │ │ +001effb0: 3030 2d35 332d 5349 2d34 2832 3329 0a20 00-53-SI-4(23).
│ │ │ +001effc0: 202d 2050 4349 2d44 5353 2d52 6571 2d31 - PCI-DSS-Req-1
│ │ │ +001effd0: 302e 310a 2020 2d20 5043 492d 4453 5376 0.1. - PCI-DSSv
│ │ │ +001effe0: 342d 3130 2e32 0a20 202d 2050 4349 2d44 4-10.2. - PCI-D
│ │ │ +001efff0: 5353 7634 2d31 302e 322e 310a 2020 2d20 SSv4-10.2.1. -
│ │ │ +001f0000: 656e 6162 6c65 5f73 7472 6174 6567 790a enable_strategy.
│ │ │ +001f0010: 2020 2d20 6c6f 775f 636f 6d70 6c65 7869 - low_complexi
│ │ │ +001f0020: 7479 0a20 202d 206c 6f77 5f64 6973 7275 ty. - low_disru
│ │ │ +001f0030: 7074 696f 6e0a 2020 2d20 6d65 6469 756d ption. - medium
│ │ │ +001f0040: 5f73 6576 6572 6974 790a 2020 2d20 6e6f _severity. - no
│ │ │ +001f0050: 5f72 6562 6f6f 745f 6e65 6564 6564 0a20 _reboot_needed.
│ │ │ +001f0060: 202d 2073 6572 7669 6365 5f61 7564 6974 - service_audit
│ │ │ +001f0070: 645f 656e 6162 6c65 640a 2020 2d20 7370 d_enabled. - sp
│ │ │ +001f0080: 6563 6961 6c5f 7365 7276 6963 655f 626c ecial_service_bl
│ │ │ +001f0090: 6f63 6b0a 2020 7768 656e 3a0a 2020 2d20 ock. when:. -
│ │ │ +001f00a0: 2722 6c69 6e75 782d 6261 7365 2220 696e '"linux-base" in
│ │ │ +001f00b0: 2061 6e73 6962 6c65 5f66 6163 7473 2e70 ansible_facts.p
│ │ │ +001f00c0: 6163 6b61 6765 7327 0a20 202d 2027 2261 ackages'. - '"a
│ │ │ +001f00d0: 7564 6974 6422 2069 6e20 616e 7369 626c uditd" in ansibl
│ │ │ +001f00e0: 655f 6661 6374 732e 7061 636b 6167 6573 e_facts.packages
│ │ │ +001f00f0: 270a 3c2f 636f 6465 3e3c 2f70 7265 3e3c '.
<
│ │ │ +001f0100: 2f64 6976 3e3c 6120 636c 6173 733d 2262 /div>Remediation Pu
│ │ │ +001f01b0: 7070 6574 2073 6e69 7070 6574 20e2 87b2 ppet snippet ...
│ │ │ +001f01c0: 3c2f 613e 3c62 723e 3c64 6976 2063 6c61
Complexity:| low |
│ │ │ +001f0260: 7472 3e3c 7472 3e3c 7468 3e44 6973 7275 tr>
| Disru
│ │ │ +001f0270: 7074 696f 6e3a 3c2f 7468 3e3c 7464 3e6c ption: | l
│ │ │ +001f0280: 6f77 3c2f 7464 3e3c 2f74 723e 3c74 723e ow |
|---|
│ │ │ +001f0290: 3c74 683e 5265 626f 6f74 3a3c 2f74 683e | Reboot: |
│ │ │ +001f02a0: 3c74 643e 6661 6c73 653c 2f74 643e 3c2f false |
│ │ │ +001f02b0: 7472 3e3c 7472 3e3c 7468 3e53 7472 6174 tr>
| Strat
│ │ │ +001f02c0: 6567 793a 3c2f 7468 3e3c 7464 3e65 6e61 egy: | ena
│ │ │ +001f02d0: 626c 653c 2f74 643e 3c2f 7472 3e3c 2f74 ble |
|---|
│ │ │ +001f02f0: 696e 636c 7564 6520 656e 6162 6c65 5f61 include enable_a
│ │ │ +001f0300: 7564 6974 640a 0a63 6c61 7373 2065 6e61 uditd..class ena
│ │ │ +001f0310: 626c 655f 6175 6469 7464 207b 0a20 2073 ble_auditd {. s
│ │ │ +001f0320: 6572 7669 6365 207b 2761 7564 6974 6427 ervice {'auditd'
│ │ │ +001f0330: 3a0a 2020 2020 656e 6162 6c65 203d 2667 :. enable =&g
│ │ │ +001f0340: 743b 2074 7275 652c 0a20 2020 2065 6e73 t; true,. ens
│ │ │ +001f0350: 7572 6520 3d26 6774 3b20 2772 756e 6e69 ure => 'runni
│ │ │ +001f0360: 6e67 272c 0a20 207d 0a7d 0a3c 2f63 6f64 ng',. }.}.
Remed
│ │ │ +001f0420: 6961 7469 6f6e 204f 5342 7569 6c64 2042 iation OSBuild B
│ │ │ +001f0430: 6c75 6570 7269 6e74 2073 6e69 7070 6574 lueprint snippet
│ │ │ +001f0440: 20e2 87b2 3c2f 613e 3c62 723e 3c64 6976 ...
.[customi
│ │ │ +001f0490: 7a61 7469 6f6e 732e 7365 7276 6963 6573 zations.services
│ │ │ +001f04a0: 5d0a 656e 6162 6c65 6420 3d20 5b22 6175 ].enabled = ["au
│ │ │ +001f04b0: 6469 7464 225d 0a3c 2f63 6f64 653e 3c2f ditd"].
│ │ │ 001f04c0: 7072 653e 3c2f 6469 763e 3c61 2063 6c61 pre>
'installed',
│ │ │ │ - }
│ │ │ │ -}
│ │ │ │ _R_e_m_e_d_i_a_t_i_o_n_ _A_n_s_i_b_l_e_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ CCoommpplleexxiittyy:: low
│ │ │ │ DDiissrruuppttiioonn:: low
│ │ │ │ RReebboooott:: false
│ │ │ │ SSttrraatteeggyy:: enable
│ │ │ │ - name: Gather the package facts
│ │ │ │ package_facts:
│ │ │ │ @@ -165,14 +148,31 @@
│ │ │ │ - PCI-DSSv4-11.5.2
│ │ │ │ - enable_strategy
│ │ │ │ - low_complexity
│ │ │ │ - low_disruption
│ │ │ │ - medium_severity
│ │ │ │ - no_reboot_needed
│ │ │ │ - package_aide_installed
│ │ │ │ +_R_e_m_e_d_i_a_t_i_o_n_ _P_u_p_p_e_t_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ +CCoommpplleexxiittyy:: low
│ │ │ │ +DDiissrruuppttiioonn:: low
│ │ │ │ +RReebboooott:: false
│ │ │ │ +SSttrraatteeggyy:: enable
│ │ │ │ +include install_aide
│ │ │ │ +
│ │ │ │ +class install_aide {
│ │ │ │ + package { 'aide':
│ │ │ │ + ensure => 'installed',
│ │ │ │ + }
│ │ │ │ +}
│ │ │ │ +_R_e_m_e_d_i_a_t_i_o_n_ _O_S_B_u_i_l_d_ _B_l_u_e_p_r_i_n_t_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ +
│ │ │ │ +[[packages]]
│ │ │ │ +name = "aide"
│ │ │ │ +version = "*"
│ │ │ │ _R_e_m_e_d_i_a_t_i_o_n_ _S_h_e_l_l_ _s_c_r_i_p_t_ _⇲
│ │ │ │ CCoommpplleexxiittyy:: low
│ │ │ │ DDiissrruuppttiioonn:: low
│ │ │ │ RReebboooott:: false
│ │ │ │ SSttrraatteeggyy:: enable
│ │ │ │ # Remediation is applicable only in certain platforms
│ │ │ │ if dpkg-query --show --showformat='${db:Status-Status}' 'linux-base' 2>/dev/null | grep -
│ │ │ │ @@ -572,31 +572,14 @@
│ │ │ │ _n_i_s_t CM-6(a)
│ │ │ │ _o_s_p_p FMT_MOF_EXT.1
│ │ │ │ _o_s_-_s_r_g SRG-OS-000324-GPOS-00125
│ │ │ │ References: _a_n_s_s_i R33
│ │ │ │ _c_i_s 5.2.1
│ │ │ │ _i_s_m 1386
│ │ │ │ _p_c_i_d_s_s_4 2.2.6, 2.2
│ │ │ │ -_R_e_m_e_d_i_a_t_i_o_n_ _O_S_B_u_i_l_d_ _B_l_u_e_p_r_i_n_t_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ -
│ │ │ │ -[[packages]]
│ │ │ │ -name = "sudo"
│ │ │ │ -version = "*"
│ │ │ │ -_R_e_m_e_d_i_a_t_i_o_n_ _P_u_p_p_e_t_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ -CCoommpplleexxiittyy:: low
│ │ │ │ -DDiissrruuppttiioonn:: low
│ │ │ │ -RReebboooott:: false
│ │ │ │ -SSttrraatteeggyy:: enable
│ │ │ │ -include install_sudo
│ │ │ │ -
│ │ │ │ -class install_sudo {
│ │ │ │ - package { 'sudo':
│ │ │ │ - ensure => 'installed',
│ │ │ │ - }
│ │ │ │ -}
│ │ │ │ _R_e_m_e_d_i_a_t_i_o_n_ _A_n_s_i_b_l_e_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ CCoommpplleexxiittyy:: low
│ │ │ │ DDiissrruuppttiioonn:: low
│ │ │ │ RReebboooott:: false
│ │ │ │ SSttrraatteeggyy:: enable
│ │ │ │ - name: Gather the package facts
│ │ │ │ package_facts:
│ │ │ │ @@ -623,14 +606,31 @@
│ │ │ │ - PCI-DSSv4-2.2.6
│ │ │ │ - enable_strategy
│ │ │ │ - low_complexity
│ │ │ │ - low_disruption
│ │ │ │ - medium_severity
│ │ │ │ - no_reboot_needed
│ │ │ │ - package_sudo_installed
│ │ │ │ +_R_e_m_e_d_i_a_t_i_o_n_ _P_u_p_p_e_t_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ +CCoommpplleexxiittyy:: low
│ │ │ │ +DDiissrruuppttiioonn:: low
│ │ │ │ +RReebboooott:: false
│ │ │ │ +SSttrraatteeggyy:: enable
│ │ │ │ +include install_sudo
│ │ │ │ +
│ │ │ │ +class install_sudo {
│ │ │ │ + package { 'sudo':
│ │ │ │ + ensure => 'installed',
│ │ │ │ + }
│ │ │ │ +}
│ │ │ │ +_R_e_m_e_d_i_a_t_i_o_n_ _O_S_B_u_i_l_d_ _B_l_u_e_p_r_i_n_t_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ +
│ │ │ │ +[[packages]]
│ │ │ │ +name = "sudo"
│ │ │ │ +version = "*"
│ │ │ │ _R_e_m_e_d_i_a_t_i_o_n_ _S_h_e_l_l_ _s_c_r_i_p_t_ _⇲
│ │ │ │ CCoommpplleexxiittyy:: low
│ │ │ │ DDiissrruuppttiioonn:: low
│ │ │ │ RReebboooott:: false
│ │ │ │ SSttrraatteeggyy:: enable
│ │ │ │ # Remediation is applicable only in certain platforms
│ │ │ │ if dpkg-query --show --showformat='${db:Status-Status}' 'linux-base' 2>/dev/null | grep -
│ │ │ │ @@ -3732,31 +3732,14 @@
│ │ │ │ Rationale: password in resisting attempts at guessing and brute-force attacks. "pwquality" enforces
│ │ │ │ complex password construction configuration and has the ability to limit brute-force
│ │ │ │ attacks on the system.
│ │ │ │ Severity: medium
│ │ │ │ Rule ID: xccdf_org.ssgproject.content_rule_package_pam_pwquality_installed
│ │ │ │ References: _o_s_-_s_r_g SRG-OS-000480-GPOS-00225
│ │ │ │ _c_i_s 5.3.1.3
│ │ │ │ -_R_e_m_e_d_i_a_t_i_o_n_ _O_S_B_u_i_l_d_ _B_l_u_e_p_r_i_n_t_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ -
│ │ │ │ -[[packages]]
│ │ │ │ -name = "libpam-pwquality"
│ │ │ │ -version = "*"
│ │ │ │ -_R_e_m_e_d_i_a_t_i_o_n_ _P_u_p_p_e_t_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ -CCoommpplleexxiittyy:: low
│ │ │ │ -DDiissrruuppttiioonn:: low
│ │ │ │ -RReebboooott:: false
│ │ │ │ -SSttrraatteeggyy:: enable
│ │ │ │ -include install_libpam-pwquality
│ │ │ │ -
│ │ │ │ -class install_libpam-pwquality {
│ │ │ │ - package { 'libpam-pwquality':
│ │ │ │ - ensure => 'installed',
│ │ │ │ - }
│ │ │ │ -}
│ │ │ │ _R_e_m_e_d_i_a_t_i_o_n_ _A_n_s_i_b_l_e_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ CCoommpplleexxiittyy:: low
│ │ │ │ DDiissrruuppttiioonn:: low
│ │ │ │ RReebboooott:: false
│ │ │ │ SSttrraatteeggyy:: enable
│ │ │ │ - name: Gather the package facts
│ │ │ │ package_facts:
│ │ │ │ @@ -3777,14 +3760,31 @@
│ │ │ │ tags:
│ │ │ │ - enable_strategy
│ │ │ │ - low_complexity
│ │ │ │ - low_disruption
│ │ │ │ - medium_severity
│ │ │ │ - no_reboot_needed
│ │ │ │ - package_pam_pwquality_installed
│ │ │ │ +_R_e_m_e_d_i_a_t_i_o_n_ _P_u_p_p_e_t_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ +CCoommpplleexxiittyy:: low
│ │ │ │ +DDiissrruuppttiioonn:: low
│ │ │ │ +RReebboooott:: false
│ │ │ │ +SSttrraatteeggyy:: enable
│ │ │ │ +include install_libpam-pwquality
│ │ │ │ +
│ │ │ │ +class install_libpam-pwquality {
│ │ │ │ + package { 'libpam-pwquality':
│ │ │ │ + ensure => 'installed',
│ │ │ │ + }
│ │ │ │ +}
│ │ │ │ +_R_e_m_e_d_i_a_t_i_o_n_ _O_S_B_u_i_l_d_ _B_l_u_e_p_r_i_n_t_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ +
│ │ │ │ +[[packages]]
│ │ │ │ +name = "libpam-pwquality"
│ │ │ │ +version = "*"
│ │ │ │ _R_e_m_e_d_i_a_t_i_o_n_ _S_h_e_l_l_ _s_c_r_i_p_t_ _⇲
│ │ │ │ CCoommpplleexxiittyy:: low
│ │ │ │ DDiissrruuppttiioonn:: low
│ │ │ │ RReebboooott:: false
│ │ │ │ SSttrraatteeggyy:: enable
│ │ │ │ # Remediation is applicable only in certain platforms
│ │ │ │ if dpkg-query --show --showformat='${db:Status-Status}' 'libpam-runtime' 2>/dev/null | grep -
│ │ │ │ @@ -26989,27 +26989,14 @@
│ │ │ │ 2.5, SR 2.6, SR 2.7, SR 7.6
│ │ │ │ _i_s_o_2_7_0_0_1_-_2_0_1_3 A.12.1.2, A.12.5.1, A.12.6.2, A.14.2.2, A.14.2.3, A.14.2.4, A.9.1.2
│ │ │ │ _n_i_s_t CM-7(a), CM-7(b), CM-6(a)
│ │ │ │ _n_i_s_t_-_c_s_f PR.IP-1, PR.PT-3
│ │ │ │ _a_n_s_s_i R62
│ │ │ │ _c_i_s 2.1.3
│ │ │ │ _p_c_i_d_s_s_4 2.2.4, 2.2
│ │ │ │ -_R_e_m_e_d_i_a_t_i_o_n_ _P_u_p_p_e_t_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ -CCoommpplleexxiittyy:: low
│ │ │ │ -DDiissrruuppttiioonn:: low
│ │ │ │ -RReebboooott:: false
│ │ │ │ -SSttrraatteeggyy:: disable
│ │ │ │ -
│ │ │ │ -include remove_dhcp
│ │ │ │ -
│ │ │ │ -class remove_dhcp {
│ │ │ │ - package { 'dhcp':
│ │ │ │ - ensure => 'purged',
│ │ │ │ - }
│ │ │ │ -}
│ │ │ │ _R_e_m_e_d_i_a_t_i_o_n_ _A_n_s_i_b_l_e_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ CCoommpplleexxiittyy:: low
│ │ │ │ DDiissrruuppttiioonn:: low
│ │ │ │ RReebboooott:: false
│ │ │ │ SSttrraatteeggyy:: disable
│ │ │ │ - name: 'Uninstall DHCP Server Package: Ensure dhcp is removed'
│ │ │ │ ansible.builtin.package:
│ │ │ │ @@ -27023,14 +27010,27 @@
│ │ │ │ - PCI-DSSv4-2.2.4
│ │ │ │ - disable_strategy
│ │ │ │ - low_complexity
│ │ │ │ - low_disruption
│ │ │ │ - medium_severity
│ │ │ │ - no_reboot_needed
│ │ │ │ - package_dhcp_removed
│ │ │ │ +_R_e_m_e_d_i_a_t_i_o_n_ _P_u_p_p_e_t_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ +CCoommpplleexxiittyy:: low
│ │ │ │ +DDiissrruuppttiioonn:: low
│ │ │ │ +RReebboooott:: false
│ │ │ │ +SSttrraatteeggyy:: disable
│ │ │ │ +
│ │ │ │ +include remove_dhcp
│ │ │ │ +
│ │ │ │ +class remove_dhcp {
│ │ │ │ + package { 'dhcp':
│ │ │ │ + ensure => 'purged',
│ │ │ │ + }
│ │ │ │ +}
│ │ │ │ _R_e_m_e_d_i_a_t_i_o_n_ _S_h_e_l_l_ _s_c_r_i_p_t_ _⇲
│ │ │ │ CCoommpplleexxiittyy:: low
│ │ │ │ DDiissrruuppttiioonn:: low
│ │ │ │ RReebboooott:: false
│ │ │ │ SSttrraatteeggyy:: disable
│ │ │ │
│ │ │ │ # CAUTION: This remediation script will remove dhcp
│ │ │ │ @@ -27059,27 +27059,14 @@
│ │ │ │ ****** RRuullee? ? UUnniinnssttaallll kkeeaa PPaacckkaaggee ? ? _[[_rr_ee_ff_]] ******
│ │ │ │ If the system does not need to act as a DHCP server, the kea package can be uninstalled.
│ │ │ │ Rationale: Removing the DHCP server ensures that it cannot be easily or accidentally reactivated and
│ │ │ │ disrupt network operation.
│ │ │ │ Severity: medium
│ │ │ │ Rule ID: xccdf_org.ssgproject.content_rule_package_kea_removed
│ │ │ │ References: _a_n_s_s_i R62
│ │ │ │ -_R_e_m_e_d_i_a_t_i_o_n_ _P_u_p_p_e_t_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ -CCoommpplleexxiittyy:: low
│ │ │ │ -DDiissrruuppttiioonn:: low
│ │ │ │ -RReebboooott:: false
│ │ │ │ -SSttrraatteeggyy:: disable
│ │ │ │ -
│ │ │ │ -include remove_kea
│ │ │ │ -
│ │ │ │ -class remove_kea {
│ │ │ │ - package { 'kea':
│ │ │ │ - ensure => 'purged',
│ │ │ │ - }
│ │ │ │ -}
│ │ │ │ _R_e_m_e_d_i_a_t_i_o_n_ _A_n_s_i_b_l_e_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ CCoommpplleexxiittyy:: low
│ │ │ │ DDiissrruuppttiioonn:: low
│ │ │ │ RReebboooott:: false
│ │ │ │ SSttrraatteeggyy:: disable
│ │ │ │ - name: 'Uninstall kea Package: Ensure kea is removed'
│ │ │ │ ansible.builtin.package:
│ │ │ │ @@ -27088,14 +27075,27 @@
│ │ │ │ tags:
│ │ │ │ - disable_strategy
│ │ │ │ - low_complexity
│ │ │ │ - low_disruption
│ │ │ │ - medium_severity
│ │ │ │ - no_reboot_needed
│ │ │ │ - package_kea_removed
│ │ │ │ +_R_e_m_e_d_i_a_t_i_o_n_ _P_u_p_p_e_t_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ +CCoommpplleexxiittyy:: low
│ │ │ │ +DDiissrruuppttiioonn:: low
│ │ │ │ +RReebboooott:: false
│ │ │ │ +SSttrraatteeggyy:: disable
│ │ │ │ +
│ │ │ │ +include remove_kea
│ │ │ │ +
│ │ │ │ +class remove_kea {
│ │ │ │ + package { 'kea':
│ │ │ │ + ensure => 'purged',
│ │ │ │ + }
│ │ │ │ +}
│ │ │ │ _R_e_m_e_d_i_a_t_i_o_n_ _S_h_e_l_l_ _s_c_r_i_p_t_ _⇲
│ │ │ │ CCoommpplleexxiittyy:: low
│ │ │ │ DDiissrruuppttiioonn:: low
│ │ │ │ RReebboooott:: false
│ │ │ │ SSttrraatteeggyy:: disable
│ │ │ │
│ │ │ │ # CAUTION: This remediation script will remove kea
│ │ │ │ @@ -27303,27 +27303,14 @@
│ │ │ │ _i_s_a_-_6_2_4_4_3_-_2_0_1_3 1.5, SR 1.6, SR 1.7, SR 1.8, SR 1.9, SR 2.1, SR 2.2, SR 2.3, SR 2.4, SR
│ │ │ │ 2.5, SR 2.6, SR 2.7, SR 7.6
│ │ │ │ _i_s_o_2_7_0_0_1_-_2_0_1_3 A.12.1.2, A.12.5.1, A.12.6.2, A.14.2.2, A.14.2.3, A.14.2.4, A.9.1.2
│ │ │ │ _n_i_s_t CM-7(a), CM-7(b), CM-6(a)
│ │ │ │ _n_i_s_t_-_c_s_f PR.IP-1, PR.PT-3
│ │ │ │ _o_s_-_s_r_g SRG-OS-000480-GPOS-00227, SRG-OS-000095-GPOS-00049
│ │ │ │ _a_n_s_s_i R62
│ │ │ │ -_R_e_m_e_d_i_a_t_i_o_n_ _P_u_p_p_e_t_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ -CCoommpplleexxiittyy:: low
│ │ │ │ -DDiissrruuppttiioonn:: low
│ │ │ │ -RReebboooott:: false
│ │ │ │ -SSttrraatteeggyy:: disable
│ │ │ │ -
│ │ │ │ -include remove_sendmail
│ │ │ │ -
│ │ │ │ -class remove_sendmail {
│ │ │ │ - package { 'sendmail':
│ │ │ │ - ensure => 'purged',
│ │ │ │ - }
│ │ │ │ -}
│ │ │ │ _R_e_m_e_d_i_a_t_i_o_n_ _A_n_s_i_b_l_e_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ CCoommpplleexxiittyy:: low
│ │ │ │ DDiissrruuppttiioonn:: low
│ │ │ │ RReebboooott:: false
│ │ │ │ SSttrraatteeggyy:: disable
│ │ │ │ - name: Gather the package facts
│ │ │ │ package_facts:
│ │ │ │ @@ -27350,14 +27337,27 @@
│ │ │ │ - NIST-800-53-CM-7(b)
│ │ │ │ - disable_strategy
│ │ │ │ - low_complexity
│ │ │ │ - low_disruption
│ │ │ │ - medium_severity
│ │ │ │ - no_reboot_needed
│ │ │ │ - package_sendmail_removed
│ │ │ │ +_R_e_m_e_d_i_a_t_i_o_n_ _P_u_p_p_e_t_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ +CCoommpplleexxiittyy:: low
│ │ │ │ +DDiissrruuppttiioonn:: low
│ │ │ │ +RReebboooott:: false
│ │ │ │ +SSttrraatteeggyy:: disable
│ │ │ │ +
│ │ │ │ +include remove_sendmail
│ │ │ │ +
│ │ │ │ +class remove_sendmail {
│ │ │ │ + package { 'sendmail':
│ │ │ │ + ensure => 'purged',
│ │ │ │ + }
│ │ │ │ +}
│ │ │ │ _R_e_m_e_d_i_a_t_i_o_n_ _S_h_e_l_l_ _s_c_r_i_p_t_ _⇲
│ │ │ │ CCoommpplleexxiittyy:: low
│ │ │ │ DDiissrruuppttiioonn:: low
│ │ │ │ RReebboooott:: false
│ │ │ │ SSttrraatteeggyy:: disable
│ │ │ │ # Remediation is applicable only in certain platforms
│ │ │ │ if dpkg-query --show --showformat='${db:Status-Status}' 'linux-base' 2>/dev/null | grep -
│ │ │ │ @@ -27740,27 +27740,14 @@
│ │ │ │ A.14.2.2, A.14.2.3, A.14.2.4, A.6.2.1, A.6.2.2, A.9.1.2
│ │ │ │ _n_i_s_t CM-7(a), CM-7(b), CM-6(a)
│ │ │ │ _n_i_s_t_-_c_s_f PR.AC-3, PR.IP-1, PR.PT-3, PR.PT-4
│ │ │ │ _a_n_s_s_i R62
│ │ │ │ _c_i_s 2.1.19
│ │ │ │ _i_s_m 1409
│ │ │ │ _p_c_i_d_s_s_4 2.2.4, 2.2
│ │ │ │ -_R_e_m_e_d_i_a_t_i_o_n_ _P_u_p_p_e_t_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ -CCoommpplleexxiittyy:: low
│ │ │ │ -DDiissrruuppttiioonn:: low
│ │ │ │ -RReebboooott:: false
│ │ │ │ -SSttrraatteeggyy:: disable
│ │ │ │ -
│ │ │ │ -include remove_xinetd
│ │ │ │ -
│ │ │ │ -class remove_xinetd {
│ │ │ │ - package { 'xinetd':
│ │ │ │ - ensure => 'purged',
│ │ │ │ - }
│ │ │ │ -}
│ │ │ │ _R_e_m_e_d_i_a_t_i_o_n_ _A_n_s_i_b_l_e_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ CCoommpplleexxiittyy:: low
│ │ │ │ DDiissrruuppttiioonn:: low
│ │ │ │ RReebboooott:: false
│ │ │ │ SSttrraatteeggyy:: disable
│ │ │ │ - name: Gather the package facts
│ │ │ │ package_facts:
│ │ │ │ @@ -27792,14 +27779,27 @@
│ │ │ │ - PCI-DSSv4-2.2.4
│ │ │ │ - disable_strategy
│ │ │ │ - low_complexity
│ │ │ │ - low_disruption
│ │ │ │ - low_severity
│ │ │ │ - no_reboot_needed
│ │ │ │ - package_xinetd_removed
│ │ │ │ +_R_e_m_e_d_i_a_t_i_o_n_ _P_u_p_p_e_t_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ +CCoommpplleexxiittyy:: low
│ │ │ │ +DDiissrruuppttiioonn:: low
│ │ │ │ +RReebboooott:: false
│ │ │ │ +SSttrraatteeggyy:: disable
│ │ │ │ +
│ │ │ │ +include remove_xinetd
│ │ │ │ +
│ │ │ │ +class remove_xinetd {
│ │ │ │ + package { 'xinetd':
│ │ │ │ + ensure => 'purged',
│ │ │ │ + }
│ │ │ │ +}
│ │ │ │ _R_e_m_e_d_i_a_t_i_o_n_ _S_h_e_l_l_ _s_c_r_i_p_t_ _⇲
│ │ │ │ CCoommpplleexxiittyy:: low
│ │ │ │ DDiissrruuppttiioonn:: low
│ │ │ │ RReebboooott:: false
│ │ │ │ SSttrraatteeggyy:: disable
│ │ │ │ # Remediation is applicable only in certain platforms
│ │ │ │ if dpkg-query --show --showformat='${db:Status-Status}' 'linux-base' 2>/dev/null | grep -
│ │ │ │ @@ -27848,27 +27848,14 @@
│ │ │ │ Severity: unknown
│ │ │ │ Rule ID: xccdf_org.ssgproject.content_rule_package_ypbind_removed
│ │ │ │ _h_i_p_a_a 164.308(a)(4)(i), 164.308(b)(1), 164.308(b)(3), 164.310(b), 164.312(e)(1),
│ │ │ │ 164.312(e)(2)(ii)
│ │ │ │ References: _a_n_s_s_i R62
│ │ │ │ _i_s_m 1409
│ │ │ │ _p_c_i_d_s_s_4 2.2.4, 2.2
│ │ │ │ -_R_e_m_e_d_i_a_t_i_o_n_ _P_u_p_p_e_t_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ -CCoommpplleexxiittyy:: low
│ │ │ │ -DDiissrruuppttiioonn:: low
│ │ │ │ -RReebboooott:: false
│ │ │ │ -SSttrraatteeggyy:: disable
│ │ │ │ -
│ │ │ │ -include remove_ypbind-mt
│ │ │ │ -
│ │ │ │ -class remove_ypbind-mt {
│ │ │ │ - package { 'ypbind-mt':
│ │ │ │ - ensure => 'purged',
│ │ │ │ - }
│ │ │ │ -}
│ │ │ │ _R_e_m_e_d_i_a_t_i_o_n_ _A_n_s_i_b_l_e_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ CCoommpplleexxiittyy:: low
│ │ │ │ DDiissrruuppttiioonn:: low
│ │ │ │ RReebboooott:: false
│ │ │ │ SSttrraatteeggyy:: disable
│ │ │ │ - name: 'Remove NIS Client: Ensure ypbind-mt is removed'
│ │ │ │ ansible.builtin.package:
│ │ │ │ @@ -27879,14 +27866,27 @@
│ │ │ │ - PCI-DSSv4-2.2.4
│ │ │ │ - disable_strategy
│ │ │ │ - low_complexity
│ │ │ │ - low_disruption
│ │ │ │ - no_reboot_needed
│ │ │ │ - package_ypbind_removed
│ │ │ │ - unknown_severity
│ │ │ │ +_R_e_m_e_d_i_a_t_i_o_n_ _P_u_p_p_e_t_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ +CCoommpplleexxiittyy:: low
│ │ │ │ +DDiissrruuppttiioonn:: low
│ │ │ │ +RReebboooott:: false
│ │ │ │ +SSttrraatteeggyy:: disable
│ │ │ │ +
│ │ │ │ +include remove_ypbind-mt
│ │ │ │ +
│ │ │ │ +class remove_ypbind-mt {
│ │ │ │ + package { 'ypbind-mt':
│ │ │ │ + ensure => 'purged',
│ │ │ │ + }
│ │ │ │ +}
│ │ │ │ _R_e_m_e_d_i_a_t_i_o_n_ _S_h_e_l_l_ _s_c_r_i_p_t_ _⇲
│ │ │ │ CCoommpplleexxiittyy:: low
│ │ │ │ DDiissrruuppttiioonn:: low
│ │ │ │ RReebboooott:: false
│ │ │ │ SSttrraatteeggyy:: disable
│ │ │ │
│ │ │ │ # CAUTION: This remediation script will remove ypbind-mt
│ │ │ │ @@ -27939,27 +27939,14 @@
│ │ │ │ _n_i_s_t CM-7(a), CM-7(b), CM-6(a), IA-5(1)(c)
│ │ │ │ _n_i_s_t_-_c_s_f PR.AC-3, PR.IP-1, PR.PT-3, PR.PT-4
│ │ │ │ _p_c_i_d_s_s Req-2.2.2
│ │ │ │ _o_s_-_s_r_g SRG-OS-000095-GPOS-00049
│ │ │ │ _a_n_s_s_i R62
│ │ │ │ _c_i_s 2.1.10
│ │ │ │ _p_c_i_d_s_s_4 2.2.4, 2.2
│ │ │ │ -_R_e_m_e_d_i_a_t_i_o_n_ _P_u_p_p_e_t_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ -CCoommpplleexxiittyy:: low
│ │ │ │ -DDiissrruuppttiioonn:: low
│ │ │ │ -RReebboooott:: false
│ │ │ │ -SSttrraatteeggyy:: disable
│ │ │ │ -
│ │ │ │ -include remove_ypserv
│ │ │ │ -
│ │ │ │ -class remove_ypserv {
│ │ │ │ - package { 'ypserv':
│ │ │ │ - ensure => 'purged',
│ │ │ │ - }
│ │ │ │ -}
│ │ │ │ _R_e_m_e_d_i_a_t_i_o_n_ _A_n_s_i_b_l_e_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ CCoommpplleexxiittyy:: low
│ │ │ │ DDiissrruuppttiioonn:: low
│ │ │ │ RReebboooott:: false
│ │ │ │ SSttrraatteeggyy:: disable
│ │ │ │ - name: 'Uninstall ypserv Package: Ensure ypserv is removed'
│ │ │ │ ansible.builtin.package:
│ │ │ │ @@ -27975,14 +27962,27 @@
│ │ │ │ - PCI-DSSv4-2.2.4
│ │ │ │ - disable_strategy
│ │ │ │ - high_severity
│ │ │ │ - low_complexity
│ │ │ │ - low_disruption
│ │ │ │ - no_reboot_needed
│ │ │ │ - package_ypserv_removed
│ │ │ │ +_R_e_m_e_d_i_a_t_i_o_n_ _P_u_p_p_e_t_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ +CCoommpplleexxiittyy:: low
│ │ │ │ +DDiissrruuppttiioonn:: low
│ │ │ │ +RReebboooott:: false
│ │ │ │ +SSttrraatteeggyy:: disable
│ │ │ │ +
│ │ │ │ +include remove_ypserv
│ │ │ │ +
│ │ │ │ +class remove_ypserv {
│ │ │ │ + package { 'ypserv':
│ │ │ │ + ensure => 'purged',
│ │ │ │ + }
│ │ │ │ +}
│ │ │ │ _R_e_m_e_d_i_a_t_i_o_n_ _S_h_e_l_l_ _s_c_r_i_p_t_ _⇲
│ │ │ │ CCoommpplleexxiittyy:: low
│ │ │ │ DDiissrruuppttiioonn:: low
│ │ │ │ RReebboooott:: false
│ │ │ │ SSttrraatteeggyy:: disable
│ │ │ │
│ │ │ │ # CAUTION: This remediation script will remove ypserv
│ │ │ │ @@ -28038,27 +28038,14 @@
│ │ │ │ _i_s_o_2_7_0_0_1_-_2_0_1_3 A.11.2.6, A.12.1.2, A.12.5.1, A.12.6.2, A.13.1.1, A.13.2.1, A.14.1.3,
│ │ │ │ A.14.2.2, A.14.2.3, A.14.2.4, A.6.2.1, A.6.2.2, A.9.1.2
│ │ │ │ _n_i_s_t CM-7(a), CM-7(b), CM-6(a), IA-5(1)(c)
│ │ │ │ _n_i_s_t_-_c_s_f PR.AC-3, PR.IP-1, PR.PT-3, PR.PT-4
│ │ │ │ _o_s_-_s_r_g SRG-OS-000095-GPOS-00049
│ │ │ │ _a_n_s_s_i R62
│ │ │ │ _p_c_i_d_s_s_4 2.2.4, 2.2
│ │ │ │ -_R_e_m_e_d_i_a_t_i_o_n_ _P_u_p_p_e_t_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ -CCoommpplleexxiittyy:: low
│ │ │ │ -DDiissrruuppttiioonn:: low
│ │ │ │ -RReebboooott:: false
│ │ │ │ -SSttrraatteeggyy:: disable
│ │ │ │ -
│ │ │ │ -include remove_rsh-server
│ │ │ │ -
│ │ │ │ -class remove_rsh-server {
│ │ │ │ - package { 'rsh-server':
│ │ │ │ - ensure => 'purged',
│ │ │ │ - }
│ │ │ │ -}
│ │ │ │ _R_e_m_e_d_i_a_t_i_o_n_ _A_n_s_i_b_l_e_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ CCoommpplleexxiittyy:: low
│ │ │ │ DDiissrruuppttiioonn:: low
│ │ │ │ RReebboooott:: false
│ │ │ │ SSttrraatteeggyy:: disable
│ │ │ │ - name: 'Uninstall rsh-server Package: Ensure rsh-server is removed'
│ │ │ │ ansible.builtin.package:
│ │ │ │ @@ -28073,14 +28060,27 @@
│ │ │ │ - PCI-DSSv4-2.2.4
│ │ │ │ - disable_strategy
│ │ │ │ - high_severity
│ │ │ │ - low_complexity
│ │ │ │ - low_disruption
│ │ │ │ - no_reboot_needed
│ │ │ │ - package_rsh-server_removed
│ │ │ │ +_R_e_m_e_d_i_a_t_i_o_n_ _P_u_p_p_e_t_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ +CCoommpplleexxiittyy:: low
│ │ │ │ +DDiissrruuppttiioonn:: low
│ │ │ │ +RReebboooott:: false
│ │ │ │ +SSttrraatteeggyy:: disable
│ │ │ │ +
│ │ │ │ +include remove_rsh-server
│ │ │ │ +
│ │ │ │ +class remove_rsh-server {
│ │ │ │ + package { 'rsh-server':
│ │ │ │ + ensure => 'purged',
│ │ │ │ + }
│ │ │ │ +}
│ │ │ │ _R_e_m_e_d_i_a_t_i_o_n_ _S_h_e_l_l_ _s_c_r_i_p_t_ _⇲
│ │ │ │ CCoommpplleexxiittyy:: low
│ │ │ │ DDiissrruuppttiioonn:: low
│ │ │ │ RReebboooott:: false
│ │ │ │ SSttrraatteeggyy:: disable
│ │ │ │
│ │ │ │ # CAUTION: This remediation script will remove rsh-server
│ │ │ │ @@ -28118,27 +28118,14 @@
│ │ │ │ _c_u_i 3.1.13
│ │ │ │ _h_i_p_a_a 164.308(a)(4)(i), 164.308(b)(1), 164.308(b)(3), 164.310(b), 164.312(e)(1),
│ │ │ │ 164.312(e)(2)(ii)
│ │ │ │ References: _i_s_o_2_7_0_0_1_-_2_0_1_3 A.8.2.3, A.13.1.1, A.13.2.1, A.13.2.3, A.14.1.2, A.14.1.3
│ │ │ │ _a_n_s_s_i R62
│ │ │ │ _c_i_s 2.2.2
│ │ │ │ _p_c_i_d_s_s_4 2.2.4, 2.2
│ │ │ │ -_R_e_m_e_d_i_a_t_i_o_n_ _P_u_p_p_e_t_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ -CCoommpplleexxiittyy:: low
│ │ │ │ -DDiissrruuppttiioonn:: low
│ │ │ │ -RReebboooott:: false
│ │ │ │ -SSttrraatteeggyy:: disable
│ │ │ │ -
│ │ │ │ -include remove_rsh
│ │ │ │ -
│ │ │ │ -class remove_rsh {
│ │ │ │ - package { 'rsh':
│ │ │ │ - ensure => 'purged',
│ │ │ │ - }
│ │ │ │ -}
│ │ │ │ _R_e_m_e_d_i_a_t_i_o_n_ _A_n_s_i_b_l_e_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ CCoommpplleexxiittyy:: low
│ │ │ │ DDiissrruuppttiioonn:: low
│ │ │ │ RReebboooott:: false
│ │ │ │ SSttrraatteeggyy:: disable
│ │ │ │ - name: 'Uninstall rsh Package: Ensure rsh is removed'
│ │ │ │ ansible.builtin.package:
│ │ │ │ @@ -28150,14 +28137,27 @@
│ │ │ │ - PCI-DSSv4-2.2.4
│ │ │ │ - disable_strategy
│ │ │ │ - low_complexity
│ │ │ │ - low_disruption
│ │ │ │ - no_reboot_needed
│ │ │ │ - package_rsh_removed
│ │ │ │ - unknown_severity
│ │ │ │ +_R_e_m_e_d_i_a_t_i_o_n_ _P_u_p_p_e_t_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ +CCoommpplleexxiittyy:: low
│ │ │ │ +DDiissrruuppttiioonn:: low
│ │ │ │ +RReebboooott:: false
│ │ │ │ +SSttrraatteeggyy:: disable
│ │ │ │ +
│ │ │ │ +include remove_rsh
│ │ │ │ +
│ │ │ │ +class remove_rsh {
│ │ │ │ + package { 'rsh':
│ │ │ │ + ensure => 'purged',
│ │ │ │ + }
│ │ │ │ +}
│ │ │ │ _R_e_m_e_d_i_a_t_i_o_n_ _S_h_e_l_l_ _s_c_r_i_p_t_ _⇲
│ │ │ │ CCoommpplleexxiittyy:: low
│ │ │ │ DDiissrruuppttiioonn:: low
│ │ │ │ RReebboooott:: false
│ │ │ │ SSttrraatteeggyy:: disable
│ │ │ │
│ │ │ │ # CAUTION: This remediation script will remove rsh
│ │ │ │ @@ -28194,27 +28194,14 @@
│ │ │ │ intentional) activation of talk services.
│ │ │ │ Severity: medium
│ │ │ │ Rule ID: xccdf_org.ssgproject.content_rule_package_talk-server_removed
│ │ │ │ _h_i_p_a_a 164.308(a)(4)(i), 164.308(b)(1), 164.308(b)(3), 164.310(b), 164.312(e)(1),
│ │ │ │ References: 164.312(e)(2)(ii)
│ │ │ │ _a_n_s_s_i R62
│ │ │ │ _p_c_i_d_s_s_4 2.2.4, 2.2
│ │ │ │ -_R_e_m_e_d_i_a_t_i_o_n_ _P_u_p_p_e_t_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ -CCoommpplleexxiittyy:: low
│ │ │ │ -DDiissrruuppttiioonn:: low
│ │ │ │ -RReebboooott:: false
│ │ │ │ -SSttrraatteeggyy:: disable
│ │ │ │ -
│ │ │ │ -include remove_talk-server
│ │ │ │ -
│ │ │ │ -class remove_talk-server {
│ │ │ │ - package { 'talk-server':
│ │ │ │ - ensure => 'purged',
│ │ │ │ - }
│ │ │ │ -}
│ │ │ │ _R_e_m_e_d_i_a_t_i_o_n_ _A_n_s_i_b_l_e_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ CCoommpplleexxiittyy:: low
│ │ │ │ DDiissrruuppttiioonn:: low
│ │ │ │ RReebboooott:: false
│ │ │ │ SSttrraatteeggyy:: disable
│ │ │ │ - name: 'Uninstall talk-server Package: Ensure talk-server is removed'
│ │ │ │ ansible.builtin.package:
│ │ │ │ @@ -28225,14 +28212,27 @@
│ │ │ │ - PCI-DSSv4-2.2.4
│ │ │ │ - disable_strategy
│ │ │ │ - low_complexity
│ │ │ │ - low_disruption
│ │ │ │ - medium_severity
│ │ │ │ - no_reboot_needed
│ │ │ │ - package_talk-server_removed
│ │ │ │ +_R_e_m_e_d_i_a_t_i_o_n_ _P_u_p_p_e_t_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ +CCoommpplleexxiittyy:: low
│ │ │ │ +DDiissrruuppttiioonn:: low
│ │ │ │ +RReebboooott:: false
│ │ │ │ +SSttrraatteeggyy:: disable
│ │ │ │ +
│ │ │ │ +include remove_talk-server
│ │ │ │ +
│ │ │ │ +class remove_talk-server {
│ │ │ │ + package { 'talk-server':
│ │ │ │ + ensure => 'purged',
│ │ │ │ + }
│ │ │ │ +}
│ │ │ │ _R_e_m_e_d_i_a_t_i_o_n_ _S_h_e_l_l_ _s_c_r_i_p_t_ _⇲
│ │ │ │ CCoommpplleexxiittyy:: low
│ │ │ │ DDiissrruuppttiioonn:: low
│ │ │ │ RReebboooott:: false
│ │ │ │ SSttrraatteeggyy:: disable
│ │ │ │
│ │ │ │ # CAUTION: This remediation script will remove talk-server
│ │ │ │ @@ -28270,27 +28270,14 @@
│ │ │ │ Severity: medium
│ │ │ │ Rule ID: xccdf_org.ssgproject.content_rule_package_talk_removed
│ │ │ │ _h_i_p_a_a 164.308(a)(4)(i), 164.308(b)(1), 164.308(b)(3), 164.310(b), 164.312(e)(1),
│ │ │ │ 164.312(e)(2)(ii)
│ │ │ │ References: _a_n_s_s_i R62
│ │ │ │ _c_i_s 2.2.3
│ │ │ │ _p_c_i_d_s_s_4 2.2.4, 2.2
│ │ │ │ -_R_e_m_e_d_i_a_t_i_o_n_ _P_u_p_p_e_t_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ -CCoommpplleexxiittyy:: low
│ │ │ │ -DDiissrruuppttiioonn:: low
│ │ │ │ -RReebboooott:: false
│ │ │ │ -SSttrraatteeggyy:: disable
│ │ │ │ -
│ │ │ │ -include remove_talk
│ │ │ │ -
│ │ │ │ -class remove_talk {
│ │ │ │ - package { 'talk':
│ │ │ │ - ensure => 'purged',
│ │ │ │ - }
│ │ │ │ -}
│ │ │ │ _R_e_m_e_d_i_a_t_i_o_n_ _A_n_s_i_b_l_e_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ CCoommpplleexxiittyy:: low
│ │ │ │ DDiissrruuppttiioonn:: low
│ │ │ │ RReebboooott:: false
│ │ │ │ SSttrraatteeggyy:: disable
│ │ │ │ - name: 'Uninstall talk Package: Ensure talk is removed'
│ │ │ │ ansible.builtin.package:
│ │ │ │ @@ -28301,14 +28288,27 @@
│ │ │ │ - PCI-DSSv4-2.2.4
│ │ │ │ - disable_strategy
│ │ │ │ - low_complexity
│ │ │ │ - low_disruption
│ │ │ │ - medium_severity
│ │ │ │ - no_reboot_needed
│ │ │ │ - package_talk_removed
│ │ │ │ +_R_e_m_e_d_i_a_t_i_o_n_ _P_u_p_p_e_t_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ +CCoommpplleexxiittyy:: low
│ │ │ │ +DDiissrruuppttiioonn:: low
│ │ │ │ +RReebboooott:: false
│ │ │ │ +SSttrraatteeggyy:: disable
│ │ │ │ +
│ │ │ │ +include remove_talk
│ │ │ │ +
│ │ │ │ +class remove_talk {
│ │ │ │ + package { 'talk':
│ │ │ │ + ensure => 'purged',
│ │ │ │ + }
│ │ │ │ +}
│ │ │ │ _R_e_m_e_d_i_a_t_i_o_n_ _S_h_e_l_l_ _s_c_r_i_p_t_ _⇲
│ │ │ │ CCoommpplleexxiittyy:: low
│ │ │ │ DDiissrruuppttiioonn:: low
│ │ │ │ RReebboooott:: false
│ │ │ │ SSttrraatteeggyy:: disable
│ │ │ │
│ │ │ │ # CAUTION: This remediation script will remove talk
│ │ │ │ @@ -28371,27 +28371,14 @@
│ │ │ │ _n_i_s_t CM-7(a), CM-7(b), CM-6(a)
│ │ │ │ _n_i_s_t_-_c_s_f PR.AC-3, PR.IP-1, PR.PT-3, PR.PT-4
│ │ │ │ _p_c_i_d_s_s Req-2.2.2
│ │ │ │ _o_s_-_s_r_g SRG-OS-000095-GPOS-00049
│ │ │ │ _a_n_s_s_i R62
│ │ │ │ _i_s_m 1409
│ │ │ │ _p_c_i_d_s_s_4 2.2.4, 2.2
│ │ │ │ -_R_e_m_e_d_i_a_t_i_o_n_ _P_u_p_p_e_t_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ -CCoommpplleexxiittyy:: low
│ │ │ │ -DDiissrruuppttiioonn:: low
│ │ │ │ -RReebboooott:: false
│ │ │ │ -SSttrraatteeggyy:: disable
│ │ │ │ -
│ │ │ │ -include remove_telnet-server
│ │ │ │ -
│ │ │ │ -class remove_telnet-server {
│ │ │ │ - package { 'telnet-server':
│ │ │ │ - ensure => 'purged',
│ │ │ │ - }
│ │ │ │ -}
│ │ │ │ _R_e_m_e_d_i_a_t_i_o_n_ _A_n_s_i_b_l_e_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ CCoommpplleexxiittyy:: low
│ │ │ │ DDiissrruuppttiioonn:: low
│ │ │ │ RReebboooott:: false
│ │ │ │ SSttrraatteeggyy:: disable
│ │ │ │ - name: 'Uninstall telnet-server Package: Ensure telnet-server is removed'
│ │ │ │ ansible.builtin.package:
│ │ │ │ @@ -28406,14 +28393,27 @@
│ │ │ │ - PCI-DSSv4-2.2.4
│ │ │ │ - disable_strategy
│ │ │ │ - high_severity
│ │ │ │ - low_complexity
│ │ │ │ - low_disruption
│ │ │ │ - no_reboot_needed
│ │ │ │ - package_telnet-server_removed
│ │ │ │ +_R_e_m_e_d_i_a_t_i_o_n_ _P_u_p_p_e_t_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ +CCoommpplleexxiittyy:: low
│ │ │ │ +DDiissrruuppttiioonn:: low
│ │ │ │ +RReebboooott:: false
│ │ │ │ +SSttrraatteeggyy:: disable
│ │ │ │ +
│ │ │ │ +include remove_telnet-server
│ │ │ │ +
│ │ │ │ +class remove_telnet-server {
│ │ │ │ + package { 'telnet-server':
│ │ │ │ + ensure => 'purged',
│ │ │ │ + }
│ │ │ │ +}
│ │ │ │ _R_e_m_e_d_i_a_t_i_o_n_ _S_h_e_l_l_ _s_c_r_i_p_t_ _⇲
│ │ │ │ CCoommpplleexxiittyy:: low
│ │ │ │ DDiissrruuppttiioonn:: low
│ │ │ │ RReebboooott:: false
│ │ │ │ SSttrraatteeggyy:: disable
│ │ │ │
│ │ │ │ # CAUTION: This remediation script will remove telnet-server
│ │ │ │ @@ -28450,27 +28450,14 @@
│ │ │ │ _h_i_p_a_a 164.308(a)(4)(i), 164.308(b)(1), 164.308(b)(3), 164.310(b), 164.312(e)(1),
│ │ │ │ 164.312(e)(2)(ii)
│ │ │ │ References: _i_s_o_2_7_0_0_1_-_2_0_1_3 A.8.2.3, A.13.1.1, A.13.2.1, A.13.2.3, A.14.1.2, A.14.1.3
│ │ │ │ _a_n_s_s_i R62
│ │ │ │ _c_i_s 2.2.4
│ │ │ │ _i_s_m 1409
│ │ │ │ _p_c_i_d_s_s_4 2.2.4, 2.2
│ │ │ │ -_R_e_m_e_d_i_a_t_i_o_n_ _P_u_p_p_e_t_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ -CCoommpplleexxiittyy:: low
│ │ │ │ -DDiissrruuppttiioonn:: low
│ │ │ │ -RReebboooott:: false
│ │ │ │ -SSttrraatteeggyy:: disable
│ │ │ │ -
│ │ │ │ -include remove_telnet
│ │ │ │ -
│ │ │ │ -class remove_telnet {
│ │ │ │ - package { 'telnet':
│ │ │ │ - ensure => 'purged',
│ │ │ │ - }
│ │ │ │ -}
│ │ │ │ _R_e_m_e_d_i_a_t_i_o_n_ _A_n_s_i_b_l_e_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ CCoommpplleexxiittyy:: low
│ │ │ │ DDiissrruuppttiioonn:: low
│ │ │ │ RReebboooott:: false
│ │ │ │ SSttrraatteeggyy:: disable
│ │ │ │ - name: 'Remove telnet Clients: Ensure telnet is removed'
│ │ │ │ ansible.builtin.package:
│ │ │ │ @@ -28482,14 +28469,27 @@
│ │ │ │ - PCI-DSSv4-2.2.4
│ │ │ │ - disable_strategy
│ │ │ │ - low_complexity
│ │ │ │ - low_disruption
│ │ │ │ - low_severity
│ │ │ │ - no_reboot_needed
│ │ │ │ - package_telnet_removed
│ │ │ │ +_R_e_m_e_d_i_a_t_i_o_n_ _P_u_p_p_e_t_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ +CCoommpplleexxiittyy:: low
│ │ │ │ +DDiissrruuppttiioonn:: low
│ │ │ │ +RReebboooott:: false
│ │ │ │ +SSttrraatteeggyy:: disable
│ │ │ │ +
│ │ │ │ +include remove_telnet
│ │ │ │ +
│ │ │ │ +class remove_telnet {
│ │ │ │ + package { 'telnet':
│ │ │ │ + ensure => 'purged',
│ │ │ │ + }
│ │ │ │ +}
│ │ │ │ _R_e_m_e_d_i_a_t_i_o_n_ _S_h_e_l_l_ _s_c_r_i_p_t_ _⇲
│ │ │ │ CCoommpplleexxiittyy:: low
│ │ │ │ DDiissrruuppttiioonn:: low
│ │ │ │ RReebboooott:: false
│ │ │ │ SSttrraatteeggyy:: disable
│ │ │ │
│ │ │ │ # CAUTION: This remediation script will remove telnet
│ │ │ │ @@ -28548,27 +28548,14 @@
│ │ │ │ A.14.2.2, A.14.2.3, A.14.2.4, A.6.2.1, A.6.2.2, A.9.1.2
│ │ │ │ _n_i_s_t CM-7(a), CM-7(b), CM-6(a)
│ │ │ │ _n_i_s_t_-_c_s_f PR.AC-3, PR.IP-1, PR.PT-3, PR.PT-4
│ │ │ │ _o_s_-_s_r_g SRG-OS-000480-GPOS-00227
│ │ │ │ _a_n_s_s_i R62
│ │ │ │ _c_i_s 2.1.16
│ │ │ │ _p_c_i_d_s_s_4 2.2.4, 2.2
│ │ │ │ -_R_e_m_e_d_i_a_t_i_o_n_ _P_u_p_p_e_t_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ -CCoommpplleexxiittyy:: low
│ │ │ │ -DDiissrruuppttiioonn:: low
│ │ │ │ -RReebboooott:: false
│ │ │ │ -SSttrraatteeggyy:: disable
│ │ │ │ -
│ │ │ │ -include remove_tftpd-hpa
│ │ │ │ -
│ │ │ │ -class remove_tftpd-hpa {
│ │ │ │ - package { 'tftpd-hpa':
│ │ │ │ - ensure => 'purged',
│ │ │ │ - }
│ │ │ │ -}
│ │ │ │ _R_e_m_e_d_i_a_t_i_o_n_ _A_n_s_i_b_l_e_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ CCoommpplleexxiittyy:: low
│ │ │ │ DDiissrruuppttiioonn:: low
│ │ │ │ RReebboooott:: false
│ │ │ │ SSttrraatteeggyy:: disable
│ │ │ │ - name: 'Uninstall tftpd-hpa Package: Ensure tftpd-hpa is removed'
│ │ │ │ ansible.builtin.package:
│ │ │ │ @@ -28582,14 +28569,27 @@
│ │ │ │ - PCI-DSSv4-2.2.4
│ │ │ │ - disable_strategy
│ │ │ │ - high_severity
│ │ │ │ - low_complexity
│ │ │ │ - low_disruption
│ │ │ │ - no_reboot_needed
│ │ │ │ - package_tftp-server_removed
│ │ │ │ +_R_e_m_e_d_i_a_t_i_o_n_ _P_u_p_p_e_t_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ +CCoommpplleexxiittyy:: low
│ │ │ │ +DDiissrruuppttiioonn:: low
│ │ │ │ +RReebboooott:: false
│ │ │ │ +SSttrraatteeggyy:: disable
│ │ │ │ +
│ │ │ │ +include remove_tftpd-hpa
│ │ │ │ +
│ │ │ │ +class remove_tftpd-hpa {
│ │ │ │ + package { 'tftpd-hpa':
│ │ │ │ + ensure => 'purged',
│ │ │ │ + }
│ │ │ │ +}
│ │ │ │ _R_e_m_e_d_i_a_t_i_o_n_ _S_h_e_l_l_ _s_c_r_i_p_t_ _⇲
│ │ │ │ CCoommpplleexxiittyy:: low
│ │ │ │ DDiissrruuppttiioonn:: low
│ │ │ │ RReebboooott:: false
│ │ │ │ SSttrraatteeggyy:: disable
│ │ │ │
│ │ │ │ # CAUTION: This remediation script will remove tftpd-hpa
│ │ │ │ @@ -28623,27 +28623,14 @@
│ │ │ │ Rationale: It is recommended that TFTP be removed, unless there is a specific need for TFTP (such as
│ │ │ │ a boot server). In that case, use extreme caution when configuring the services.
│ │ │ │ Severity: low
│ │ │ │ Rule ID: xccdf_org.ssgproject.content_rule_package_tftp_removed
│ │ │ │ _o_s_-_s_r_g SRG-OS-000074-GPOS-00042
│ │ │ │ References: _a_n_s_s_i R62
│ │ │ │ _p_c_i_d_s_s_4 2.2.4, 2.2
│ │ │ │ -_R_e_m_e_d_i_a_t_i_o_n_ _P_u_p_p_e_t_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ -CCoommpplleexxiittyy:: low
│ │ │ │ -DDiissrruuppttiioonn:: low
│ │ │ │ -RReebboooott:: false
│ │ │ │ -SSttrraatteeggyy:: disable
│ │ │ │ -
│ │ │ │ -include remove_tftp
│ │ │ │ -
│ │ │ │ -class remove_tftp {
│ │ │ │ - package { 'tftp':
│ │ │ │ - ensure => 'purged',
│ │ │ │ - }
│ │ │ │ -}
│ │ │ │ _R_e_m_e_d_i_a_t_i_o_n_ _A_n_s_i_b_l_e_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ CCoommpplleexxiittyy:: low
│ │ │ │ DDiissrruuppttiioonn:: low
│ │ │ │ RReebboooott:: false
│ │ │ │ SSttrraatteeggyy:: disable
│ │ │ │ - name: 'Remove tftp Daemon: Ensure tftp is removed'
│ │ │ │ ansible.builtin.package:
│ │ │ │ @@ -28654,14 +28641,27 @@
│ │ │ │ - PCI-DSSv4-2.2.4
│ │ │ │ - disable_strategy
│ │ │ │ - low_complexity
│ │ │ │ - low_disruption
│ │ │ │ - low_severity
│ │ │ │ - no_reboot_needed
│ │ │ │ - package_tftp_removed
│ │ │ │ +_R_e_m_e_d_i_a_t_i_o_n_ _P_u_p_p_e_t_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ +CCoommpplleexxiittyy:: low
│ │ │ │ +DDiissrruuppttiioonn:: low
│ │ │ │ +RReebboooott:: false
│ │ │ │ +SSttrraatteeggyy:: disable
│ │ │ │ +
│ │ │ │ +include remove_tftp
│ │ │ │ +
│ │ │ │ +class remove_tftp {
│ │ │ │ + package { 'tftp':
│ │ │ │ + ensure => 'purged',
│ │ │ │ + }
│ │ │ │ +}
│ │ │ │ _R_e_m_e_d_i_a_t_i_o_n_ _S_h_e_l_l_ _s_c_r_i_p_t_ _⇲
│ │ │ │ CCoommpplleexxiittyy:: low
│ │ │ │ DDiissrruuppttiioonn:: low
│ │ │ │ RReebboooott:: false
│ │ │ │ SSttrraatteeggyy:: disable
│ │ │ │
│ │ │ │ # CAUTION: This remediation script will remove tftp
│ │ │ │ @@ -29592,26 +29592,14 @@
│ │ │ │ _n_i_s_t_-_c_s_f PR.AC-4, PR.DS-5
│ │ │ │ _p_c_i_d_s_s Req-2.2.4
│ │ │ │ _o_s_-_s_r_g SRG-OS-000480-GPOS-00227
│ │ │ │ _a_n_s_s_i R50
│ │ │ │ _c_i_s 5.1.2
│ │ │ │ _i_s_m 1449
│ │ │ │ _p_c_i_d_s_s_4 2.2.6, 2.2
│ │ │ │ -_R_e_m_e_d_i_a_t_i_o_n_ _P_u_p_p_e_t_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ -
│ │ │ │ -
│ │ │ │ -
│ │ │ │ -include ssh_private_key_perms
│ │ │ │ -
│ │ │ │ -class ssh_private_key_perms {
│ │ │ │ - exec { 'sshd_priv_key':
│ │ │ │ - command => "chmod 0600 /etc/ssh/*_key",
│ │ │ │ - path => '/bin:/usr/bin'
│ │ │ │ - }
│ │ │ │ -}
│ │ │ │ _R_e_m_e_d_i_a_t_i_o_n_ _A_n_s_i_b_l_e_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ CCoommpplleexxiittyy:: low
│ │ │ │ DDiissrruuppttiioonn:: low
│ │ │ │ RReebboooott:: false
│ │ │ │ SSttrraatteeggyy:: configure
│ │ │ │ - name: Gather the package facts
│ │ │ │ package_facts:
│ │ │ │ @@ -29675,14 +29663,26 @@
│ │ │ │ - PCI-DSSv4-2.2.6
│ │ │ │ - configure_strategy
│ │ │ │ - file_permissions_sshd_private_key
│ │ │ │ - low_complexity
│ │ │ │ - low_disruption
│ │ │ │ - medium_severity
│ │ │ │ - no_reboot_needed
│ │ │ │ +_R_e_m_e_d_i_a_t_i_o_n_ _P_u_p_p_e_t_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ +
│ │ │ │ +
│ │ │ │ +
│ │ │ │ +include ssh_private_key_perms
│ │ │ │ +
│ │ │ │ +class ssh_private_key_perms {
│ │ │ │ + exec { 'sshd_priv_key':
│ │ │ │ + command => "chmod 0600 /etc/ssh/*_key",
│ │ │ │ + path => '/bin:/usr/bin'
│ │ │ │ + }
│ │ │ │ +}
│ │ │ │ _R_e_m_e_d_i_a_t_i_o_n_ _S_h_e_l_l_ _s_c_r_i_p_t_ _⇲
│ │ │ │ # Remediation is applicable only in certain platforms
│ │ │ │ if dpkg-query --show --showformat='${db:Status-Status}' 'linux-base' 2>/dev/null | grep -
│ │ │ │ q '^installed$'; then
│ │ │ │
│ │ │ │ for keyfile in /etc/ssh/*_key; do
│ │ │ │ test -f "$keyfile" || continue
│ │ │ │ @@ -29720,23 +29720,14 @@
│ │ │ │ _n_i_s_t AC-17(a), CM-6(a), AC-6(1)
│ │ │ │ _n_i_s_t_-_c_s_f PR.AC-4, PR.DS-5
│ │ │ │ _p_c_i_d_s_s Req-2.2.4
│ │ │ │ _o_s_-_s_r_g SRG-OS-000480-GPOS-00227
│ │ │ │ _a_n_s_s_i R50
│ │ │ │ _c_i_s 5.1.3
│ │ │ │ _p_c_i_d_s_s_4 2.2.6, 2.2
│ │ │ │ -_R_e_m_e_d_i_a_t_i_o_n_ _P_u_p_p_e_t_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ -include ssh_public_key_perms
│ │ │ │ -
│ │ │ │ -class ssh_public_key_perms {
│ │ │ │ - exec { 'sshd_pub_key':
│ │ │ │ - command => "chmod 0644 /etc/ssh/*.pub",
│ │ │ │ - path => '/bin:/usr/bin'
│ │ │ │ - }
│ │ │ │ -}
│ │ │ │ _R_e_m_e_d_i_a_t_i_o_n_ _A_n_s_i_b_l_e_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ CCoommpplleexxiittyy:: low
│ │ │ │ DDiissrruuppttiioonn:: low
│ │ │ │ RReebboooott:: false
│ │ │ │ SSttrraatteeggyy:: configure
│ │ │ │ - name: Gather the package facts
│ │ │ │ package_facts:
│ │ │ │ @@ -29800,14 +29791,23 @@
│ │ │ │ - PCI-DSSv4-2.2.6
│ │ │ │ - configure_strategy
│ │ │ │ - file_permissions_sshd_pub_key
│ │ │ │ - low_complexity
│ │ │ │ - low_disruption
│ │ │ │ - medium_severity
│ │ │ │ - no_reboot_needed
│ │ │ │ +_R_e_m_e_d_i_a_t_i_o_n_ _P_u_p_p_e_t_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ +include ssh_public_key_perms
│ │ │ │ +
│ │ │ │ +class ssh_public_key_perms {
│ │ │ │ + exec { 'sshd_pub_key':
│ │ │ │ + command => "chmod 0644 /etc/ssh/*.pub",
│ │ │ │ + path => '/bin:/usr/bin'
│ │ │ │ + }
│ │ │ │ +}
│ │ │ │ _R_e_m_e_d_i_a_t_i_o_n_ _S_h_e_l_l_ _s_c_r_i_p_t_ _⇲
│ │ │ │ CCoommpplleexxiittyy:: low
│ │ │ │ DDiissrruuppttiioonn:: low
│ │ │ │ RReebboooott:: false
│ │ │ │ SSttrraatteeggyy:: configure
│ │ │ │ # Remediation is applicable only in certain platforms
│ │ │ │ if dpkg-query --show --showformat='${db:Status-Status}' 'linux-base' 2>/dev/null | grep -
│ │ │ │ @@ -29901,31 +29901,14 @@
│ │ │ │ References: SR 2.1
│ │ │ │ _i_s_o_2_7_0_0_1_-_2_0_1_3 A.18.1.4, A.7.1.1, A.9.2.1, A.9.2.2, A.9.2.3, A.9.2.4, A.9.2.6, A.9.3.1,
│ │ │ │ A.9.4.2, A.9.4.3
│ │ │ │ _n_i_s_t CM-6(a)
│ │ │ │ _n_i_s_t_-_c_s_f PR.AC-1, PR.AC-6, PR.AC-7
│ │ │ │ _o_s_-_s_r_g SRG-OS-000375-GPOS-00160
│ │ │ │ _a_n_s_s_i R67
│ │ │ │ -_R_e_m_e_d_i_a_t_i_o_n_ _O_S_B_u_i_l_d_ _B_l_u_e_p_r_i_n_t_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ -
│ │ │ │ -[[packages]]
│ │ │ │ -name = "sssd"
│ │ │ │ -version = "*"
│ │ │ │ -_R_e_m_e_d_i_a_t_i_o_n_ _P_u_p_p_e_t_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ -CCoommpplleexxiittyy:: low
│ │ │ │ -DDiissrruuppttiioonn:: low
│ │ │ │ -RReebboooott:: false
│ │ │ │ -SSttrraatteeggyy:: enable
│ │ │ │ -include install_sssd
│ │ │ │ -
│ │ │ │ -class install_sssd {
│ │ │ │ - package { 'sssd':
│ │ │ │ - ensure => 'installed',
│ │ │ │ - }
│ │ │ │ -}
│ │ │ │ _R_e_m_e_d_i_a_t_i_o_n_ _A_n_s_i_b_l_e_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ CCoommpplleexxiittyy:: low
│ │ │ │ DDiissrruuppttiioonn:: low
│ │ │ │ RReebboooott:: false
│ │ │ │ SSttrraatteeggyy:: enable
│ │ │ │ - name: Gather the package facts
│ │ │ │ package_facts:
│ │ │ │ @@ -29948,14 +29931,31 @@
│ │ │ │ - NIST-800-53-CM-6(a)
│ │ │ │ - enable_strategy
│ │ │ │ - low_complexity
│ │ │ │ - low_disruption
│ │ │ │ - medium_severity
│ │ │ │ - no_reboot_needed
│ │ │ │ - package_sssd_installed
│ │ │ │ +_R_e_m_e_d_i_a_t_i_o_n_ _P_u_p_p_e_t_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ +CCoommpplleexxiittyy:: low
│ │ │ │ +DDiissrruuppttiioonn:: low
│ │ │ │ +RReebboooott:: false
│ │ │ │ +SSttrraatteeggyy:: enable
│ │ │ │ +include install_sssd
│ │ │ │ +
│ │ │ │ +class install_sssd {
│ │ │ │ + package { 'sssd':
│ │ │ │ + ensure => 'installed',
│ │ │ │ + }
│ │ │ │ +}
│ │ │ │ +_R_e_m_e_d_i_a_t_i_o_n_ _O_S_B_u_i_l_d_ _B_l_u_e_p_r_i_n_t_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ +
│ │ │ │ +[[packages]]
│ │ │ │ +name = "sssd"
│ │ │ │ +version = "*"
│ │ │ │ _R_e_m_e_d_i_a_t_i_o_n_ _S_h_e_l_l_ _s_c_r_i_p_t_ _⇲
│ │ │ │ CCoommpplleexxiittyy:: low
│ │ │ │ DDiissrruuppttiioonn:: low
│ │ │ │ RReebboooott:: false
│ │ │ │ SSttrraatteeggyy:: enable
│ │ │ │ # Remediation is applicable only in certain platforms
│ │ │ │ if dpkg-query --show --showformat='${db:Status-Status}' 'sssd-common' 2>/dev/null | grep -
│ │ │ │ @@ -29985,31 +29985,14 @@
│ │ │ │ References: SR 2.1
│ │ │ │ _i_s_o_2_7_0_0_1_-_2_0_1_3 A.18.1.4, A.7.1.1, A.9.2.1, A.9.2.2, A.9.2.3, A.9.2.4, A.9.2.6, A.9.3.1,
│ │ │ │ A.9.4.2, A.9.4.3
│ │ │ │ _n_i_s_t CM-6(a), IA-5(10)
│ │ │ │ _n_i_s_t_-_c_s_f PR.AC-1, PR.AC-6, PR.AC-7
│ │ │ │ _o_s_-_s_r_g SRG-OS-000375-GPOS-00160
│ │ │ │ _a_n_s_s_i R67
│ │ │ │ -_R_e_m_e_d_i_a_t_i_o_n_ _O_S_B_u_i_l_d_ _B_l_u_e_p_r_i_n_t_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ -
│ │ │ │ -[customizations.services]
│ │ │ │ -enabled = ["sssd"]
│ │ │ │ -_R_e_m_e_d_i_a_t_i_o_n_ _P_u_p_p_e_t_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ -CCoommpplleexxiittyy:: low
│ │ │ │ -DDiissrruuppttiioonn:: low
│ │ │ │ -RReebboooott:: false
│ │ │ │ -SSttrraatteeggyy:: enable
│ │ │ │ -include enable_sssd
│ │ │ │ -
│ │ │ │ -class enable_sssd {
│ │ │ │ - service {'sssd':
│ │ │ │ - enable => true,
│ │ │ │ - ensure => 'running',
│ │ │ │ - }
│ │ │ │ -}
│ │ │ │ _R_e_m_e_d_i_a_t_i_o_n_ _A_n_s_i_b_l_e_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ CCoommpplleexxiittyy:: low
│ │ │ │ DDiissrruuppttiioonn:: low
│ │ │ │ RReebboooott:: false
│ │ │ │ SSttrraatteeggyy:: enable
│ │ │ │ - name: Gather the package facts
│ │ │ │ package_facts:
│ │ │ │ @@ -30049,14 +30032,31 @@
│ │ │ │ - no_reboot_needed
│ │ │ │ - service_sssd_enabled
│ │ │ │ - special_service_block
│ │ │ │ when:
│ │ │ │ - '"sssd-common" in ansible_facts.packages'
│ │ │ │ - ( "sssd-common" in ansible_facts.packages and "linux-base" in ansible_facts.packages
│ │ │ │ )
│ │ │ │ +_R_e_m_e_d_i_a_t_i_o_n_ _P_u_p_p_e_t_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ +CCoommpplleexxiittyy:: low
│ │ │ │ +DDiissrruuppttiioonn:: low
│ │ │ │ +RReebboooott:: false
│ │ │ │ +SSttrraatteeggyy:: enable
│ │ │ │ +include enable_sssd
│ │ │ │ +
│ │ │ │ +class enable_sssd {
│ │ │ │ + service {'sssd':
│ │ │ │ + enable => true,
│ │ │ │ + ensure => 'running',
│ │ │ │ + }
│ │ │ │ +}
│ │ │ │ +_R_e_m_e_d_i_a_t_i_o_n_ _O_S_B_u_i_l_d_ _B_l_u_e_p_r_i_n_t_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ +
│ │ │ │ +[customizations.services]
│ │ │ │ +enabled = ["sssd"]
│ │ │ │ _R_e_m_e_d_i_a_t_i_o_n_ _S_h_e_l_l_ _s_c_r_i_p_t_ _⇲
│ │ │ │ CCoommpplleexxiittyy:: low
│ │ │ │ DDiissrruuppttiioonn:: low
│ │ │ │ RReebboooott:: false
│ │ │ │ SSttrraatteeggyy:: enable
│ │ │ │ # Remediation is applicable only in certain platforms
│ │ │ │ if dpkg-query --show --showformat='${db:Status-Status}' 'sssd-common' 2>/dev/null | grep -
│ │ │ │ @@ -30805,31 +30805,14 @@
│ │ │ │ SRG-OS-000350-GPOS-00138, SRG-OS-000351-GPOS-00139, SRG-OS-000352-GPOS-00140,
│ │ │ │ SRG-OS-000353-GPOS-00141, SRG-OS-000354-GPOS-00142, SRG-OS-000358-GPOS-00145,
│ │ │ │ SRG-OS-000365-GPOS-00152, SRG-OS-000392-GPOS-00172, SRG-OS-000475-GPOS-00220
│ │ │ │ _a_n_s_s_i R33, R73
│ │ │ │ _c_i_s 6.2.1.1
│ │ │ │ _i_s_m 0582, 0846
│ │ │ │ _p_c_i_d_s_s_4 10.2.1, 10.2
│ │ │ │ -_R_e_m_e_d_i_a_t_i_o_n_ _O_S_B_u_i_l_d_ _B_l_u_e_p_r_i_n_t_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ -
│ │ │ │ -[[packages]]
│ │ │ │ -name = "auditd"
│ │ │ │ -version = "*"
│ │ │ │ -_R_e_m_e_d_i_a_t_i_o_n_ _P_u_p_p_e_t_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ -CCoommpplleexxiittyy:: low
│ │ │ │ -DDiissrruuppttiioonn:: low
│ │ │ │ -RReebboooott:: false
│ │ │ │ -SSttrraatteeggyy:: enable
│ │ │ │ -include install_auditd
│ │ │ │ -
│ │ │ │ -class install_auditd {
│ │ │ │ - package { 'auditd':
│ │ │ │ - ensure => 'installed',
│ │ │ │ - }
│ │ │ │ -}
│ │ │ │ _R_e_m_e_d_i_a_t_i_o_n_ _A_n_s_i_b_l_e_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ CCoommpplleexxiittyy:: low
│ │ │ │ DDiissrruuppttiioonn:: low
│ │ │ │ RReebboooott:: false
│ │ │ │ SSttrraatteeggyy:: enable
│ │ │ │ - name: Gather the package facts
│ │ │ │ package_facts:
│ │ │ │ @@ -30870,14 +30853,31 @@
│ │ │ │ - PCI-DSSv4-10.2.1
│ │ │ │ - enable_strategy
│ │ │ │ - low_complexity
│ │ │ │ - low_disruption
│ │ │ │ - medium_severity
│ │ │ │ - no_reboot_needed
│ │ │ │ - package_audit_installed
│ │ │ │ +_R_e_m_e_d_i_a_t_i_o_n_ _P_u_p_p_e_t_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ +CCoommpplleexxiittyy:: low
│ │ │ │ +DDiissrruuppttiioonn:: low
│ │ │ │ +RReebboooott:: false
│ │ │ │ +SSttrraatteeggyy:: enable
│ │ │ │ +include install_auditd
│ │ │ │ +
│ │ │ │ +class install_auditd {
│ │ │ │ + package { 'auditd':
│ │ │ │ + ensure => 'installed',
│ │ │ │ + }
│ │ │ │ +}
│ │ │ │ +_R_e_m_e_d_i_a_t_i_o_n_ _O_S_B_u_i_l_d_ _B_l_u_e_p_r_i_n_t_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ +
│ │ │ │ +[[packages]]
│ │ │ │ +name = "auditd"
│ │ │ │ +version = "*"
│ │ │ │ _R_e_m_e_d_i_a_t_i_o_n_ _S_h_e_l_l_ _s_c_r_i_p_t_ _⇲
│ │ │ │ CCoommpplleexxiittyy:: low
│ │ │ │ DDiissrruuppttiioonn:: low
│ │ │ │ RReebboooott:: false
│ │ │ │ SSttrraatteeggyy:: enable
│ │ │ │ # Remediation is applicable only in certain platforms
│ │ │ │ if dpkg-query --show --showformat='${db:Status-Status}' 'linux-base' 2>/dev/null | grep -
│ │ │ │ @@ -30938,31 +30938,14 @@
│ │ │ │ SRG-OS-000392-GPOS-00172, SRG-OS-000475-GPOS-00220
│ │ │ │ _a_p_p_-_s_r_g_-_c_t_r SRG-APP-000095-CTR-000170, SRG-APP-000409-CTR-000990, SRG-APP-000508-CTR-
│ │ │ │ 001300, SRG-APP-000510-CTR-001310
│ │ │ │ _a_n_s_s_i R33, R73
│ │ │ │ _c_i_s 6.2.1.2
│ │ │ │ _i_s_m 1409
│ │ │ │ _p_c_i_d_s_s_4 10.2.1, 10.2
│ │ │ │ -_R_e_m_e_d_i_a_t_i_o_n_ _O_S_B_u_i_l_d_ _B_l_u_e_p_r_i_n_t_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ -
│ │ │ │ -[customizations.services]
│ │ │ │ -enabled = ["auditd"]
│ │ │ │ -_R_e_m_e_d_i_a_t_i_o_n_ _P_u_p_p_e_t_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ -CCoommpplleexxiittyy:: low
│ │ │ │ -DDiissrruuppttiioonn:: low
│ │ │ │ -RReebboooott:: false
│ │ │ │ -SSttrraatteeggyy:: enable
│ │ │ │ -include enable_auditd
│ │ │ │ -
│ │ │ │ -class enable_auditd {
│ │ │ │ - service {'auditd':
│ │ │ │ - enable => true,
│ │ │ │ - ensure => 'running',
│ │ │ │ - }
│ │ │ │ -}
│ │ │ │ _R_e_m_e_d_i_a_t_i_o_n_ _A_n_s_i_b_l_e_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ CCoommpplleexxiittyy:: low
│ │ │ │ DDiissrruuppttiioonn:: low
│ │ │ │ RReebboooott:: false
│ │ │ │ SSttrraatteeggyy:: enable
│ │ │ │ - name: Gather the package facts
│ │ │ │ package_facts:
│ │ │ │ @@ -31029,14 +31012,31 @@
│ │ │ │ - medium_severity
│ │ │ │ - no_reboot_needed
│ │ │ │ - service_auditd_enabled
│ │ │ │ - special_service_block
│ │ │ │ when:
│ │ │ │ - '"linux-base" in ansible_facts.packages'
│ │ │ │ - '"auditd" in ansible_facts.packages'
│ │ │ │ +_R_e_m_e_d_i_a_t_i_o_n_ _P_u_p_p_e_t_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ +CCoommpplleexxiittyy:: low
│ │ │ │ +DDiissrruuppttiioonn:: low
│ │ │ │ +RReebboooott:: false
│ │ │ │ +SSttrraatteeggyy:: enable
│ │ │ │ +include enable_auditd
│ │ │ │ +
│ │ │ │ +class enable_auditd {
│ │ │ │ + service {'auditd':
│ │ │ │ + enable => true,
│ │ │ │ + ensure => 'running',
│ │ │ │ + }
│ │ │ │ +}
│ │ │ │ +_R_e_m_e_d_i_a_t_i_o_n_ _O_S_B_u_i_l_d_ _B_l_u_e_p_r_i_n_t_ _s_n_i_p_p_e_t_ _⇲
│ │ │ │ +
│ │ │ │ +[customizations.services]
│ │ │ │ +enabled = ["auditd"]
│ │ │ │ _R_e_m_e_d_i_a_t_i_o_n_ _S_h_e_l_l_ _s_c_r_i_p_t_ _⇲
│ │ │ │ CCoommpplleexxiittyy:: low
│ │ │ │ DDiissrruuppttiioonn:: low
│ │ │ │ RReebboooott:: false
│ │ │ │ SSttrraatteeggyy:: enable
│ │ │ │ # Remediation is applicable only in certain platforms
│ │ │ │ if dpkg-query --show --showformat='${db:Status-Status}' 'linux-base' 2>/dev/null | grep -
│ │ ├── ./usr/share/doc/ssg-debian/ssg-debian12-guide-anssi_bp28_minimal.html
│ │ │ @@ -23582,129 +23582,129 @@
│ │ │ 0005c1d0: 6c61 7073 6522 2064 6174 612d 7461 7267 lapse" data-targ
│ │ │ 0005c1e0: 6574 3d22 2369 6434 3922 2074 6162 696e et="#id49" tabin
│ │ │ 0005c1f0: 6465 783d 2230 2220 726f 6c65 3d22 6275 dex="0" role="bu
│ │ │ 0005c200: 7474 6f6e 2220 6172 6961 2d65 7870 616e tton" aria-expan
│ │ │ 0005c210: 6465 643d 2266 616c 7365 2220 7469 746c ded="false" titl
│ │ │ 0005c220: 653d 2241 6374 6976 6174 6520 746f 2072 e="Activate to r
│ │ │ 0005c230: 6576 6561 6c22 2068 7265 663d 2223 2122 eveal" href="#!"
│ │ │ -0005c240: 3e52 656d 6564 6961 7469 6f6e 204f 5342 >Remediation OSB
│ │ │ -0005c250: 7569 6c64 2042 6c75 6570 7269 6e74 2073 uild Blueprint s
│ │ │ -0005c260: 6e69 7070 6574 20e2 87b2 3c2f 613e 3c62 nippet ....[[p
│ │ │ -0005c2b0: 6163 6b61 6765 735d 5d0a 6e61 6d65 203d ackages]].name =
│ │ │ -0005c2c0: 2022 6c69 6270 616d 2d70 7771 7561 6c69 "libpam-pwquali
│ │ │ -0005c2d0: 7479 220a 7665 7273 696f 6e20 3d20 222a ty".version = "*
│ │ │ -0005c2e0: 220a 3c2f 636f 6465 3e3c 2f70 7265 3e3c ".
<
│ │ │ -0005c2f0: 2f64 6976 3e3c 6120 636c 6173 733d 2262 /div>
Remediation Pup
│ │ │ -0005c3a0: 7065 7420 736e 6970 7065 7420 e287 b23c pet snippet ...<
│ │ │ -0005c3b0: 2f61 3e3c 6272 3e3c 6469 7620 636c 6173 /a>
|
│ │ │ -0005c430: 436f 6d70 6c65 7869 7479 3a3c 2f74 683e Complexity: |
│ │ │ -0005c440: 3c74 643e 6c6f 773c 2f74 643e 3c2f 7472 low |
|---|
| Disrupt
│ │ │ -0005c460: 696f 6e3a 3c2f 7468 3e3c 7464 3e6c 6f77 ion: | low
│ │ │ -0005c470: 3c2f 7464 3e3c 2f74 723e 3c74 723e 3c74 |
|---|
Reboot:false
| Strateg
│ │ │ -0005c4b0: 793a 3c2f 7468 3e3c 7464 3e65 6e61 626c y: | enabl
│ │ │ -0005c4c0: 653c 2f74 643e 3c2f 7472 3e3c 2f74 6162 e |
|---|
in
│ │ │ -0005c4e0: 636c 7564 6520 696e 7374 616c 6c5f 6c69 clude install_li
│ │ │ -0005c4f0: 6270 616d 2d70 7771 7561 6c69 7479 0a0a bpam-pwquality..
│ │ │ -0005c500: 636c 6173 7320 696e 7374 616c 6c5f 6c69 class install_li
│ │ │ -0005c510: 6270 616d 2d70 7771 7561 6c69 7479 207b bpam-pwquality {
│ │ │ -0005c520: 0a20 2070 6163 6b61 6765 207b 2027 6c69 . package { 'li
│ │ │ -0005c530: 6270 616d 2d70 7771 7561 6c69 7479 273a bpam-pwquality':
│ │ │ -0005c540: 0a20 2020 2065 6e73 7572 6520 3d26 6774 . ensure =>
│ │ │ -0005c550: 3b20 2769 6e73 7461 6c6c 6564 272c 0a20 ; 'installed',.
│ │ │ -0005c560: 207d 0a7d 0a3c 2f63 6f64 653e 3c2f 7072 }.}.Remediation
│ │ │ -0005c620: 416e 7369 626c 6520 736e 6970 7065 7420 Ansible snippet
│ │ │ -0005c630: e287 b23c 2f61 3e3c 6272 3e3c 6469 7620 ...
│ │ │ -0005c6b0: 3c74 683e 436f 6d70 6c65 7869 7479 3a3c | Complexity:<
│ │ │ -0005c6c0: 2f74 683e 3c74 643e 6c6f 773c 2f74 643e /th> | low |
│ │ │ -0005c6d0: 3c2f 7472 3e3c 7472 3e3c 7468 3e44 6973
| Dis
│ │ │ -0005c6e0: 7275 7074 696f 6e3a 3c2f 7468 3e3c 7464 ruption: | low |
|---|
Reboot: | false |
│ │ │ -0005c720: 3c2f 7472 3e3c 7472 3e3c 7468 3e53 7472 | Str
│ │ │ -0005c730: 6174 6567 793a 3c2f 7468 3e3c 7464 3e65 ategy: | e
│ │ │ -0005c740: 6e61 626c 653c 2f74 643e 3c2f 7472 3e3c nable |
<
│ │ │ -0005c750: 2f74 6162 6c65 3e3c 7072 653e 3c63 6f64 /table>- name: Gather
│ │ │ -0005c770: 2074 6865 2070 6163 6b61 6765 2066 6163 the package fac
│ │ │ -0005c780: 7473 0a20 2070 6163 6b61 6765 5f66 6163 ts. package_fac
│ │ │ -0005c790: 7473 3a0a 2020 2020 6d61 6e61 6765 723a ts:. manager:
│ │ │ -0005c7a0: 2061 7574 6f0a 2020 7461 6773 3a0a 2020 auto. tags:.
│ │ │ -0005c7b0: 2d20 656e 6162 6c65 5f73 7472 6174 6567 - enable_strateg
│ │ │ -0005c7c0: 790a 2020 2d20 6c6f 775f 636f 6d70 6c65 y. - low_comple
│ │ │ -0005c7d0: 7869 7479 0a20 202d 206c 6f77 5f64 6973 xity. - low_dis
│ │ │ -0005c7e0: 7275 7074 696f 6e0a 2020 2d20 6d65 6469 ruption. - medi
│ │ │ -0005c7f0: 756d 5f73 6576 6572 6974 790a 2020 2d20 um_severity. -
│ │ │ -0005c800: 6e6f 5f72 6562 6f6f 745f 6e65 6564 6564 no_reboot_needed
│ │ │ -0005c810: 0a20 202d 2070 6163 6b61 6765 5f70 616d . - package_pam
│ │ │ -0005c820: 5f70 7771 7561 6c69 7479 5f69 6e73 7461 _pwquality_insta
│ │ │ -0005c830: 6c6c 6564 0a0a 2d20 6e61 6d65 3a20 456e lled..- name: En
│ │ │ -0005c840: 7375 7265 206c 6962 7061 6d2d 7077 7175 sure libpam-pwqu
│ │ │ -0005c850: 616c 6974 7920 6973 2069 6e73 7461 6c6c ality is install
│ │ │ -0005c860: 6564 0a20 2061 6e73 6962 6c65 2e62 7569 ed. ansible.bui
│ │ │ -0005c870: 6c74 696e 2e70 6163 6b61 6765 3a0a 2020 ltin.package:.
│ │ │ -0005c880: 2020 6e61 6d65 3a20 6c69 6270 616d 2d70 name: libpam-p
│ │ │ -0005c890: 7771 7561 6c69 7479 0a20 2020 2073 7461 wquality. sta
│ │ │ -0005c8a0: 7465 3a20 7072 6573 656e 740a 2020 7768 te: present. wh
│ │ │ -0005c8b0: 656e 3a20 2722 6c69 6270 616d 2d72 756e en: '"libpam-run
│ │ │ -0005c8c0: 7469 6d65 2220 696e 2061 6e73 6962 6c65 time" in ansible
│ │ │ -0005c8d0: 5f66 6163 7473 2e70 6163 6b61 6765 7327 _facts.packages'
│ │ │ -0005c8e0: 0a20 2074 6167 733a 0a20 202d 2065 6e61 . tags:. - ena
│ │ │ -0005c8f0: 626c 655f 7374 7261 7465 6779 0a20 202d ble_strategy. -
│ │ │ -0005c900: 206c 6f77 5f63 6f6d 706c 6578 6974 790a low_complexity.
│ │ │ -0005c910: 2020 2d20 6c6f 775f 6469 7372 7570 7469 - low_disrupti
│ │ │ -0005c920: 6f6e 0a20 202d 206d 6564 6975 6d5f 7365 on. - medium_se
│ │ │ -0005c930: 7665 7269 7479 0a20 202d 206e 6f5f 7265 verity. - no_re
│ │ │ -0005c940: 626f 6f74 5f6e 6565 6465 640a 2020 2d20 boot_needed. -
│ │ │ -0005c950: 7061 636b 6167 655f 7061 6d5f 7077 7175 package_pam_pwqu
│ │ │ -0005c960: 616c 6974 795f 696e 7374 616c 6c65 640a ality_installed.
│ │ │ +0005c240: 3e52 656d 6564 6961 7469 6f6e 2041 6e73 >Remediation Ans
│ │ │ +0005c250: 6962 6c65 2073 6e69 7070 6574 20e2 87b2 ible snippet ...
│ │ │ +0005c260: 3c2f 613e 3c62 723e 3c64 6976 2063 6c61
| Complexity: | low |
|---|
| Disrup
│ │ │ +0005c310: 7469 6f6e 3a3c 2f74 683e 3c74 643e 6c6f tion: | lo
│ │ │ +0005c320: 773c 2f74 643e 3c2f 7472 3e3c 7472 3e3c w |
|---|
<
│ │ │ +0005c330: 7468 3e52 6562 6f6f 743a 3c2f 7468 3e3c th>Reboot:<
│ │ │ +0005c340: 7464 3e66 616c 7365 3c2f 7464 3e3c 2f74 td>false
| Strate
│ │ │ +0005c360: 6779 3a3c 2f74 683e 3c74 643e 656e 6162 gy: | enab
│ │ │ +0005c370: 6c65 3c2f 7464 3e3c 2f74 723e 3c2f 7461 le |
|---|
-
│ │ │ +0005c390: 206e 616d 653a 2047 6174 6865 7220 7468 name: Gather th
│ │ │ +0005c3a0: 6520 7061 636b 6167 6520 6661 6374 730a e package facts.
│ │ │ +0005c3b0: 2020 7061 636b 6167 655f 6661 6374 733a package_facts:
│ │ │ +0005c3c0: 0a20 2020 206d 616e 6167 6572 3a20 6175 . manager: au
│ │ │ +0005c3d0: 746f 0a20 2074 6167 733a 0a20 202d 2065 to. tags:. - e
│ │ │ +0005c3e0: 6e61 626c 655f 7374 7261 7465 6779 0a20 nable_strategy.
│ │ │ +0005c3f0: 202d 206c 6f77 5f63 6f6d 706c 6578 6974 - low_complexit
│ │ │ +0005c400: 790a 2020 2d20 6c6f 775f 6469 7372 7570 y. - low_disrup
│ │ │ +0005c410: 7469 6f6e 0a20 202d 206d 6564 6975 6d5f tion. - medium_
│ │ │ +0005c420: 7365 7665 7269 7479 0a20 202d 206e 6f5f severity. - no_
│ │ │ +0005c430: 7265 626f 6f74 5f6e 6565 6465 640a 2020 reboot_needed.
│ │ │ +0005c440: 2d20 7061 636b 6167 655f 7061 6d5f 7077 - package_pam_pw
│ │ │ +0005c450: 7175 616c 6974 795f 696e 7374 616c 6c65 quality_installe
│ │ │ +0005c460: 640a 0a2d 206e 616d 653a 2045 6e73 7572 d..- name: Ensur
│ │ │ +0005c470: 6520 6c69 6270 616d 2d70 7771 7561 6c69 e libpam-pwquali
│ │ │ +0005c480: 7479 2069 7320 696e 7374 616c 6c65 640a ty is installed.
│ │ │ +0005c490: 2020 616e 7369 626c 652e 6275 696c 7469 ansible.builti
│ │ │ +0005c4a0: 6e2e 7061 636b 6167 653a 0a20 2020 206e n.package:. n
│ │ │ +0005c4b0: 616d 653a 206c 6962 7061 6d2d 7077 7175 ame: libpam-pwqu
│ │ │ +0005c4c0: 616c 6974 790a 2020 2020 7374 6174 653a ality. state:
│ │ │ +0005c4d0: 2070 7265 7365 6e74 0a20 2077 6865 6e3a present. when:
│ │ │ +0005c4e0: 2027 226c 6962 7061 6d2d 7275 6e74 696d '"libpam-runtim
│ │ │ +0005c4f0: 6522 2069 6e20 616e 7369 626c 655f 6661 e" in ansible_fa
│ │ │ +0005c500: 6374 732e 7061 636b 6167 6573 270a 2020 cts.packages'.
│ │ │ +0005c510: 7461 6773 3a0a 2020 2d20 656e 6162 6c65 tags:. - enable
│ │ │ +0005c520: 5f73 7472 6174 6567 790a 2020 2d20 6c6f _strategy. - lo
│ │ │ +0005c530: 775f 636f 6d70 6c65 7869 7479 0a20 202d w_complexity. -
│ │ │ +0005c540: 206c 6f77 5f64 6973 7275 7074 696f 6e0a low_disruption.
│ │ │ +0005c550: 2020 2d20 6d65 6469 756d 5f73 6576 6572 - medium_sever
│ │ │ +0005c560: 6974 790a 2020 2d20 6e6f 5f72 6562 6f6f ity. - no_reboo
│ │ │ +0005c570: 745f 6e65 6564 6564 0a20 202d 2070 6163 t_needed. - pac
│ │ │ +0005c580: 6b61 6765 5f70 616d 5f70 7771 7561 6c69 kage_pam_pwquali
│ │ │ +0005c590: 7479 5f69 6e73 7461 6c6c 6564 0a3c 2f63 ty_installed.
│ │ │ +0005c5b0: 3c61 2063 6c61 7373 3d22 6274 6e20 6274 Reme
│ │ │ +0005c650: 6469 6174 696f 6e20 5075 7070 6574 2073 diation Puppet s
│ │ │ +0005c660: 6e69 7070 6574 20e2 87b2 3c2f 613e 3c62 nippet ...| Compl
│ │ │ +0005c6f0: 6578 6974 793a 3c2f 7468 3e3c 7464 3e6c exity: | l
│ │ │ +0005c700: 6f77 3c2f 7464 3e3c 2f74 723e 3c74 723e ow |
|---|
│ │ │ +0005c710: 3c74 683e 4469 7372 7570 7469 6f6e 3a3c | Disruption:<
│ │ │ +0005c720: 2f74 683e 3c74 643e 6c6f 773c 2f74 643e /th> | low |
│ │ │ +0005c730: 3c2f 7472 3e3c 7472 3e3c 7468 3e52 6562
| Reb
│ │ │ +0005c740: 6f6f 743a 3c2f 7468 3e3c 7464 3e66 616c oot: | fal
│ │ │ +0005c750: 7365 3c2f 7464 3e3c 2f74 723e 3c74 723e se |
|---|
│ │ │ +0005c760: 3c74 683e 5374 7261 7465 6779 3a3c 2f74 | Strategy: | enable |
include
│ │ │ +0005c7a0: 2069 6e73 7461 6c6c 5f6c 6962 7061 6d2d install_libpam-
│ │ │ +0005c7b0: 7077 7175 616c 6974 790a 0a63 6c61 7373 pwquality..class
│ │ │ +0005c7c0: 2069 6e73 7461 6c6c 5f6c 6962 7061 6d2d install_libpam-
│ │ │ +0005c7d0: 7077 7175 616c 6974 7920 7b0a 2020 7061 pwquality {. pa
│ │ │ +0005c7e0: 636b 6167 6520 7b20 276c 6962 7061 6d2d ckage { 'libpam-
│ │ │ +0005c7f0: 7077 7175 616c 6974 7927 3a0a 2020 2020 pwquality':.
│ │ │ +0005c800: 656e 7375 7265 203d 2667 743b 2027 696e ensure => 'in
│ │ │ +0005c810: 7374 616c 6c65 6427 2c0a 2020 7d0a 7d0a stalled',. }.}.
│ │ │ +0005c820: 3c2f 636f 6465 3e3c 2f70 7265 3e3c 2f64 R
│ │ │ +0005c8d0: 656d 6564 6961 7469 6f6e 204f 5342 7569 emediation OSBui
│ │ │ +0005c8e0: 6c64 2042 6c75 6570 7269 6e74 2073 6e69 ld Blueprint sni
│ │ │ +0005c8f0: 7070 6574 20e2 87b2 3c2f 613e 3c62 723e ppet ...
│ │ │ +0005c900: 3c64 6976 2063 6c61 7373 3d22 7061 6e65
<
│ │ │ +0005c930: 7072 653e 3c63 6f64 653e 0a5b 5b70 6163 pre>
.[[pac
│ │ │ +0005c940: 6b61 6765 735d 5d0a 6e61 6d65 203d 2022 kages]].name = "
│ │ │ +0005c950: 6c69 6270 616d 2d70 7771 7561 6c69 7479 libpam-pwquality
│ │ │ +0005c960: 220a 7665 7273 696f 6e20 3d20 222a 220a ".version = "*".
│ │ │ 0005c970: 3c2f 636f 6465 3e3c 2f70 7265 3e3c 2f64 Remedi
│ │ │ -0006ad30: 6174 696f 6e20 5075 7070 6574 2073 6e69 ation Puppet sni
│ │ │ -0006ad40: 7070 6574 20e2 87b2 3c2f 613e 3c62 723e ppet ...
│ │ │ -0006ad50: 3c64 6976 2063 6c61 7373 3d22 7061 6e65
<
│ │ │ -0006ad80: 7461 626c 6520 636c 6173 733d 2274 6162 table class="tab
│ │ │ -0006ad90: 6c65 2074 6162 6c65 2d73 7472 6970 6564 le table-striped
│ │ │ -0006ada0: 2074 6162 6c65 2d62 6f72 6465 7265 6420 table-bordered
│ │ │ -0006adb0: 7461 626c 652d 636f 6e64 656e 7365 6422 table-condensed"
│ │ │ -0006adc0: 3e3c 7472 3e3c 7468 3e43 6f6d 706c 6578 >
| Complex
│ │ │ -0006add0: 6974 793a 3c2f 7468 3e3c 7464 3e6c 6f77 ity: | low
│ │ │ -0006ade0: 3c2f 7464 3e3c 2f74 723e 3c74 723e 3c74 |
|---|
Disruption:| low |
│ │ │ -0006ae10: 7472 3e3c 7472 3e3c 7468 3e52 6562 6f6f tr>
| Reboo
│ │ │ -0006ae20: 743a 3c2f 7468 3e3c 7464 3e66 616c 7365 t: | false
│ │ │ -0006ae30: 3c2f 7464 3e3c 2f74 723e 3c74 723e 3c74 |
|---|
Strategy:
│ │ │ -0006ae50: 3c74 643e 6469 7361 626c 653c 2f74 643e | disable |
│ │ │ -0006ae60: 3c2f 7472 3e3c 2f74 6162 6c65 3e3c 7072
.include
│ │ │ -0006ae80: 2072 656d 6f76 655f 6468 6370 0a0a 636c remove_dhcp..cl
│ │ │ -0006ae90: 6173 7320 7265 6d6f 7665 5f64 6863 7020 ass remove_dhcp
│ │ │ -0006aea0: 7b0a 2020 7061 636b 6167 6520 7b20 2764 {. package { 'd
│ │ │ -0006aeb0: 6863 7027 3a0a 2020 2020 656e 7375 7265 hcp':. ensure
│ │ │ -0006aec0: 203d 2667 743b 2027 7075 7267 6564 272c => 'purged',
│ │ │ -0006aed0: 0a20 207d 0a7d 0a3c 2f63 6f64 653e 3c2f . }.}.
│ │ │ -0006aee0: 7072 653e 3c2f 6469 763e 3c61 2063 6c61 pre> Remediatio
│ │ │ -0006af90: 6e20 416e 7369 626c 6520 736e 6970 7065 n Ansible snippe
│ │ │ -0006afa0: 7420 e287 b23c 2f61 3e3c 6272 3e3c 6469 t ...
Complexity
│ │ │ -0006b030: 3a3c 2f74 683e 3c74 643e 6c6f 773c 2f74 : | low | | D
│ │ │ -0006b050: 6973 7275 7074 696f 6e3a 3c2f 7468 3e3c isruption: | <
│ │ │ -0006b060: 7464 3e6c 6f77 3c2f 7464 3e3c 2f74 723e td>low
│ │ │ -0006b070: 3c74 723e 3c74 683e 5265 626f 6f74 3a3c | Reboot:<
│ │ │ -0006b080: 2f74 683e 3c74 643e 6661 6c73 653c 2f74 /th> | false |
|---|
| S
│ │ │ -0006b0a0: 7472 6174 6567 793a 3c2f 7468 3e3c 7464 trategy: | disable |
|---|
<
│ │ │ -0006b0d0: 636f 6465 3e2d 206e 616d 653a 2027 556e code>- name: 'Un
│ │ │ -0006b0e0: 696e 7374 616c 6c20 4448 4350 2053 6572 install DHCP Ser
│ │ │ -0006b0f0: 7665 7220 5061 636b 6167 653a 2045 6e73 ver Package: Ens
│ │ │ -0006b100: 7572 6520 6468 6370 2069 7320 7265 6d6f ure dhcp is remo
│ │ │ -0006b110: 7665 6427 0a20 2061 6e73 6962 6c65 2e62 ved'. ansible.b
│ │ │ -0006b120: 7569 6c74 696e 2e70 6163 6b61 6765 3a0a uiltin.package:.
│ │ │ -0006b130: 2020 2020 6e61 6d65 3a20 6468 6370 0a20 name: dhcp.
│ │ │ -0006b140: 2020 2073 7461 7465 3a20 6162 7365 6e74 state: absent
│ │ │ -0006b150: 0a20 2074 6167 733a 0a20 202d 204e 4953 . tags:. - NIS
│ │ │ -0006b160: 542d 3830 302d 3533 2d43 4d2d 3628 6129 T-800-53-CM-6(a)
│ │ │ -0006b170: 0a20 202d 204e 4953 542d 3830 302d 3533 . - NIST-800-53
│ │ │ -0006b180: 2d43 4d2d 3728 6129 0a20 202d 204e 4953 -CM-7(a). - NIS
│ │ │ -0006b190: 542d 3830 302d 3533 2d43 4d2d 3728 6229 T-800-53-CM-7(b)
│ │ │ -0006b1a0: 0a20 202d 2050 4349 2d44 5353 7634 2d32 . - PCI-DSSv4-2
│ │ │ -0006b1b0: 2e32 0a20 202d 2050 4349 2d44 5353 7634 .2. - PCI-DSSv4
│ │ │ -0006b1c0: 2d32 2e32 2e34 0a20 202d 2064 6973 6162 -2.2.4. - disab
│ │ │ -0006b1d0: 6c65 5f73 7472 6174 6567 790a 2020 2d20 le_strategy. -
│ │ │ -0006b1e0: 6c6f 775f 636f 6d70 6c65 7869 7479 0a20 low_complexity.
│ │ │ -0006b1f0: 202d 206c 6f77 5f64 6973 7275 7074 696f - low_disruptio
│ │ │ -0006b200: 6e0a 2020 2d20 6d65 6469 756d 5f73 6576 n. - medium_sev
│ │ │ -0006b210: 6572 6974 790a 2020 2d20 6e6f 5f72 6562 erity. - no_reb
│ │ │ -0006b220: 6f6f 745f 6e65 6564 6564 0a20 202d 2070 oot_needed. - p
│ │ │ -0006b230: 6163 6b61 6765 5f64 6863 705f 7265 6d6f ackage_dhcp_remo
│ │ │ -0006b240: 7665 640a 3c2f 636f 6465 3e3c 2f70 7265 ved.
│ │ │ +0006ad80: 3c74 6162 6c65 2063 6c61 7373 3d22 7461
| Comple
│ │ │ +0006add0: 7869 7479 3a3c 2f74 683e 3c74 643e 6c6f xity: | lo
│ │ │ +0006ade0: 773c 2f74 643e 3c2f 7472 3e3c 7472 3e3c w |
|---|
<
│ │ │ +0006adf0: 7468 3e44 6973 7275 7074 696f 6e3a 3c2f th>Disruption:
│ │ │ +0006ae00: 7468 3e3c 7464 3e6c 6f77 3c2f 7464 3e3c th>| low | <
│ │ │ +0006ae10: 2f74 723e 3c74 723e 3c74 683e 5265 626f /tr>
| Rebo
│ │ │ +0006ae20: 6f74 3a3c 2f74 683e 3c74 643e 6661 6c73 ot: | fals
│ │ │ +0006ae30: 653c 2f74 643e 3c2f 7472 3e3c 7472 3e3c e |
|---|
<
│ │ │ +0006ae40: 7468 3e53 7472 6174 6567 793a 3c2f 7468 th>Strategy:| disable |
- name:
│ │ │ +0006ae80: 2027 556e 696e 7374 616c 6c20 4448 4350 'Uninstall DHCP
│ │ │ +0006ae90: 2053 6572 7665 7220 5061 636b 6167 653a Server Package:
│ │ │ +0006aea0: 2045 6e73 7572 6520 6468 6370 2069 7320 Ensure dhcp is
│ │ │ +0006aeb0: 7265 6d6f 7665 6427 0a20 2061 6e73 6962 removed'. ansib
│ │ │ +0006aec0: 6c65 2e62 7569 6c74 696e 2e70 6163 6b61 le.builtin.packa
│ │ │ +0006aed0: 6765 3a0a 2020 2020 6e61 6d65 3a20 6468 ge:. name: dh
│ │ │ +0006aee0: 6370 0a20 2020 2073 7461 7465 3a20 6162 cp. state: ab
│ │ │ +0006aef0: 7365 6e74 0a20 2074 6167 733a 0a20 202d sent. tags:. -
│ │ │ +0006af00: 204e 4953 542d 3830 302d 3533 2d43 4d2d NIST-800-53-CM-
│ │ │ +0006af10: 3628 6129 0a20 202d 204e 4953 542d 3830 6(a). - NIST-80
│ │ │ +0006af20: 302d 3533 2d43 4d2d 3728 6129 0a20 202d 0-53-CM-7(a). -
│ │ │ +0006af30: 204e 4953 542d 3830 302d 3533 2d43 4d2d NIST-800-53-CM-
│ │ │ +0006af40: 3728 6229 0a20 202d 2050 4349 2d44 5353 7(b). - PCI-DSS
│ │ │ +0006af50: 7634 2d32 2e32 0a20 202d 2050 4349 2d44 v4-2.2. - PCI-D
│ │ │ +0006af60: 5353 7634 2d32 2e32 2e34 0a20 202d 2064 SSv4-2.2.4. - d
│ │ │ +0006af70: 6973 6162 6c65 5f73 7472 6174 6567 790a isable_strategy.
│ │ │ +0006af80: 2020 2d20 6c6f 775f 636f 6d70 6c65 7869 - low_complexi
│ │ │ +0006af90: 7479 0a20 202d 206c 6f77 5f64 6973 7275 ty. - low_disru
│ │ │ +0006afa0: 7074 696f 6e0a 2020 2d20 6d65 6469 756d ption. - medium
│ │ │ +0006afb0: 5f73 6576 6572 6974 790a 2020 2d20 6e6f _severity. - no
│ │ │ +0006afc0: 5f72 6562 6f6f 745f 6e65 6564 6564 0a20 _reboot_needed.
│ │ │ +0006afd0: 202d 2070 6163 6b61 6765 5f64 6863 705f - package_dhcp_
│ │ │ +0006afe0: 7265 6d6f 7665 640a 3c2f 636f 6465 3e3c removed.<
│ │ │ +0006aff0: 2f70 7265 3e3c 2f64 6976 3e3c 6120 636c /pre>
Remediati
│ │ │ +0006b0a0: 6f6e 2050 7570 7065 7420 736e 6970 7065 on Puppet snippe
│ │ │ +0006b0b0: 7420 e287 b23c 2f61 3e3c 6272 3e3c 6469 t ...Complexity
│ │ │ +0006b140: 3a3c 2f74 683e 3c74 643e 6c6f 773c 2f74 : | low | | D
│ │ │ +0006b160: 6973 7275 7074 696f 6e3a 3c2f 7468 3e3c isruption: | <
│ │ │ +0006b170: 7464 3e6c 6f77 3c2f 7464 3e3c 2f74 723e td>low
│ │ │ +0006b180: 3c74 723e 3c74 683e 5265 626f 6f74 3a3c | Reboot:<
│ │ │ +0006b190: 2f74 683e 3c74 643e 6661 6c73 653c 2f74 /th> | false |
|---|
| S
│ │ │ +0006b1b0: 7472 6174 6567 793a 3c2f 7468 3e3c 7464 trategy: | disable |
|---|
<
│ │ │ +0006b1e0: 636f 6465 3e0a 696e 636c 7564 6520 7265 code>.include re
│ │ │ +0006b1f0: 6d6f 7665 5f64 6863 700a 0a63 6c61 7373 move_dhcp..class
│ │ │ +0006b200: 2072 656d 6f76 655f 6468 6370 207b 0a20 remove_dhcp {.
│ │ │ +0006b210: 2070 6163 6b61 6765 207b 2027 6468 6370 package { 'dhcp
│ │ │ +0006b220: 273a 0a20 2020 2065 6e73 7572 6520 3d26 ':. ensure =&
│ │ │ +0006b230: 6774 3b20 2770 7572 6765 6427 2c0a 2020 gt; 'purged',.
│ │ │ +0006b240: 7d0a 7d0a 3c2f 636f 6465 3e3c 2f70 7265 }.}. Remed
│ │ │ -0006bfd0: 6961 7469 6f6e 2050 7570 7065 7420 736e iation Puppet sn
│ │ │ -0006bfe0: 6970 7065 7420 e287 b23c 2f61 3e3c 6272 ippet ...
│ │ │ -0006c020: 3c74 6162 6c65 2063 6c61 7373 3d22 7461
| Comple
│ │ │ -0006c070: 7869 7479 3a3c 2f74 683e 3c74 643e 6c6f xity: | lo
│ │ │ -0006c080: 773c 2f74 643e 3c2f 7472 3e3c 7472 3e3c w |
|---|
<
│ │ │ -0006c090: 7468 3e44 6973 7275 7074 696f 6e3a 3c2f th>Disruption:
│ │ │ -0006c0a0: 7468 3e3c 7464 3e6c 6f77 3c2f 7464 3e3c th>| low | <
│ │ │ -0006c0b0: 2f74 723e 3c74 723e 3c74 683e 5265 626f /tr>
| Rebo
│ │ │ -0006c0c0: 6f74 3a3c 2f74 683e 3c74 643e 6661 6c73 ot: | fals
│ │ │ -0006c0d0: 653c 2f74 643e 3c2f 7472 3e3c 7472 3e3c e |
|---|
<
│ │ │ -0006c0e0: 7468 3e53 7472 6174 6567 793a 3c2f 7468 th>Strategy:| disable |
.includ
│ │ │ -0006c120: 6520 7265 6d6f 7665 5f6b 6561 0a0a 636c e remove_kea..cl
│ │ │ -0006c130: 6173 7320 7265 6d6f 7665 5f6b 6561 207b ass remove_kea {
│ │ │ -0006c140: 0a20 2070 6163 6b61 6765 207b 2027 6b65 . package { 'ke
│ │ │ -0006c150: 6127 3a0a 2020 2020 656e 7375 7265 203d a':. ensure =
│ │ │ -0006c160: 2667 743b 2027 7075 7267 6564 272c 0a20 > 'purged',.
│ │ │ -0006c170: 207d 0a7d 0a3c 2f63 6f64 653e 3c2f 7072 }.}.
Remediation
│ │ │ -0006c230: 416e 7369 626c 6520 736e 6970 7065 7420 Ansible snippet
│ │ │ -0006c240: e287 b23c 2f61 3e3c 6272 3e3c 6469 7620 ...
│ │ │ -0006c2c0: 3c74 683e 436f 6d70 6c65 7869 7479 3a3c | Complexity:<
│ │ │ -0006c2d0: 2f74 683e 3c74 643e 6c6f 773c 2f74 643e /th> | low |
│ │ │ -0006c2e0: 3c2f 7472 3e3c 7472 3e3c 7468 3e44 6973
| Dis
│ │ │ -0006c2f0: 7275 7074 696f 6e3a 3c2f 7468 3e3c 7464 ruption: | low |
|---|
Reboot: | false |
│ │ │ -0006c330: 3c2f 7472 3e3c 7472 3e3c 7468 3e53 7472 | Str
│ │ │ -0006c340: 6174 6567 793a 3c2f 7468 3e3c 7464 3e64 ategy: | d
│ │ │ -0006c350: 6973 6162 6c65 3c2f 7464 3e3c 2f74 723e isable |
│ │ │ -0006c360: 3c2f 7461 626c 653e 3c70 7265 3e3c 636f
- name: 'Unin
│ │ │ -0006c380: 7374 616c 6c20 6b65 6120 5061 636b 6167 stall kea Packag
│ │ │ -0006c390: 653a 2045 6e73 7572 6520 6b65 6120 6973 e: Ensure kea is
│ │ │ -0006c3a0: 2072 656d 6f76 6564 270a 2020 616e 7369 removed'. ansi
│ │ │ -0006c3b0: 626c 652e 6275 696c 7469 6e2e 7061 636b ble.builtin.pack
│ │ │ -0006c3c0: 6167 653a 0a20 2020 206e 616d 653a 206b age:. name: k
│ │ │ -0006c3d0: 6561 0a20 2020 2073 7461 7465 3a20 6162 ea. state: ab
│ │ │ -0006c3e0: 7365 6e74 0a20 2074 6167 733a 0a20 202d sent. tags:. -
│ │ │ -0006c3f0: 2064 6973 6162 6c65 5f73 7472 6174 6567 disable_strateg
│ │ │ -0006c400: 790a 2020 2d20 6c6f 775f 636f 6d70 6c65 y. - low_comple
│ │ │ -0006c410: 7869 7479 0a20 202d 206c 6f77 5f64 6973 xity. - low_dis
│ │ │ -0006c420: 7275 7074 696f 6e0a 2020 2d20 6d65 6469 ruption. - medi
│ │ │ -0006c430: 756d 5f73 6576 6572 6974 790a 2020 2d20 um_severity. -
│ │ │ -0006c440: 6e6f 5f72 6562 6f6f 745f 6e65 6564 6564 no_reboot_needed
│ │ │ -0006c450: 0a20 202d 2070 6163 6b61 6765 5f6b 6561 . - package_kea
│ │ │ -0006c460: 5f72 656d 6f76 6564 0a3c 2f63 6f64 653e _removed.
│ │ │ +0006bfd0: 6961 7469 6f6e 2041 6e73 6962 6c65 2073 iation Ansible s
│ │ │ +0006bfe0: 6e69 7070 6574 20e2 87b2 3c2f 613e 3c62 nippet ...| Compl
│ │ │ +0006c070: 6578 6974 793a 3c2f 7468 3e3c 7464 3e6c exity: | l
│ │ │ +0006c080: 6f77 3c2f 7464 3e3c 2f74 723e 3c74 723e ow |
|---|
│ │ │ +0006c090: 3c74 683e 4469 7372 7570 7469 6f6e 3a3c | Disruption:<
│ │ │ +0006c0a0: 2f74 683e 3c74 643e 6c6f 773c 2f74 643e /th> | low |
│ │ │ +0006c0b0: 3c2f 7472 3e3c 7472 3e3c 7468 3e52 6562
| Reb
│ │ │ +0006c0c0: 6f6f 743a 3c2f 7468 3e3c 7464 3e66 616c oot: | fal
│ │ │ +0006c0d0: 7365 3c2f 7464 3e3c 2f74 723e 3c74 723e se |
|---|
│ │ │ +0006c0e0: 3c74 683e 5374 7261 7465 6779 3a3c 2f74 | Strategy: | disable |
<
│ │ │ +0006c110: 7072 653e 3c63 6f64 653e 2d20 6e61 6d65 pre>
- name
│ │ │ +0006c120: 3a20 2755 6e69 6e73 7461 6c6c 206b 6561 : 'Uninstall kea
│ │ │ +0006c130: 2050 6163 6b61 6765 3a20 456e 7375 7265 Package: Ensure
│ │ │ +0006c140: 206b 6561 2069 7320 7265 6d6f 7665 6427 kea is removed'
│ │ │ +0006c150: 0a20 2061 6e73 6962 6c65 2e62 7569 6c74 . ansible.built
│ │ │ +0006c160: 696e 2e70 6163 6b61 6765 3a0a 2020 2020 in.package:.
│ │ │ +0006c170: 6e61 6d65 3a20 6b65 610a 2020 2020 7374 name: kea. st
│ │ │ +0006c180: 6174 653a 2061 6273 656e 740a 2020 7461 ate: absent. ta
│ │ │ +0006c190: 6773 3a0a 2020 2d20 6469 7361 626c 655f gs:. - disable_
│ │ │ +0006c1a0: 7374 7261 7465 6779 0a20 202d 206c 6f77 strategy. - low
│ │ │ +0006c1b0: 5f63 6f6d 706c 6578 6974 790a 2020 2d20 _complexity. -
│ │ │ +0006c1c0: 6c6f 775f 6469 7372 7570 7469 6f6e 0a20 low_disruption.
│ │ │ +0006c1d0: 202d 206d 6564 6975 6d5f 7365 7665 7269 - medium_severi
│ │ │ +0006c1e0: 7479 0a20 202d 206e 6f5f 7265 626f 6f74 ty. - no_reboot
│ │ │ +0006c1f0: 5f6e 6565 6465 640a 2020 2d20 7061 636b _needed. - pack
│ │ │ +0006c200: 6167 655f 6b65 615f 7265 6d6f 7665 640a age_kea_removed.
│ │ │ +0006c210: 3c2f 636f 6465 3e3c 2f70 7265 3e3c 2f64 R
│ │ │ +0006c2c0: 656d 6564 6961 7469 6f6e 2050 7570 7065 emediation Puppe
│ │ │ +0006c2d0: 7420 736e 6970 7065 7420 e287 b23c 2f61 t snippet ...| Co
│ │ │ +0006c360: 6d70 6c65 7869 7479 3a3c 2f74 683e 3c74 mplexity: | low
<
│ │ │ +0006c380: 7472 3e3c 7468 3e44 6973 7275 7074 696f tr>Disruptio
│ │ │ +0006c390: 6e3a 3c2f 7468 3e3c 7464 3e6c 6f77 3c2f n: | low
│ │ │ +0006c3a0: 7464 3e3c 2f74 723e 3c74 723e 3c74 683e td> | |
│ │ │ +0006c3b0: 5265 626f 6f74 3a3c 2f74 683e 3c74 643e Reboot: |
│ │ │ +0006c3c0: 6661 6c73 653c 2f74 643e 3c2f 7472 3e3c false |
<
│ │ │ +0006c3d0: 7472 3e3c 7468 3e53 7472 6174 6567 793a tr>Strategy:
│ │ │ +0006c3e0: 3c2f 7468 3e3c 7464 3e64 6973 6162 6c65 | disable
│ │ │ +0006c3f0: 3c2f 7464 3e3c 2f74 723e 3c2f 7461 626c | .in
│ │ │ +0006c410: 636c 7564 6520 7265 6d6f 7665 5f6b 6561 clude remove_kea
│ │ │ +0006c420: 0a0a 636c 6173 7320 7265 6d6f 7665 5f6b ..class remove_k
│ │ │ +0006c430: 6561 207b 0a20 2070 6163 6b61 6765 207b ea {. package {
│ │ │ +0006c440: 2027 6b65 6127 3a0a 2020 2020 656e 7375 'kea':. ensu
│ │ │ +0006c450: 7265 203d 2667 743b 2027 7075 7267 6564 re => 'purged
│ │ │ +0006c460: 272c 0a20 207d 0a7d 0a3c 2f63 6f64 653e ',. }.}.
│ │ │ 0006c470: 3c2f 7072 653e 3c2f 6469 763e 3c61 2063
Reme
│ │ │ -0006e130: 6469 6174 696f 6e20 5075 7070 6574 2073 diation Puppet s
│ │ │ -0006e140: 6e69 7070 6574 20e2 87b2 3c2f 613e 3c62 nippet ...| Compl
│ │ │ -0006e1d0: 6578 6974 793a 3c2f 7468 3e3c 7464 3e6c exity: | l
│ │ │ -0006e1e0: 6f77 3c2f 7464 3e3c 2f74 723e 3c74 723e ow |
|---|
│ │ │ -0006e1f0: 3c74 683e 4469 7372 7570 7469 6f6e 3a3c | Disruption:<
│ │ │ -0006e200: 2f74 683e 3c74 643e 6c6f 773c 2f74 643e /th> | low |
│ │ │ -0006e210: 3c2f 7472 3e3c 7472 3e3c 7468 3e52 6562
| Reb
│ │ │ -0006e220: 6f6f 743a 3c2f 7468 3e3c 7464 3e66 616c oot: | fal
│ │ │ -0006e230: 7365 3c2f 7464 3e3c 2f74 723e 3c74 723e se |
|---|
│ │ │ -0006e240: 3c74 683e 5374 7261 7465 6779 3a3c 2f74 | Strategy: | disable |
<
│ │ │ -0006e270: 7072 653e 3c63 6f64 653e 0a69 6e63 6c75 pre>
.inclu
│ │ │ -0006e280: 6465 2072 656d 6f76 655f 7365 6e64 6d61 de remove_sendma
│ │ │ -0006e290: 696c 0a0a 636c 6173 7320 7265 6d6f 7665 il..class remove
│ │ │ -0006e2a0: 5f73 656e 646d 6169 6c20 7b0a 2020 7061 _sendmail {. pa
│ │ │ -0006e2b0: 636b 6167 6520 7b20 2773 656e 646d 6169 ckage { 'sendmai
│ │ │ -0006e2c0: 6c27 3a0a 2020 2020 656e 7375 7265 203d l':. ensure =
│ │ │ -0006e2d0: 2667 743b 2027 7075 7267 6564 272c 0a20 > 'purged',.
│ │ │ -0006e2e0: 207d 0a7d 0a3c 2f63 6f64 653e 3c2f 7072 }.}. Remediation
│ │ │ -0006e3a0: 416e 7369 626c 6520 736e 6970 7065 7420 Ansible snippet
│ │ │ -0006e3b0: e287 b23c 2f61 3e3c 6272 3e3c 6469 7620 ...
│ │ │ -0006e430: 3c74 683e 436f 6d70 6c65 7869 7479 3a3c | Complexity:<
│ │ │ -0006e440: 2f74 683e 3c74 643e 6c6f 773c 2f74 643e /th> | low |
│ │ │ -0006e450: 3c2f 7472 3e3c 7472 3e3c 7468 3e44 6973
| Dis
│ │ │ -0006e460: 7275 7074 696f 6e3a 3c2f 7468 3e3c 7464 ruption: | low |
|---|
Reboot: | false |
│ │ │ -0006e4a0: 3c2f 7472 3e3c 7472 3e3c 7468 3e53 7472 | Str
│ │ │ -0006e4b0: 6174 6567 793a 3c2f 7468 3e3c 7464 3e64 ategy: | d
│ │ │ -0006e4c0: 6973 6162 6c65 3c2f 7464 3e3c 2f74 723e isable |
│ │ │ -0006e4d0: 3c2f 7461 626c 653e 3c70 7265 3e3c 636f
- name: Gathe
│ │ │ -0006e4f0: 7220 7468 6520 7061 636b 6167 6520 6661 r the package fa
│ │ │ -0006e500: 6374 730a 2020 7061 636b 6167 655f 6661 cts. package_fa
│ │ │ -0006e510: 6374 733a 0a20 2020 206d 616e 6167 6572 cts:. manager
│ │ │ -0006e520: 3a20 6175 746f 0a20 2074 6167 733a 0a20 : auto. tags:.
│ │ │ -0006e530: 202d 204e 4953 542d 3830 302d 3533 2d43 - NIST-800-53-C
│ │ │ -0006e540: 4d2d 3628 6129 0a20 202d 204e 4953 542d M-6(a). - NIST-
│ │ │ -0006e550: 3830 302d 3533 2d43 4d2d 3728 6129 0a20 800-53-CM-7(a).
│ │ │ -0006e560: 202d 204e 4953 542d 3830 302d 3533 2d43 - NIST-800-53-C
│ │ │ -0006e570: 4d2d 3728 6229 0a20 202d 2064 6973 6162 M-7(b). - disab
│ │ │ -0006e580: 6c65 5f73 7472 6174 6567 790a 2020 2d20 le_strategy. -
│ │ │ -0006e590: 6c6f 775f 636f 6d70 6c65 7869 7479 0a20 low_complexity.
│ │ │ -0006e5a0: 202d 206c 6f77 5f64 6973 7275 7074 696f - low_disruptio
│ │ │ -0006e5b0: 6e0a 2020 2d20 6d65 6469 756d 5f73 6576 n. - medium_sev
│ │ │ -0006e5c0: 6572 6974 790a 2020 2d20 6e6f 5f72 6562 erity. - no_reb
│ │ │ -0006e5d0: 6f6f 745f 6e65 6564 6564 0a20 202d 2070 oot_needed. - p
│ │ │ -0006e5e0: 6163 6b61 6765 5f73 656e 646d 6169 6c5f ackage_sendmail_
│ │ │ -0006e5f0: 7265 6d6f 7665 640a 0a2d 206e 616d 653a removed..- name:
│ │ │ -0006e600: 2027 556e 696e 7374 616c 6c20 5365 6e64 'Uninstall Send
│ │ │ -0006e610: 6d61 696c 2050 6163 6b61 6765 3a20 456e mail Package: En
│ │ │ -0006e620: 7375 7265 2073 656e 646d 6169 6c20 6973 sure sendmail is
│ │ │ -0006e630: 2072 656d 6f76 6564 270a 2020 616e 7369 removed'. ansi
│ │ │ -0006e640: 626c 652e 6275 696c 7469 6e2e 7061 636b ble.builtin.pack
│ │ │ -0006e650: 6167 653a 0a20 2020 206e 616d 653a 2073 age:. name: s
│ │ │ -0006e660: 656e 646d 6169 6c0a 2020 2020 7374 6174 endmail. stat
│ │ │ -0006e670: 653a 2061 6273 656e 740a 2020 7768 656e e: absent. when
│ │ │ -0006e680: 3a20 2722 6c69 6e75 782d 6261 7365 2220 : '"linux-base"
│ │ │ -0006e690: 696e 2061 6e73 6962 6c65 5f66 6163 7473 in ansible_facts
│ │ │ -0006e6a0: 2e70 6163 6b61 6765 7327 0a20 2074 6167 .packages'. tag
│ │ │ -0006e6b0: 733a 0a20 202d 204e 4953 542d 3830 302d s:. - NIST-800-
│ │ │ -0006e6c0: 3533 2d43 4d2d 3628 6129 0a20 202d 204e 53-CM-6(a). - N
│ │ │ -0006e6d0: 4953 542d 3830 302d 3533 2d43 4d2d 3728 IST-800-53-CM-7(
│ │ │ -0006e6e0: 6129 0a20 202d 204e 4953 542d 3830 302d a). - NIST-800-
│ │ │ -0006e6f0: 3533 2d43 4d2d 3728 6229 0a20 202d 2064 53-CM-7(b). - d
│ │ │ -0006e700: 6973 6162 6c65 5f73 7472 6174 6567 790a isable_strategy.
│ │ │ -0006e710: 2020 2d20 6c6f 775f 636f 6d70 6c65 7869 - low_complexi
│ │ │ -0006e720: 7479 0a20 202d 206c 6f77 5f64 6973 7275 ty. - low_disru
│ │ │ -0006e730: 7074 696f 6e0a 2020 2d20 6d65 6469 756d ption. - medium
│ │ │ -0006e740: 5f73 6576 6572 6974 790a 2020 2d20 6e6f _severity. - no
│ │ │ -0006e750: 5f72 6562 6f6f 745f 6e65 6564 6564 0a20 _reboot_needed.
│ │ │ -0006e760: 202d 2070 6163 6b61 6765 5f73 656e 646d - package_sendm
│ │ │ -0006e770: 6169 6c5f 7265 6d6f 7665 640a 3c2f 636f ail_removed.<
│ │ │ +0006e150: 6272 3e3c 6469 7620 636c 6173 733d 2270 br>| Comp
│ │ │ +0006e1d0: 6c65 7869 7479 3a3c 2f74 683e 3c74 643e lexity: |
│ │ │ +0006e1e0: 6c6f 773c 2f74 643e 3c2f 7472 3e3c 7472 low |
|---|
| Disruption:
│ │ │ +0006e200: 3c2f 7468 3e3c 7464 3e6c 6f77 3c2f 7464 | low |
|---|
| Re
│ │ │ +0006e220: 626f 6f74 3a3c 2f74 683e 3c74 643e 6661 boot: | fa
│ │ │ +0006e230: 6c73 653c 2f74 643e 3c2f 7472 3e3c 7472 lse |
|---|
| Strategy:
│ │ │ +0006e250: 7468 3e3c 7464 3e64 6973 6162 6c65 3c2f th> | disable
│ │ │ +0006e260: 7464 3e3c 2f74 723e 3c2f 7461 626c 653e td> |
|---|
│ │ │ +0006e270: 3c70 7265 3e3c 636f 6465 3e2d 206e 616d
- nam
│ │ │ +0006e280: 653a 2047 6174 6865 7220 7468 6520 7061 e: Gather the pa
│ │ │ +0006e290: 636b 6167 6520 6661 6374 730a 2020 7061 ckage facts. pa
│ │ │ +0006e2a0: 636b 6167 655f 6661 6374 733a 0a20 2020 ckage_facts:.
│ │ │ +0006e2b0: 206d 616e 6167 6572 3a20 6175 746f 0a20 manager: auto.
│ │ │ +0006e2c0: 2074 6167 733a 0a20 202d 204e 4953 542d tags:. - NIST-
│ │ │ +0006e2d0: 3830 302d 3533 2d43 4d2d 3628 6129 0a20 800-53-CM-6(a).
│ │ │ +0006e2e0: 202d 204e 4953 542d 3830 302d 3533 2d43 - NIST-800-53-C
│ │ │ +0006e2f0: 4d2d 3728 6129 0a20 202d 204e 4953 542d M-7(a). - NIST-
│ │ │ +0006e300: 3830 302d 3533 2d43 4d2d 3728 6229 0a20 800-53-CM-7(b).
│ │ │ +0006e310: 202d 2064 6973 6162 6c65 5f73 7472 6174 - disable_strat
│ │ │ +0006e320: 6567 790a 2020 2d20 6c6f 775f 636f 6d70 egy. - low_comp
│ │ │ +0006e330: 6c65 7869 7479 0a20 202d 206c 6f77 5f64 lexity. - low_d
│ │ │ +0006e340: 6973 7275 7074 696f 6e0a 2020 2d20 6d65 isruption. - me
│ │ │ +0006e350: 6469 756d 5f73 6576 6572 6974 790a 2020 dium_severity.
│ │ │ +0006e360: 2d20 6e6f 5f72 6562 6f6f 745f 6e65 6564 - no_reboot_need
│ │ │ +0006e370: 6564 0a20 202d 2070 6163 6b61 6765 5f73 ed. - package_s
│ │ │ +0006e380: 656e 646d 6169 6c5f 7265 6d6f 7665 640a endmail_removed.
│ │ │ +0006e390: 0a2d 206e 616d 653a 2027 556e 696e 7374 .- name: 'Uninst
│ │ │ +0006e3a0: 616c 6c20 5365 6e64 6d61 696c 2050 6163 all Sendmail Pac
│ │ │ +0006e3b0: 6b61 6765 3a20 456e 7375 7265 2073 656e kage: Ensure sen
│ │ │ +0006e3c0: 646d 6169 6c20 6973 2072 656d 6f76 6564 dmail is removed
│ │ │ +0006e3d0: 270a 2020 616e 7369 626c 652e 6275 696c '. ansible.buil
│ │ │ +0006e3e0: 7469 6e2e 7061 636b 6167 653a 0a20 2020 tin.package:.
│ │ │ +0006e3f0: 206e 616d 653a 2073 656e 646d 6169 6c0a name: sendmail.
│ │ │ +0006e400: 2020 2020 7374 6174 653a 2061 6273 656e state: absen
│ │ │ +0006e410: 740a 2020 7768 656e 3a20 2722 6c69 6e75 t. when: '"linu
│ │ │ +0006e420: 782d 6261 7365 2220 696e 2061 6e73 6962 x-base" in ansib
│ │ │ +0006e430: 6c65 5f66 6163 7473 2e70 6163 6b61 6765 le_facts.package
│ │ │ +0006e440: 7327 0a20 2074 6167 733a 0a20 202d 204e s'. tags:. - N
│ │ │ +0006e450: 4953 542d 3830 302d 3533 2d43 4d2d 3628 IST-800-53-CM-6(
│ │ │ +0006e460: 6129 0a20 202d 204e 4953 542d 3830 302d a). - NIST-800-
│ │ │ +0006e470: 3533 2d43 4d2d 3728 6129 0a20 202d 204e 53-CM-7(a). - N
│ │ │ +0006e480: 4953 542d 3830 302d 3533 2d43 4d2d 3728 IST-800-53-CM-7(
│ │ │ +0006e490: 6229 0a20 202d 2064 6973 6162 6c65 5f73 b). - disable_s
│ │ │ +0006e4a0: 7472 6174 6567 790a 2020 2d20 6c6f 775f trategy. - low_
│ │ │ +0006e4b0: 636f 6d70 6c65 7869 7479 0a20 202d 206c complexity. - l
│ │ │ +0006e4c0: 6f77 5f64 6973 7275 7074 696f 6e0a 2020 ow_disruption.
│ │ │ +0006e4d0: 2d20 6d65 6469 756d 5f73 6576 6572 6974 - medium_severit
│ │ │ +0006e4e0: 790a 2020 2d20 6e6f 5f72 6562 6f6f 745f y. - no_reboot_
│ │ │ +0006e4f0: 6e65 6564 6564 0a20 202d 2070 6163 6b61 needed. - packa
│ │ │ +0006e500: 6765 5f73 656e 646d 6169 6c5f 7265 6d6f ge_sendmail_remo
│ │ │ +0006e510: 7665 640a 3c2f 636f 6465 3e3c 2f70 7265 ved.
Remediation P
│ │ │ +0006e5d0: 7570 7065 7420 736e 6970 7065 7420 e287 uppet snippet ..
│ │ │ +0006e5e0: b23c 2f61 3e3c 6272 3e3c 6469 7620 636c .
Complexity:| low |
│ │ │ +0006e680: 7472 3e3c 7472 3e3c 7468 3e44 6973 7275 tr>
| Disru
│ │ │ +0006e690: 7074 696f 6e3a 3c2f 7468 3e3c 7464 3e6c ption: | l
│ │ │ +0006e6a0: 6f77 3c2f 7464 3e3c 2f74 723e 3c74 723e ow |
|---|
│ │ │ +0006e6b0: 3c74 683e 5265 626f 6f74 3a3c 2f74 683e | Reboot: |
│ │ │ +0006e6c0: 3c74 643e 6661 6c73 653c 2f74 643e 3c2f false |
│ │ │ +0006e6d0: 7472 3e3c 7472 3e3c 7468 3e53 7472 6174 tr>
| Strat
│ │ │ +0006e6e0: 6567 793a 3c2f 7468 3e3c 7464 3e64 6973 egy: | dis
│ │ │ +0006e6f0: 6162 6c65 3c2f 7464 3e3c 2f74 723e 3c2f able |
│ │ │ +0006e700: 7461 626c 653e 3c70 7265 3e3c 636f 6465 table>.include remove
│ │ │ +0006e720: 5f73 656e 646d 6169 6c0a 0a63 6c61 7373 _sendmail..class
│ │ │ +0006e730: 2072 656d 6f76 655f 7365 6e64 6d61 696c remove_sendmail
│ │ │ +0006e740: 207b 0a20 2070 6163 6b61 6765 207b 2027 {. package { '
│ │ │ +0006e750: 7365 6e64 6d61 696c 273a 0a20 2020 2065 sendmail':. e
│ │ │ +0006e760: 6e73 7572 6520 3d26 6774 3b20 2770 7572 nsure => 'pur
│ │ │ +0006e770: 6765 6427 2c0a 2020 7d0a 7d0a 3c2f 636f ged',. }.}.
<
│ │ │ 0006e790: 6120 636c 6173 733d 2262 746e 2062 746e a class="btn btn
│ │ │ 0006e7a0: 2d73 7563 6365 7373 2220 6461 7461 2d74 -success" data-t
│ │ │ 0006e7b0: 6f67 676c 653d 2263 6f6c 6c61 7073 6522 oggle="collapse"
│ │ │ 0006e7c0: 2064 6174 612d 7461 7267 6574 3d22 2369 data-target="#i
│ │ │ 0006e7d0: 6437 3622 2074 6162 696e 6465 783d 2230 d76" tabindex="0
│ │ │ 0006e7e0: 2220 726f 6c65 3d22 6275 7474 6f6e 2220 " role="button"
│ │ │ @@ -28817,120 +28817,120 @@
│ │ │ 00070900: 6172 6765 743d 2223 6964 3738 2220 7461 arget="#id78" ta
│ │ │ 00070910: 6269 6e64 6578 3d22 3022 2072 6f6c 653d bindex="0" role=
│ │ │ 00070920: 2262 7574 746f 6e22 2061 7269 612d 6578 "button" aria-ex
│ │ │ 00070930: 7061 6e64 6564 3d22 6661 6c73 6522 2074 panded="false" t
│ │ │ 00070940: 6974 6c65 3d22 4163 7469 7661 7465 2074 itle="Activate t
│ │ │ 00070950: 6f20 7265 7665 616c 2220 6872 6566 3d22 o reveal" href="
│ │ │ 00070960: 2321 223e 5265 6d65 6469 6174 696f 6e20 #!">Remediation
│ │ │ -00070970: 5075 7070 6574 2073 6e69 7070 6574 20e2 Puppet snippet .
│ │ │ -00070980: 87b2 3c2f 613e 3c62 723e 3c64 6976 2063 ..
- name: '
│ │ │ +00074410: 556e 696e 7374 616c 6c20 7970 7365 7276 Uninstall ypserv
│ │ │ +00074420: 2050 6163 6b61 6765 3a20 456e 7375 7265 Package: Ensure
│ │ │ +00074430: 2079 7073 6572 7620 6973 2072 656d 6f76 ypserv is remov
│ │ │ +00074440: 6564 270a 2020 616e 7369 626c 652e 6275 ed'. ansible.bu
│ │ │ +00074450: 696c 7469 6e2e 7061 636b 6167 653a 0a20 iltin.package:.
│ │ │ +00074460: 2020 206e 616d 653a 2079 7073 6572 760a name: ypserv.
│ │ │ +00074470: 2020 2020 7374 6174 653a 2061 6273 656e state: absen
│ │ │ +00074480: 740a 2020 7461 6773 3a0a 2020 2d20 4e49 t. tags:. - NI
│ │ │ +00074490: 5354 2d38 3030 2d35 332d 434d 2d36 2861 ST-800-53-CM-6(a
│ │ │ +000744a0: 290a 2020 2d20 4e49 5354 2d38 3030 2d35 ). - NIST-800-5
│ │ │ +000744b0: 332d 434d 2d37 2861 290a 2020 2d20 4e49 3-CM-7(a). - NI
│ │ │ +000744c0: 5354 2d38 3030 2d35 332d 434d 2d37 2862 ST-800-53-CM-7(b
│ │ │ +000744d0: 290a 2020 2d20 4e49 5354 2d38 3030 2d35 ). - NIST-800-5
│ │ │ +000744e0: 332d 4941 2d35 2831 2928 6329 0a20 202d 3-IA-5(1)(c). -
│ │ │ +000744f0: 2050 4349 2d44 5353 2d52 6571 2d32 2e32 PCI-DSS-Req-2.2
│ │ │ +00074500: 2e32 0a20 202d 2050 4349 2d44 5353 7634 .2. - PCI-DSSv4
│ │ │ +00074510: 2d32 2e32 0a20 202d 2050 4349 2d44 5353 -2.2. - PCI-DSS
│ │ │ +00074520: 7634 2d32 2e32 2e34 0a20 202d 2064 6973 v4-2.2.4. - dis
│ │ │ +00074530: 6162 6c65 5f73 7472 6174 6567 790a 2020 able_strategy.
│ │ │ +00074540: 2d20 6869 6768 5f73 6576 6572 6974 790a - high_severity.
│ │ │ +00074550: 2020 2d20 6c6f 775f 636f 6d70 6c65 7869 - low_complexi
│ │ │ +00074560: 7479 0a20 202d 206c 6f77 5f64 6973 7275 ty. - low_disru
│ │ │ +00074570: 7074 696f 6e0a 2020 2d20 6e6f 5f72 6562 ption. - no_reb
│ │ │ +00074580: 6f6f 745f 6e65 6564 6564 0a20 202d 2070 oot_needed. - p
│ │ │ +00074590: 6163 6b61 6765 5f79 7073 6572 765f 7265 ackage_ypserv_re
│ │ │ +000745a0: 6d6f 7665 640a 3c2f 636f 6465 3e3c 2f70 moved.
Remediation
│ │ │ +00074660: 2050 7570 7065 7420 736e 6970 7065 7420 Puppet snippet
│ │ │ +00074670: e287 b23c 2f61 3e3c 6272 3e3c 6469 7620 ...
│ │ │ +000746f0: 3c74 683e 436f 6d70 6c65 7869 7479 3a3c | Complexity:<
│ │ │ +00074700: 2f74 683e 3c74 643e 6c6f 773c 2f74 643e /th> | low |
│ │ │ +00074710: 3c2f 7472 3e3c 7472 3e3c 7468 3e44 6973
| Dis
│ │ │ +00074720: 7275 7074 696f 6e3a 3c2f 7468 3e3c 7464 ruption: | low |
|---|
Reboot: | false |
│ │ │ +00074760: 3c2f 7472 3e3c 7472 3e3c 7468 3e53 7472 | Str
│ │ │ +00074770: 6174 6567 793a 3c2f 7468 3e3c 7464 3e64 ategy: | d
│ │ │ +00074780: 6973 6162 6c65 3c2f 7464 3e3c 2f74 723e isable |
│ │ │ +00074790: 3c2f 7461 626c 653e 3c70 7265 3e3c 636f
.include remo
│ │ │ +000747b0: 7665 5f79 7073 6572 760a 0a63 6c61 7373 ve_ypserv..class
│ │ │ +000747c0: 2072 656d 6f76 655f 7970 7365 7276 207b remove_ypserv {
│ │ │ +000747d0: 0a20 2070 6163 6b61 6765 207b 2027 7970 . package { 'yp
│ │ │ +000747e0: 7365 7276 273a 0a20 2020 2065 6e73 7572 serv':. ensur
│ │ │ +000747f0: 6520 3d26 6774 3b20 2770 7572 6765 6427 e => 'purged'
│ │ │ +00074800: 2c0a 2020 7d0a 7d0a 3c2f 636f 6465 3e3c ,. }.}.<
│ │ │ 00074810: 2f70 7265 3e3c 2f64 6976 3e3c 6120 636c /pre>
Remedia
│ │ │ -00076340: 7469 6f6e 2050 7570 7065 7420 736e 6970 tion Puppet snip
│ │ │ -00076350: 7065 7420 e287 b23c 2f61 3e3c 6272 3e3c pet ...
<
│ │ │ -00076360: 6469 7620 636c 6173 733d 2270 616e 656c div class="panel
│ │ │ -00076370: 2d63 6f6c 6c61 7073 6520 636f 6c6c 6170 -collapse collap
│ │ │ -00076380: 7365 2220 6964 3d22 6964 3930 223e 3c74 se" id="id90">
│ │ │ -000763d0: 3c74 723e 3c74 683e 436f 6d70 6c65 7869 | Complexi
│ │ │ -000763e0: 7479 3a3c 2f74 683e 3c74 643e 6c6f 773c ty: | low<
│ │ │ -000763f0: 2f74 643e 3c2f 7472 3e3c 7472 3e3c 7468 /td> |
|---|
| Disruption: | low |
|---|
| Reboot
│ │ │ -00076430: 3a3c 2f74 683e 3c74 643e 6661 6c73 653c : | false<
│ │ │ -00076440: 2f74 643e 3c2f 7472 3e3c 7472 3e3c 7468 /td> |
|---|
| Strategy: | <
│ │ │ -00076460: 7464 3e64 6973 6162 6c65 3c2f 7464 3e3c td>disable<
│ │ │ -00076470: 2f74 723e 3c2f 7461 626c 653e 3c70 7265 /tr>
|---|
.include
│ │ │ -00076490: 7265 6d6f 7665 5f72 7368 2d73 6572 7665 remove_rsh-serve
│ │ │ -000764a0: 720a 0a63 6c61 7373 2072 656d 6f76 655f r..class remove_
│ │ │ -000764b0: 7273 682d 7365 7276 6572 207b 0a20 2070 rsh-server {. p
│ │ │ -000764c0: 6163 6b61 6765 207b 2027 7273 682d 7365 ackage { 'rsh-se
│ │ │ -000764d0: 7276 6572 273a 0a20 2020 2065 6e73 7572 rver':. ensur
│ │ │ -000764e0: 6520 3d26 6774 3b20 2770 7572 6765 6427 e => 'purged'
│ │ │ -000764f0: 2c0a 2020 7d0a 7d0a 3c2f 636f 6465 3e3c ,. }.}.<
│ │ │ -00076500: 2f70 7265 3e3c 2f64 6976 3e3c 6120 636c /pre>
Remediati
│ │ │ -000765b0: 6f6e 2041 6e73 6962 6c65 2073 6e69 7070 on Ansible snipp
│ │ │ -000765c0: 6574 20e2 87b2 3c2f 613e 3c62 723e 3c64 et ...<
│ │ │ -00076640: 7472 3e3c 7468 3e43 6f6d 706c 6578 6974 tr>Complexit
│ │ │ -00076650: 793a 3c2f 7468 3e3c 7464 3e6c 6f77 3c2f y: | low
│ │ │ -00076660: 7464 3e3c 2f74 723e 3c74 723e 3c74 683e td> | |
│ │ │ -00076670: 4469 7372 7570 7469 6f6e 3a3c 2f74 683e Disruption: |
│ │ │ -00076680: 3c74 643e 6c6f 773c 2f74 643e 3c2f 7472 low |
|---|
| Reboot:
│ │ │ -000766a0: 3c2f 7468 3e3c 7464 3e66 616c 7365 3c2f | false
│ │ │ -000766b0: 7464 3e3c 2f74 723e 3c74 723e 3c74 683e td> |
|---|
|
│ │ │ -000766c0: 5374 7261 7465 6779 3a3c 2f74 683e 3c74 Strategy: | disable
│ │ │ -000766e0: 7472 3e3c 2f74 6162 6c65 3e3c 7072 653e tr>
|---|
│ │ │ -000766f0: 3c63 6f64 653e 2d20 6e61 6d65 3a20 2755 - name: 'U
│ │ │ -00076700: 6e69 6e73 7461 6c6c 2072 7368 2d73 6572 ninstall rsh-ser
│ │ │ -00076710: 7665 7220 5061 636b 6167 653a 2045 6e73 ver Package: Ens
│ │ │ -00076720: 7572 6520 7273 682d 7365 7276 6572 2069 ure rsh-server i
│ │ │ -00076730: 7320 7265 6d6f 7665 6427 0a20 2061 6e73 s removed'. ans
│ │ │ -00076740: 6962 6c65 2e62 7569 6c74 696e 2e70 6163 ible.builtin.pac
│ │ │ -00076750: 6b61 6765 3a0a 2020 2020 6e61 6d65 3a20 kage:. name:
│ │ │ -00076760: 7273 682d 7365 7276 6572 0a20 2020 2073 rsh-server. s
│ │ │ -00076770: 7461 7465 3a20 6162 7365 6e74 0a20 2074 tate: absent. t
│ │ │ -00076780: 6167 733a 0a20 202d 204e 4953 542d 3830 ags:. - NIST-80
│ │ │ -00076790: 302d 3533 2d43 4d2d 3628 6129 0a20 202d 0-53-CM-6(a). -
│ │ │ -000767a0: 204e 4953 542d 3830 302d 3533 2d43 4d2d NIST-800-53-CM-
│ │ │ -000767b0: 3728 6129 0a20 202d 204e 4953 542d 3830 7(a). - NIST-80
│ │ │ -000767c0: 302d 3533 2d43 4d2d 3728 6229 0a20 202d 0-53-CM-7(b). -
│ │ │ -000767d0: 204e 4953 542d 3830 302d 3533 2d49 412d NIST-800-53-IA-
│ │ │ -000767e0: 3528 3129 2863 290a 2020 2d20 5043 492d 5(1)(c). - PCI-
│ │ │ -000767f0: 4453 5376 342d 322e 320a 2020 2d20 5043 DSSv4-2.2. - PC
│ │ │ -00076800: 492d 4453 5376 342d 322e 322e 340a 2020 I-DSSv4-2.2.4.
│ │ │ -00076810: 2d20 6469 7361 626c 655f 7374 7261 7465 - disable_strate
│ │ │ -00076820: 6779 0a20 202d 2068 6967 685f 7365 7665 gy. - high_seve
│ │ │ -00076830: 7269 7479 0a20 202d 206c 6f77 5f63 6f6d rity. - low_com
│ │ │ -00076840: 706c 6578 6974 790a 2020 2d20 6c6f 775f plexity. - low_
│ │ │ -00076850: 6469 7372 7570 7469 6f6e 0a20 202d 206e disruption. - n
│ │ │ -00076860: 6f5f 7265 626f 6f74 5f6e 6565 6465 640a o_reboot_needed.
│ │ │ -00076870: 2020 2d20 7061 636b 6167 655f 7273 682d - package_rsh-
│ │ │ -00076880: 7365 7276 6572 5f72 656d 6f76 6564 0a3c server_removed.<
│ │ │ +00076340: 7469 6f6e 2041 6e73 6962 6c65 2073 6e69 tion Ansible sni
│ │ │ +00076350: 7070 6574 20e2 87b2 3c2f 613e 3c62 723e ppet ...
│ │ │ +00076360: 3c64 6976 2063 6c61 7373 3d22 7061 6e65 <
│ │ │ +00076390: 7461 626c 6520 636c 6173 733d 2274 6162 table class="tab
│ │ │ +000763a0: 6c65 2074 6162 6c65 2d73 7472 6970 6564 le table-striped
│ │ │ +000763b0: 2074 6162 6c65 2d62 6f72 6465 7265 6420 table-bordered
│ │ │ +000763c0: 7461 626c 652d 636f 6e64 656e 7365 6422 table-condensed"
│ │ │ +000763d0: 3e3c 7472 3e3c 7468 3e43 6f6d 706c 6578 >
| Complex
│ │ │ +000763e0: 6974 793a 3c2f 7468 3e3c 7464 3e6c 6f77 ity: | low
│ │ │ +000763f0: 3c2f 7464 3e3c 2f74 723e 3c74 723e 3c74 |
|---|
Disruption:| low |
│ │ │ +00076420: 7472 3e3c 7472 3e3c 7468 3e52 6562 6f6f tr>
| Reboo
│ │ │ +00076430: 743a 3c2f 7468 3e3c 7464 3e66 616c 7365 t: | false
│ │ │ +00076440: 3c2f 7464 3e3c 2f74 723e 3c74 723e 3c74 |
|---|
Strategy:
│ │ │ +00076460: 3c74 643e 6469 7361 626c 653c 2f74 643e | disable |
│ │ │ +00076470: 3c2f 7472 3e3c 2f74 6162 6c65 3e3c 7072
- name:
│ │ │ +00076490: 2755 6e69 6e73 7461 6c6c 2072 7368 2d73 'Uninstall rsh-s
│ │ │ +000764a0: 6572 7665 7220 5061 636b 6167 653a 2045 erver Package: E
│ │ │ +000764b0: 6e73 7572 6520 7273 682d 7365 7276 6572 nsure rsh-server
│ │ │ +000764c0: 2069 7320 7265 6d6f 7665 6427 0a20 2061 is removed'. a
│ │ │ +000764d0: 6e73 6962 6c65 2e62 7569 6c74 696e 2e70 nsible.builtin.p
│ │ │ +000764e0: 6163 6b61 6765 3a0a 2020 2020 6e61 6d65 ackage:. name
│ │ │ +000764f0: 3a20 7273 682d 7365 7276 6572 0a20 2020 : rsh-server.
│ │ │ +00076500: 2073 7461 7465 3a20 6162 7365 6e74 0a20 state: absent.
│ │ │ +00076510: 2074 6167 733a 0a20 202d 204e 4953 542d tags:. - NIST-
│ │ │ +00076520: 3830 302d 3533 2d43 4d2d 3628 6129 0a20 800-53-CM-6(a).
│ │ │ +00076530: 202d 204e 4953 542d 3830 302d 3533 2d43 - NIST-800-53-C
│ │ │ +00076540: 4d2d 3728 6129 0a20 202d 204e 4953 542d M-7(a). - NIST-
│ │ │ +00076550: 3830 302d 3533 2d43 4d2d 3728 6229 0a20 800-53-CM-7(b).
│ │ │ +00076560: 202d 204e 4953 542d 3830 302d 3533 2d49 - NIST-800-53-I
│ │ │ +00076570: 412d 3528 3129 2863 290a 2020 2d20 5043 A-5(1)(c). - PC
│ │ │ +00076580: 492d 4453 5376 342d 322e 320a 2020 2d20 I-DSSv4-2.2. -
│ │ │ +00076590: 5043 492d 4453 5376 342d 322e 322e 340a PCI-DSSv4-2.2.4.
│ │ │ +000765a0: 2020 2d20 6469 7361 626c 655f 7374 7261 - disable_stra
│ │ │ +000765b0: 7465 6779 0a20 202d 2068 6967 685f 7365 tegy. - high_se
│ │ │ +000765c0: 7665 7269 7479 0a20 202d 206c 6f77 5f63 verity. - low_c
│ │ │ +000765d0: 6f6d 706c 6578 6974 790a 2020 2d20 6c6f omplexity. - lo
│ │ │ +000765e0: 775f 6469 7372 7570 7469 6f6e 0a20 202d w_disruption. -
│ │ │ +000765f0: 206e 6f5f 7265 626f 6f74 5f6e 6565 6465 no_reboot_neede
│ │ │ +00076600: 640a 2020 2d20 7061 636b 6167 655f 7273 d. - package_rs
│ │ │ +00076610: 682d 7365 7276 6572 5f72 656d 6f76 6564 h-server_removed
│ │ │ +00076620: 0a3c 2f63 6f64 653e 3c2f 7072 653e 3c2f .
│ │ │ +00076630: 6469 763e 3c61 2063 6c61 7373 3d22 6274 div>
│ │ │ +000766d0: 5265 6d65 6469 6174 696f 6e20 5075 7070 Remediation Pupp
│ │ │ +000766e0: 6574 2073 6e69 7070 6574 20e2 87b2 3c2f et snippet ...
│ │ │ +000766f0: 613e 3c62 723e 3c64 6976 2063 6c61 7373 a>
.include
│ │ │ +00077f00: 7265 6d6f 7665 5f72 7368 0a0a 636c 6173 remove_rsh..clas
│ │ │ +00077f10: 7320 7265 6d6f 7665 5f72 7368 207b 0a20 s remove_rsh {.
│ │ │ +00077f20: 2070 6163 6b61 6765 207b 2027 7273 6827 package { 'rsh'
│ │ │ +00077f30: 3a0a 2020 2020 656e 7375 7265 203d 2667 :. ensure =&g
│ │ │ +00077f40: 743b 2027 7075 7267 6564 272c 0a20 207d t; 'purged',. }
│ │ │ +00077f50: 0a7d 0a3c 2f63 6f64 653e 3c2f 7072 653e .}.
│ │ │ 00077f60: 3c2f 6469 763e 3c61 2063 6c61 7373 3d22
Remediat
│ │ │ -00079270: 696f 6e20 5075 7070 6574 2073 6e69 7070 ion Puppet snipp
│ │ │ -00079280: 6574 20e2 87b2 3c2f 613e 3c62 723e 3c64 et ...
<
│ │ │ -00079300: 7472 3e3c 7468 3e43 6f6d 706c 6578 6974 tr>Complexit
│ │ │ -00079310: 793a 3c2f 7468 3e3c 7464 3e6c 6f77 3c2f y: | low
│ │ │ -00079320: 7464 3e3c 2f74 723e 3c74 723e 3c74 683e td> | |
│ │ │ -00079330: 4469 7372 7570 7469 6f6e 3a3c 2f74 683e Disruption: |
│ │ │ -00079340: 3c74 643e 6c6f 773c 2f74 643e 3c2f 7472 low |
|---|
| Reboot:
│ │ │ -00079360: 3c2f 7468 3e3c 7464 3e66 616c 7365 3c2f | false
│ │ │ -00079370: 7464 3e3c 2f74 723e 3c74 723e 3c74 683e td> |
|---|
|
│ │ │ -00079380: 5374 7261 7465 6779 3a3c 2f74 683e 3c74 Strategy: | disable
│ │ │ -000793a0: 7472 3e3c 2f74 6162 6c65 3e3c 7072 653e tr>
|---|