RHEL6-STIG icon indicating copy to clipboard operation
RHEL6-STIG copied to clipboard

RFE: option to create ssg tailoring file

Open jamescassell opened this issue 6 years ago • 2 comments

The defaults chosen for this project sometimes fail the scap-security-guide checks. It would be nice to create a tailoring file for variables here that would allow ssg to pass its checks. Notably, the daemon umask settings and the audit failure actions do not pass the ssg default checks. (see https://github.com/OpenSCAP/scap-security-guide/issues/2755)

jamescassell avatar Apr 16 '18 22:04 jamescassell

@redhatrises thanks for the link. My RFE is more to automatically create that tailoring file based on the defaults of this (ansible-lockdown RHEL6-STIG) project.

jamescassell avatar Apr 16 '18 22:04 jamescassell

This role needs to be updated to be more inline with the RHEL7 roles so that it has vars for each STIG rule/id. Once that is done it should be simple to create tailored vars files for different use cases.

shepdelacreme avatar Apr 17 '18 01:04 shepdelacreme