|
6 | 6 | ubtu24cis_apparmor_enforce_only: false |
7 | 7 | changed_when: false |
8 | 8 |
|
9 | | -- name: "PRELIM | AUDIT | Register if snap being used" |
| 9 | +- name: "PRELIM | AUDIT | squashfs logic" |
10 | 10 | when: ubtu24cis_rule_1_1_1_7 |
11 | 11 | tags: always |
12 | | - ansible.builtin.shell: df -h | grep -wc "/snap" |
13 | | - changed_when: false |
14 | | - failed_when: prelim_snap_pkg_mgr.rc not in [ 0, 1 ] |
15 | | - register: prelim_snap_pkg_mgr |
| 12 | + block: |
| 13 | + - name: "PRELIM | AUDIT | Register if snap being used" |
| 14 | + ansible.builtin.shell: lsblk | grep -wc "/snap" |
| 15 | + changed_when: false |
| 16 | + failed_when: prelim_snap_pkg_mgr.rc not in [ 0, 1 ] |
| 17 | + register: prelim_snap_pkg_mgr |
16 | 18 |
|
17 | | -- name: "PRELIM | AUDIT | Register if squashfs is built into the kernel" |
18 | | - when: ubtu24cis_rule_1_1_1_7 |
19 | | - tags: always |
20 | | - ansible.builtin.shell: cat /lib/modules/$(uname -r)/modules.builtin | grep -c "squashfs" |
21 | | - changed_when: false |
22 | | - failed_when: prelim_squashfs_builtin.rc not in [ 0, 1 ] |
23 | | - register: prelim_squashfs_builtin |
| 19 | + - name: "PRELIM | AUDIT | Register if squashfs is built into the kernel" |
| 20 | + ansible.builtin.shell: cat /lib/modules/$(uname -r)/modules.builtin | grep "squashfs" |
| 21 | + changed_when: false |
| 22 | + failed_when: prelim_squashfs_builtin.rc not in [ 0, 1 ] |
| 23 | + register: prelim_squashfs_builtin |
24 | 24 |
|
25 | 25 | - name: PRELIM | AUDIT | Section 1.1 | Create list of mount points |
26 | 26 | tags: always |
|
67 | 67 | file: audit.yml |
68 | 68 |
|
69 | 69 | - name: Include pre-remediation audit tasks |
70 | | - when: run_audit or audit_only or setup_audit |
| 70 | + when: |
| 71 | + - run_audit or audit_only |
| 72 | + - setup_audit |
71 | 73 | tags: |
72 | 74 | - run_audit |
73 | 75 | - setup_audit |
|
264 | 266 |
|
265 | 267 | - name: "PRELIM | PATCH | Install UFW" |
266 | 268 | when: |
267 | | - - ubtu24cis_rule_2_4_1_1 |
| 269 | + - ubtu24cis_rule_4_2_1 |
| 270 | + - ubtu24cis_section4 |
268 | 271 | - ubtu24cis_firewall_package == "ufw" |
269 | 272 | tags: always |
270 | 273 | ansible.builtin.package: |
|
0 commit comments