Disable sysctl_kernel_modules_disabled Ansible remediation#12514
Merged
Mab879 merged 1 commit intoComplianceAsCode:masterfrom Oct 18, 2024
Merged
Conversation
The remediation causes boot failure for UEFI systems.
|
This datastream diff is auto generated by the check Click here to see the full diffNew content has different text for rule 'xccdf_org.ssgproject.content_rule_sysctl_kernel_modules_disabled'.
--- xccdf_org.ssgproject.content_rule_sysctl_kernel_modules_disabled
+++ xccdf_org.ssgproject.content_rule_sysctl_kernel_modules_disabled
@@ -7,7 +7,7 @@
To make sure that the setting is persistent, add the following line to a file in the directory /etc/sysctl.d: kernel.modules_disabled = 1
[warning]:
-This rule doesn't come with Bash remediation. Remediating this rule during the installation process disrupts the install and boot process.
+This rule doesn't come with remediation. Remediating this rule during the installation process disrupts the install and boot process.
[reference]:
R10
New data stream is missing ansible remediation for rule 'xccdf_org.ssgproject.content_rule_sysctl_kernel_modules_disabled'. |
|
Code Climate has analyzed commit fe7fea3 and detected 0 issues on this pull request. The test coverage on the diff in this pull request is 100.0% (50% is the threshold). This pull request will bring the total coverage in the repository to 61.0% (0.0% change). View more on Code Climate. |
Collaborator
|
For the record, |
Member
|
Waving Automatus tests as they not related to this PR. |
Mab879
approved these changes
Oct 18, 2024
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description:
Disable Ansible remediation for
sysctl_kernel_modules_disabled.Rationale:
The remediation causes boot failure for UEFI systems.
The rule already had disabled Bash remediation (#6586) because of the same reason as #12508 .
Fixes #12508
Review Hints:
Run Contest
/hardening/ansible/anssi_bp28_highto see if machine boots successfully after ANSSI hardening.