Skip to content

Releases: ansible-lockdown/RHEL8-CIS

CIS 3.0.0 Oct 25 updates

06 Nov 14:00
ef8d9dd

Choose a tag to compare

##Remediate
workflow updates
audit improvements
pre-commit updates
linting
Readme update

##ssue Fixes:
Thank you to all contributors
#485
#489
#492
#494
#496
#499
#501
#506
#505
#508

What's Changed

New Contributors

Full Changelog: 3.2.0...3.2.1

CIS 3.0.0 July 25 updates

05 Aug 14:27
ab859a3

Choose a tag to compare

Based upon CIS Version: 3.0.0 10th November 2023

Remediate

pre-commit updates
rule 6.2.11 updates and improvements

#433
#460
#462
#463
#466
#468
#470
#473
#475
#476

What's Changed

New Contributors

Full Changelog: 3.1.2...3.2.0

CIS 3.0.0 March25 updates

20 Mar 15:51
730386c

Choose a tag to compare

Based upon CIS Version: 3.0.0 10th November 2023

Remediate

pre-commit updates
rule 6.2.8 added missing default var
rule 6.2.11 updates and improvements
#455

What's Changed

Full Changelog: 3.1.1...3.1.2

CIS 3.0.0 - Feb25 Updates

20 Feb 16:38
013be19

Choose a tag to compare

Based upon CIS Version: 3.0.0 10th November 2023

Remediate

#449
#452

pre-commit updates

What's Changed

Full Changelog: 3.1.0...3.1.1

CIS Version: 3.0.0 - Dec24 Updates

10 Dec 15:39
65731c1

Choose a tag to compare

Based upon CIS Version: 3.0.0 10th November 2023

Remediate

Removed nested variables to allow greater ease to override
conditionals updated

  • 4.4.3.4.3
  • 4.4.3.4.4
  • 6.2.11
    Typo fix in var output
  • 6.2.6
  • 6.2.7

Improved logic is 4.4.1.2

AUDIT

What's Changed

Full Changelog: 3.0.1...3.1.0

CIS Version: 3.0.0 - Oct24 Updates

18 Oct 12:28
0576f15

Choose a tag to compare

Based upon CIS Version: 3.0.0 10th November 2023

Remediate

Rebase to fix some older issues, shows as some updates.
Pre-commit updates
Many improvements to different controls
Audit updates
New workflow pipeline

AUDIT

What's Changed

New Contributors

Full Changelog: 3.0.0...3.0.1

CIS 3.0.0 - 1-10-2023

20 Jun 15:39
a1516d9

Choose a tag to compare

CIS Version: 3.0.0 10th November 2023

Remediate

V3.0.0 release
Pre-commit updates
Many improvements to different controls
Audit updates
New workflow pipeline

AUDIT

  • Audit only option added
  • New goss binary now supported
  • Audit variables tidied and moved

What's Changed

#356
#358
#366
#370
#371
#373
#374
#383
#385

Final Benchmark 2.0.0 Release

06 Mar 13:46
bc4cdf8

Choose a tag to compare

CIS Version: 2.0.0 2-23-2022

Remediate

Issues closed and PRs merged - What's changed
Pre-commit updates
Many improvements to different controls
ansible version to 2.11.1

AUDIT

  • Audit only option added
  • New goss binary now supported
  • Audit variables tidied and moved

What's Changed

New Contributors

Full Changelog: 2.5.2...v2.6

RHEL8 CIS - 2.0.0

19 Jul 13:49
9115397

Choose a tag to compare

  • audit updates

    • pre and post and format type updates
    • #323 thanks to @cobrin preserve copied audit files permissions
    • python 3 only
    • Improvements for workflow and new pipeline methods
    • README updated with badges and labels to use the new workflow
  • pre-commit added and several checks, pre-commit-ci added to repo to ensure content

    • README updated
  • Updates to container discovery and usage within benchmark

  • linting

  • aligned ansible version to 2.10.1 +

  • home directories files change links

  • #304

    • improve passwd check for user only is using sudo thanks to manish on discord community for highlighting issue.

thanks to @bbaassssiiee

  • removed legacy tcp_wrappers information
  • disable ipv6 options
    • #299
    • disable ipv6 for sshd - rhel8cis_ipv6_sshd_disable: false (default) - added to prelim
    • disable ipv6 for chrony - rhel8cis_ipv6_chrony_disable: false (default) - added to prelim
    • turn off ipv6 for localhost - rhel8cis_ipv6_disable_localhost: false (default) - refer https://access.redhat.com/solutions/8709
    • #306
    • #295 crypto policy option updates
    • #296
  • journald
  • #320 thanks to @bbbbaassiieeee set files even if rsyslog chosen

What's Changed

New Contributors

Full Changelog: 2.5.1...2.5.2

Beta test for pamd

25 Apr 15:20
080629a

Choose a tag to compare

Beta test for pamd Pre-release
Pre-release

thanks to @Crayeth

#278
Added new options to allow ipv6 rules if required although ipv6 disabled
rhel8cis_ipv6_sysctl_force
default: true
thanks to @bbaassssiiee

#279
#280
#281
#284
new option to allow manual changes to pamd files without using authconfig
rhel8cis_5_4_2_risks need sto be set to ACCEPT to run
default: NEVER**