1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160
|
groups:
- export_filesystems_read_only
- files
- partitions
- permissions_important_account_files
- permissions_local
- permissions_var_log_dir
- permissions_within_important_dirs
name: filesystem
packages:
- filesystem
rules:
- dir_group_ownership_library_dirs
- dir_groupownership_binary_dirs
- dir_ownership_binary_dirs
- dir_ownership_library_dirs
- dir_permissions_binary_dirs
- dir_permissions_library_dirs
- dir_perms_world_writable_root_owned
- dir_perms_world_writable_sticky_bits
- dir_perms_world_writable_system_owned
- dir_perms_world_writable_system_owned_group
- dir_system_commands_group_root_owned
- dir_system_commands_root_owned
- directory_groupowner_etc_sysctld
- directory_owner_etc_sysctld
- directory_permissions_etc_sysctld
- file_etc_security_opasswd
- file_groupowner_backup_etc_group
- file_groupowner_backup_etc_gshadow
- file_groupowner_backup_etc_passwd
- file_groupowner_backup_etc_shadow
- file_groupowner_etc_crypttab
- file_groupowner_etc_group
- file_groupowner_etc_gshadow
- file_groupowner_etc_passwd
- file_groupowner_etc_security_opasswd
- file_groupowner_etc_security_opasswd_old
- file_groupowner_etc_shadow
- file_groupowner_etc_shells
- file_groupowner_systemmap
- file_groupowner_var_log
- file_groupowner_var_log_messages
- file_groupowner_var_log_syslog
- file_groupownership_audit_binaries
- file_groupownership_system_commands_dirs
- file_owner_backup_etc_group
- file_owner_backup_etc_gshadow
- file_owner_backup_etc_passwd
- file_owner_backup_etc_shadow
- file_owner_etc_crypttab
- file_owner_etc_group
- file_owner_etc_gshadow
- file_owner_etc_passwd
- file_owner_etc_security_opasswd
- file_owner_etc_security_opasswd_old
- file_owner_etc_shells
- file_owner_etc_shadow
- file_owner_systemmap
- file_owner_var_log
- file_owner_var_log_messages
- file_owner_var_log_syslog
- file_ownership_audit_binaries
- file_ownership_binary_dirs
- file_ownership_library_dirs
- file_permissions_audit_binaries
- file_permissions_backup_etc_group
- file_permissions_backup_etc_gshadow
- file_permissions_backup_etc_passwd
- file_permissions_backup_etc_shadow
- file_permissions_binary_dirs
- file_permissions_etc_audit_auditd
- file_permissions_etc_audit_rulesd
- file_permissions_etc_audit_rules
- file_permissions_etc_crypttab
- file_permissions_etc_group
- file_permissions_etc_gshadow
- file_permissions_etc_passwd
- file_permissions_etc_security_opasswd
- file_permissions_etc_security_opasswd_old
- file_permissions_etc_shadow
- file_permissions_etc_shells
- file_permissions_library_dirs
- file_permissions_local_var_log_messages
- file_permissions_system_commands_dirs
- file_permissions_systemmap
- file_permissions_unauthorized_sgid
- file_permissions_unauthorized_suid
- file_permissions_unauthorized_world_writable
- file_permissions_ungroupowned
- file_permissions_var_log
- file_permissions_var_log_messages
- file_permissions_var_log_syslog
- mount_option_boot_efi_nosuid
- mount_option_boot_noauto
- mount_option_boot_nodev
- mount_option_boot_noexec
- mount_option_boot_nosuid
- mount_option_dev_shm_nodev
- mount_option_dev_shm_noexec
- mount_option_dev_shm_nosuid
- mount_option_home_grpquota
- mount_option_home_nodev
- mount_option_home_noexec
- mount_option_home_nosuid
- mount_option_home_usrquota
- mount_option_krb_sec_remote_filesystems
- mount_option_nodev_nonroot_local_partitions
- mount_option_nodev_remote_filesystems
- mount_option_nodev_removable_partitions
- mount_option_noexec_remote_filesystems
- mount_option_noexec_removable_partitions
- mount_option_nosuid_remote_filesystems
- mount_option_nosuid_removable_partitions
- mount_option_opt_nosuid
- mount_option_proc_hidepid
- mount_option_srv_nosuid
- mount_option_tmp_nodev
- mount_option_tmp_noexec
- mount_option_tmp_nosuid
- mount_option_var_log_audit_nodev
- mount_option_var_log_audit_noexec
- mount_option_var_log_audit_nosuid
- mount_option_var_log_nodev
- mount_option_var_log_noexec
- mount_option_var_log_nosuid
- mount_option_var_nodev
- mount_option_var_noexec
- mount_option_var_nosuid
- mount_option_var_tmp_bind
- mount_option_var_tmp_nodev
- mount_option_var_tmp_noexec
- mount_option_var_tmp_nosuid
- no_files_unowned_by_user
- partition_for_boot
- partition_for_dev_shm
- partition_for_home
- partition_for_opt
- partition_for_srv
- partition_for_tmp
- partition_for_usr
- partition_for_var
- partition_for_var_log
- partition_for_var_log_audit
- partition_for_var_tmp
- permissions_local_audit_binaries
- permissions_local_var_log
- permissions_local_var_log_audit
- root_permissions_syslibrary_files
- run_chkstat
- sysctl_fs_protected_fifos
- sysctl_fs_protected_hardlinks
- sysctl_fs_protected_regular
- sysctl_fs_protected_symlinks
templates:
- mount
- mount_option
- mount_option_remote_filesystems
- mount_option_removable_partitions
|