From 24f3f73717bf845f7993c32e39b3e20f4392e8f2 Mon Sep 17 00:00:00 2001 From: Major Hayden Date: Tue, 7 Jun 2016 08:30:38 -0500 Subject: [PATCH] Add release note for V-38524 implementation This patch is a follow on patch for change I228f8aa7b0df80cce16e54c5f1e11da678bfd67d that implemented V-38524. Change-Id: I77b1c141e9de1fd949b18bc693c68fea56b8e2d6 --- .../notes/implemented-v38524-b357edec95128307.yaml | 12 ++++++++++++ 1 file changed, 12 insertions(+) create mode 100644 releasenotes/notes/implemented-v38524-b357edec95128307.yaml diff --git a/releasenotes/notes/implemented-v38524-b357edec95128307.yaml b/releasenotes/notes/implemented-v38524-b357edec95128307.yaml new file mode 100644 index 00000000..24ebec9f --- /dev/null +++ b/releasenotes/notes/implemented-v38524-b357edec95128307.yaml @@ -0,0 +1,12 @@ +--- +features: + - | + A task was added that restricts ICMPv4 redirects to meet the requirements + of V-38524 in the STIG. This configuration is disabled by default since + it could cause issues with LXC in some environments. + + Deployers can enable this configuration by setting an Ansible variable: + + .. code-block:: yaml + + security_disable_icmpv4_redirects: yes