ansible-hardening/vars/ubuntu.yml
Major Hayden 4c792445d4 Move common variables to common.yml
This patch creates a common.yml variables file to hold variables
that apply to all distributions supported by the role. It also adds
comments into the existing vars file to instruct developers and
deployers about the proper location for variables.

Implements: blueprint security-rhel7-stig
Change-Id: Idad1cbfe0c6992a6333c4740080764a3ac776628
2016-11-20 17:11:12 +00:00

135 lines
3.5 KiB
YAML

---
# Copyright 2016, Rackspace US, Inc.
#
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
#
# http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
## Variables for Ubuntu 14.04 (trusty) and Ubuntu 16.04 (xenial)
# The following variables apply only to Ubuntu 14.04 (trusty) and Ubuntu 16.04
# (xenial) and deployers should not override them.
#
# For more details, see 'vars/main.yml'.
# Maximum age of the apt cache before a refresh is required
cache_timeout: 600
# Configuration file paths
pam_auth_file: /etc/pam.d/common-auth
pam_password_file: /etc/pam.d/common-password
vsftpd_conf_file: /etc/vsftpd.conf
grub_conf_file: /boot/grub/grub.cfg
aide_cron_job_path: /etc/cron.daily/aide
aide_database_file: /var/lib/aide/aide.db
chrony_conf_file: /etc/chrony/chrony.conf
# Service name
cron_service: cron
ssh_service: ssh
chrony_service: chrony
clamav_service: clamd
# Commands
grub_update_cmd: "update-grub"
ssh_keysign_path: /usr/lib/openssh
# RHEL 6 STIG: Packages to add/remove
stig_packages:
- packages:
- auditd
- audispd-plugins
- aide
- aide-common
- chrony
- debsums
- logrotate
- postfix
state: "{{ security_package_state }}"
enabled: True
- packages:
- apparmor
- apparmor-profiles
- apparmor-utils
state: "{{ security_package_state }}"
enabled: "{{ security_enable_linux_security_module }}"
- packages:
- fail2ban
state: "{{ security_package_state }}"
enabled: "{{ security_install_fail2ban }}"
- packages:
- xinetd
state: absent
enabled: "{{ security_remove_xinetd }}"
- packages:
- nis
state: absent
enabled: "{{ security_remove_ypserv }}"
- packages:
- tftpd
state: absent
enabled: "{{ security_remove_tftp_server }}"
- packages:
- slapd
state: absent
enabled: "{{ security_remove_ldap_server }}"
- packages:
- sendmail
state: absent
enabled: "{{ security_remove_sendmail }}"
- packages:
- xorg-xserver
state: absent
enabled: "{{ security_remove_xorg }}"
- packages:
- rsh-server
state: absent
enabled: "{{ security_remove_rsh_server }}"
- packages:
- telnetd
state: absent
enabled: "{{ security_remove_telnet_server }}"
# RHEL 7 STIG: Packages to add/remove
stig_packages_rhel7:
- packages:
- libpwquality-common
- openssh-client
- openssh-server
- screen
state: "{{ security_package_state }}"
enabled: True
- packages:
- clamav
- clamav-daemon
- clamav-freshclam
state: "{{ security_package_state }}"
enabled: "{{ security_enable_virus_scanner }}"
- packages:
- rsh-server
state: absent
enabled: "{{ security_rhel7_remove_rsh_server }}"
- packages:
- telnetd
state: absent
enabled: "{{ security_rhel7_remove_telnet_server }}"
- packages:
- tftpd
state: absent
enabled: "{{ security_rhel7_remove_tftp_server }}"
- packages:
- xorg-xserver
state: absent
enabled: "{{ security_rhel7_remove_xorg }}"
- packages:
- nis
state: absent
enabled: "{{ security_rhel7_remove_ypserv }}"