Documentos de Académico
Documentos de Profesional
Documentos de Cultura
1 subscription-manager register
2 subscription-manager refresh
3 subscription-manager attach --auto
4 dnf install python3
5 yum install ansible-core
6 ansible --version
# cat /etc/redhat-release
instalar goss:
curl -L https://github.com/goss-org/goss/releases/latest/download/goss-linux-amd64 -o
/usr/local/bin/goss
crear audit.yml
---
- name: RHEL8 CIS Audit
hosts: all
become: true
roles:
- name: "CIS1"
vars:
setup_audit: true
run_audit: true
crear site.yml
---
- name: Run RHEL8 CIS hardening
hosts: all
become: true
roles:
- role: "CIS1"
solucion:
: TASK [RHEL8-CIS : 1.2.5 | PATCH | Ensure updates, patches, and additional security software
are installed | Patch] ***
fatal: [localhost]: FAILED! => {"changed": false, "msg": "Failed to download metadata for repo
'epel': GPG verification is enabled, but GPG signature is not available. This may be an error or the
repository does not support GPG verification: Status code: 404 for
http://mirrors.upr.edu/epel/8/Everything/x86_64/repodata/repomd.xml.asc (IP: 136.145.244.40)",
"rc": 1, "results": []}
Linea 52
#line: line: gpgcheck=1 --> line: gpgcheck=0 Modificacion
Linea 85
#line: line: gpgcheck=1 --> line: gpgcheck=0 Modificacion
[main]
gpgcheck=0
installonly_limit=3
clean_requirements_on_remove=True
best=True
skip_if_unavailable=False
repo_gpgcheck=0
TASK [RHEL8-CIS-OK : 5.3.3 | Ensure cryptographic mechanisms are used to protect the integrity
of audit tools] ***
fatal: [localhost]: FAILED! => {"changed": false, "msg": "Path /etc/aide.conf does not exist !", "rc":
257}
solution:
cd /root/.ansible/roles/CIS-RHEL8/
379 LL
380 ll
381 git init
382 git pull
384 git add .
385 git commit -m "first commit"
386 git commit -m "chequeo de reglas"
387 git branch -M main
388 git remote add origin https://github.com/JohanaER/CISPRUEBA.git
389 git push -u origin main
cd /root/.ansible/roles/RHEL8-CIS
355 git pull
356 git init
357 git config --global init.defaultBranch custom-changes
358 git pull
359 git config --global --edit
360 git commit --amend –reset-author