Commit Graph

342 Commits

Author SHA1 Message Date
Samson-W 5ac0f976c9 Update format of hardening.sh 2019-09-24 18:14:18 +08:00
Samson-W ba786480b5 Add --final method for reset password for reguler and root user, and reinit aide database 2019-09-23 18:44:23 +08:00
Samson-W d75c1accd8 Fix some bugs for auditd record 2019-09-10 18:15:18 +08:00
Samson-W 6e7bef7a9d Fix some bug for audit rules set. 2019-09-10 17:14:59 +08:00
Samson-W 59d481fd1d Update README.md and README-CN.md 2019-09-09 19:57:49 +08:00
Samson-W 515b906c48 Fix a bug of 8.1.27: If dir does not exist, an error will be generated when using the find command. 2019-09-06 16:51:56 +08:00
Samson-W 92a96e8dc3 Optimize the code of 2.2~2.4 2019-09-06 15:57:49 +08:00
Samson-W 74c2984631 Fix some bugs for 2.1 2.3 2019-09-06 04:55:26 +08:00
Samson-W 10fb74a744 Fix bug of 2.1 2019-09-05 18:07:19 +08:00
Samson-W c31073eb1e Update how_to_creating_and_making_an_AMI_public.mkd and remove duplicate check for /var/log/sudo.log 2019-09-04 02:03:53 +08:00
Samson-W 6fab8a8c2d Fix some bugs. 2019-08-31 17:49:03 +08:00
Samson-W 81d6f39b8a Fix a bug of 9.2.13 2019-08-28 16:36:32 +08:00
Samson-W b95a9b07c2 Modify 9.2.11~9.2.13 to be compatible with CentOS. 2019-08-28 16:31:19 +08:00
Samson-W 19914f08ab Optimization tips for 9.2.1~9.2.10 2019-08-26 19:14:39 +08:00
Samson-W 2ba13e7318 Modify 9.2.3~9.2.10 to be compatible with CentOS. 2019-08-26 18:25:28 +08:00
Samson-W f5de9a24f9 Fix some bugs and add apply method for CentOS. 2019-08-26 18:03:29 +08:00
Samson-W 783d6e4455 Add check_param_pair_by_value method and Modify 9.2.2 to be compatible with CentOS. 2019-08-26 04:16:00 +08:00
Samson-W a635b7d4a9 Modify 9.2.1 to be compatible with CentOS. 2019-08-20 01:34:34 +08:00
Samson-W c887516d36 Modify 9.1.1~9.1.8 to be compatible with CentOS. 2019-08-18 20:33:51 +08:00
Samson-W 1d77dbee83 Modify 8.5 8.6 to be compatible with CentOS. 2019-08-17 23:31:47 +08:00
Samson-W 4df1ad9f1e Modify 8.4.1 8.4.2 to be compatible with CentOS. 2019-08-16 18:27:33 +08:00
Samson-W fe19d99160 Modify 8.1.7 and 8.4.1 to be compatible with CentOS 2019-08-14 18:40:30 +08:00
Samson-W 7f23fe9c1c modify 8.1.23~8.1.32 to be compatible with CentOS. 2019-08-13 20:04:33 +08:00
Samson-W 36d8055522 Fix a spelling error. 2019-08-13 17:59:35 +08:00
Samson-W d3cbebb7e6 modify 8.1.17~8.1.22 to be compatible with CentOS 2019-08-13 17:55:55 +08:00
Samson-W 99cab257b2 Add new method for check audit path is exist, and update 8.1.19 2019-08-13 17:44:31 +08:00
Samson-W d0bbbb9cc7 modify 8.1.10~8.1.16 to be compatible with CentOS, and add new feature to 5.8. 2019-08-12 18:56:21 +08:00
Samson-W eb230b20ff Fix a bug for 8.1.2 2019-08-11 03:23:01 +08:00
Samson-W ff38211d6e modify 8.1.1.1~8.1.9 to be compatible with CentOS. 2019-08-11 03:20:55 +08:00
Samson-W 8c9e91dab3 Fix a bug of 8.0 2019-08-09 15:44:50 +08:00
Samson-W d614bdde72 Update README doc.
modify 7.2.4~7.6 to be compatible with CentOS.
2019-08-08 17:55:23 +08:00
Samson-W 3af015cbc7 Delete obsolete check items:7.3.3_disable_ipv6. 2019-08-08 12:27:43 +08:00
Samson-W 445824fef2 Modified 7.1.1~7.2.3 to be compatible with CentOS. 2019-08-08 05:33:23 +08:00
Samson-W 19b3831baf Modified 6.7~6.20 to be compatible with CentOS. 2019-08-08 05:13:55 +08:00
Samson-W d0a730c321 Modified 6.2~6.6 to be compatible with CentOS. 2019-08-07 23:56:20 +08:00
Samson-W ec1174c2d0 Rename 5.10 to 5.8 2019-08-07 04:15:06 +08:00
Samson-W 286293441e Fix some bugs. 2019-08-07 03:40:30 +08:00
Samson-W 0be34f1b41 Remove some obsolete check items.
Add is_service_active method to utils.sh
Modified 5.2 5.3 to be compatible with CentOS.
2019-08-06 19:43:57 +08:00
Samson-W 29afbe2401 Modified 5.1.7 to be compatible with CentOS. 2019-08-06 17:09:17 +08:00
Samson-W 10f07cf6ff Remove duplicate check items 5.1.7, and fix a bug for 5.1.2 2019-08-06 12:27:32 +08:00
Samson-W 22ca3864d4 Modified 4.6 5.1.1~5.1.7 to be compatible with CentOS. 2019-08-06 06:03:15 +08:00
Samson-W f8aa395b6e Modified 4.5 to be compatible with CentOS. 2019-08-03 04:49:42 +08:00
Samson-W 74db39a3ae Modified 4.4 to be compatible with CentOS. 2019-08-03 04:40:48 +08:00
Samson-W 2a1d76d397 Modified 4.1 to be compatible with CentOS. 2019-08-03 04:17:09 +08:00
Samson-W 3a57b18b76 Modified 3.3 to be compatible with CentOS. 2019-08-02 17:47:17 +08:00
Samson-W 6a754aae63 Modified 3.2 to be compatible with CentOS. 2019-08-02 17:35:11 +08:00
Samson-W 635972c961 Modified 3.1 to be compatible with CentOS. 2019-08-02 17:17:43 +08:00
Samson-W db2f6a5f34 Modified utils.sh and 8.7 to be compatible with CentOS. 2019-08-02 15:44:39 +08:00
Samson-W 359a7c3c5e Modified utils.sh and 2.25 to be compatible with CentOS. 2019-08-02 04:16:53 +08:00
Samson-W c9ba18c101 Update audit and apply methods for 2.17 2019-08-01 17:55:32 +08:00
Samson-W f4633c21af Modified 2.2 2.3 2.4 to be compatible with CentOS. 2019-08-01 12:10:41 +08:00
Samson-W 674e034324 Add audit and apply methods for redhat/CentOS to 2.2 2019-08-01 05:40:16 +08:00
Samson-W 1fa5bdd149 Modify 2.1 for compatibility. 2019-08-01 04:46:59 +08:00
Samson-W c5e9839e97 Add audit and apply methods for redhat/CentOS to 1.4 2019-08-01 04:30:16 +08:00
Samson-W 3fa6ecd82d Fix some bugs for 1.3 2019-08-01 04:06:33 +08:00
Samson-W 7435284d07 Add audit and apply methods for redhat/CentOS to 1.3 2019-08-01 04:01:28 +08:00
Samson-W c79b61c977 Fix a bug for 1.2 2019-08-01 03:59:30 +08:00
Samson-W 399a8a3721 Add audit and apply methods for redhat/CentOS to 1.2. 2019-07-31 18:02:53 +08:00
Samson-W 5ea65ad6de Add audit and apply methods for redhat/CentOS to 1.1. 2019-07-31 16:27:45 +08:00
Samson-W 58c32abfc6 Add method for set OS version to general config. 2019-07-30 19:45:12 +08:00
Samson-W 4047430b4b Add audit and apply methods for 8.1.32 2019-07-19 23:47:28 +08:00
Samson-W eea44e5124 Optimizational function for 8.3.3 8.3.6 2019-05-22 01:36:37 +08:00
Samson-W 25c083a731 Fix some bugs for 8.2.4 2019-05-21 17:45:51 +08:00
Samson-W 3717ab1550 Fix a bug for 8.3.1 2019-05-21 15:54:00 +08:00
Samson-W 70b95bd177 Fix some bugs. 2019-05-21 12:39:45 +08:00
Samson-W cfd14ce818 Fix some bugs. 2019-05-21 11:43:16 +08:00
Samson-W e3a7b267d5 Apply check_audit_is_immutable_mode method for auditd rules check item. 2019-05-18 04:53:05 +08:00
Samson-W 8856f64d16 Add check_audit_is_immutable_mode method in lib/utils.sh and apply the method for 8.1.4 2019-05-18 04:36:55 +08:00
Samson-W 0bd15205e9 Add auditd rules for 8.1.29 8.1.30 8.1.31 base stig-Ubuntu_16-04_LTS. 2019-05-18 04:00:18 +08:00
Samson-W 08a0db4561 Add audit and apply methods for 8.1.28. 2019-05-17 17:28:41 +08:00
Samson-W fa964bc586 Add auditd rules for 8.1.7 8.1.17 8.1.19 base stig-Ubuntu_16-04_LTS. 2019-05-17 17:10:58 +08:00
Samson-W 8d3737fa43 Add auditd rules for chfn in 8.1.22 base stig-Ubuntu_16-04_LTS. 2019-05-17 15:03:12 +08:00
Samson-W 9d886d7bf9 1, Add check rounds of pam_unix for 9.2.13 base stig-Ubuntu_16-04_LTS.
2,Fix a bug: when the configured values have different lengths, the reassignment is incorrect.
2019-05-16 17:40:40 +08:00
Samson-W c4b9847694 Fix a bug for 9.2.15 and delete the debug method in lib/utils.sh 2019-05-16 14:45:12 +08:00
Samson-W b762376882 Fix a bug for 8.2.5: when syslog-ng has installed, pass this check item. 2019-05-14 17:48:49 +08:00
Samson-W efb9efafdc Add audit and apply methods for 12.5 12.6 12.12 12.13 2019-05-14 14:24:15 +08:00
Samson-W 39da6d480a Add audit and apply methods for 12.4: Ensure permissions on /etc/gshadow are configured 2019-05-14 04:07:26 +08:00
Samson-W a29f621ea7 Combine the functions of 12.4 to 12.1, 12.5 to 12.2, 12.6 to 12.3. 2019-05-14 04:05:04 +08:00
Samson-W 22002609f4 Rename file name of 9.5 2019-05-14 03:46:07 +08:00
Samson-W b629896e82 Add check ownership method for 12.1 2019-05-14 03:40:20 +08:00
Samson-W a1f02aaabf Reorder check items. 2019-05-13 17:34:34 +08:00
Samson-W 0e9f690966 Delete unimplemented item 10.5, which is implemented by 10.1.5. 2019-05-13 17:23:30 +08:00
Samson-W 56b3db72b0 Add audit and apply methods for 10.1.5: Ensure inactive password lock is 30 days or less. 2019-05-13 17:14:37 +08:00
Samson-W 0de7b1d404 Remove 10.1.5 and add runtime check method to 10.1.2: for min password lifetime. 2019-05-12 05:13:07 +08:00
Samson-W cf7c0cae75 Remove 10.1.6 and add runtime check method to 10.1.1: for max password lifetime. 2019-05-10 17:32:39 +08:00
Samson-W 0c676832d1 Rename and reorder number for pam module check. 2019-05-10 15:49:17 +08:00
Samson-W e35e51602a Rename 9.3.27 check script name. 2019-05-09 18:34:16 +08:00
Samson-W 0dcaecc466 Add audit and apply methods for 9.3.27: Ensure SSH access is limited. 2019-05-09 18:32:27 +08:00
Samson-W 4893491e16 Add audit and apply methods for 9.3.26: Ensure SSH LoginGraceTime is set to one minute or less 2019-05-09 17:07:34 +08:00
Samson-W 175fae40d7 Modify ClientAliveInterval to 300 by new benchmark doc. 2019-05-09 15:34:20 +08:00
Samson-W 9c93e6955a Add check ownership methods for 9.3.23 2019-05-09 15:07:49 +08:00
Samson-W 977b32a801 Add audit and apply methods for 9.3.25: Ensure only strong Key Exchange algorithms are used. 2019-05-09 14:57:46 +08:00
Samson-W 1604707e56 Modify audit and apply methods for 9.3.24 2019-05-09 14:06:04 +08:00
Samson-W 9d8e8cf2e3 Modify the serial number of the inspection check item. 2019-05-09 11:57:58 +08:00
Samson-W 81da986be0 Fix bug for 9.1.1 , when debian version is 9.* 2019-05-09 11:28:14 +08:00
Samson-W e3245dce49 Fix a bug for 8.3.1 2019-05-08 10:57:50 +08:00
Samson-W a1446eecd7 Modify 8.3.2. 2019-05-08 10:46:09 +08:00
Samson-W f3981f9d18 Rename 8.5 to 8.6, 8.6 to 8.7, add 8.5. 2019-05-08 10:43:16 +08:00
Samson-W 11d2770fc6 Modify 8.3.2 2019-05-07 19:03:35 +08:00
Samson-W 69c45da7c0 Modify 8.3.1 8.3.2 and add 8.2.5 2019-05-06 23:43:12 +08:00