mirror of https://github.com/CISOfy/lynis.git
Added /srv/www as SSL certificate search path and enabled several plugins by default
This commit is contained in:
parent
64d3464543
commit
632007bc02
14
default.prf
14
default.prf
|
@ -52,20 +52,29 @@ config:show_tool_tips:1:
|
||||||
#
|
#
|
||||||
# Plugins
|
# Plugins
|
||||||
# ---------------
|
# ---------------
|
||||||
# Define which plugins are enabled (nothing happens if plugin isn't available)
|
# Define which plugins are enabled
|
||||||
|
# (nothing happens if plugin isn't available)
|
||||||
#
|
#
|
||||||
#################################################################################
|
#################################################################################
|
||||||
|
|
||||||
|
# Lynis Plugins for Enterprise Users
|
||||||
plugin=compliance
|
plugin=compliance
|
||||||
plugin=control-panels
|
plugin=control-panels
|
||||||
|
plugin=crypto
|
||||||
|
plugin=dns
|
||||||
plugin=docker
|
plugin=docker
|
||||||
plugin=file-integrity
|
plugin=file-integrity
|
||||||
plugin=file-systems
|
plugin=file-systems
|
||||||
plugin=files
|
plugin=files
|
||||||
plugin=firewalls
|
plugin=firewalls
|
||||||
|
plugin=kernel
|
||||||
|
plugin=memory
|
||||||
|
plugin=nginx
|
||||||
plugin=processes
|
plugin=processes
|
||||||
|
plugin=security-modules
|
||||||
plugin=software
|
plugin=software
|
||||||
plugin=system-integrity
|
plugin=system-integrity
|
||||||
|
plugin=users
|
||||||
|
|
||||||
#################################################################################
|
#################################################################################
|
||||||
#
|
#
|
||||||
|
@ -92,6 +101,7 @@ sysctl:kernel.core_uses_pid:1:1:XXX:
|
||||||
sysctl:kernel.ctrl-alt-del:0:1:XXX:
|
sysctl:kernel.ctrl-alt-del:0:1:XXX:
|
||||||
sysctl:kernel.exec-shield-randomize:1:1:XXX:
|
sysctl:kernel.exec-shield-randomize:1:1:XXX:
|
||||||
sysctl:kernel.exec-shield:1:1:XXX:
|
sysctl:kernel.exec-shield:1:1:XXX:
|
||||||
|
sysctl:kernel.kptr_restrict:1:1:Restrict access to kernel symbols:
|
||||||
sysctl:kernel.sysrq:0:1:Disable magic SysRQ:
|
sysctl:kernel.sysrq:0:1:Disable magic SysRQ:
|
||||||
sysctl:kernel.use-nx:0:1:XXX:
|
sysctl:kernel.use-nx:0:1:XXX:
|
||||||
|
|
||||||
|
@ -178,7 +188,7 @@ openldap:slapd.conf:owner:ldap-root:
|
||||||
#################################################################################
|
#################################################################################
|
||||||
|
|
||||||
# Locations where to search for SSL certificates
|
# Locations where to search for SSL certificates
|
||||||
ssl:certificates:/etc/pki /etc/ssl /usr/local/share/ca-certificates /var/www:
|
ssl:certificates:/etc/pki /etc/ssl /usr/local/share/ca-certificates /var/www /srv/www:
|
||||||
|
|
||||||
|
|
||||||
#################################################################################
|
#################################################################################
|
||||||
|
|
Loading…
Reference in New Issue