Skip to content

Commit 19f5083

Browse files
committed
rhel9: align kickstarts with rules in the profile regarding mount options
1 parent b50dfc0 commit 19f5083

12 files changed

+29
-29
lines changed

products/rhel9/kickstart/ssg-rhel9-anssi_bp28_enhanced-ks.cfg

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -103,13 +103,13 @@ logvol /opt --fstype=xfs --name=opt --vgname=VolGroup --size=1024 --fsoptions="n
103103
# Ensure /srv Located On Separate Partition
104104
logvol /srv --fstype=xfs --name=srv --vgname=VolGroup --size=1024 --fsoptions="nodev,nosuid"
105105
# Ensure /home Located On Separate Partition
106-
logvol /home --fstype=xfs --name=home --vgname=VolGroup --size=1024 --fsoptions="nodev"
106+
logvol /home --fstype=xfs --name=home --vgname=VolGroup --size=1024 --fsoptions="nodev,noexec,nosuid"
107107
# Ensure /tmp Located On Separate Partition
108108
logvol /tmp --fstype=xfs --name=tmp --vgname=VolGroup --size=1024 --fsoptions="nodev,nosuid,noexec"
109109
# Ensure /var/tmp Located On Separate Partition
110110
logvol /var/tmp --fstype=xfs --name=vartmp --vgname=VolGroup --size=1024 --fsoptions="nodev,nosuid,noexec"
111111
# Ensure /var Located On Separate Partition
112-
logvol /var --fstype=xfs --name=var --vgname=VolGroup --size=3072 --fsoptions="nodev"
112+
logvol /var --fstype=xfs --name=var --vgname=VolGroup --size=3072 --fsoptions="nodev,nosuid,noexec"
113113
# Ensure /var/log Located On Separate Partition
114114
logvol /var/log --fstype=xfs --name=varlog --vgname=VolGroup --size=1024 --fsoptions="nodev,nosuid,noexec"
115115
# Ensure /var/log/audit Located On Separate Partition

products/rhel9/kickstart/ssg-rhel9-anssi_bp28_high-ks.cfg

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -107,13 +107,13 @@ logvol /opt --fstype=xfs --name=opt --vgname=VolGroup --size=1024 --fsoptions="n
107107
# Ensure /srv Located On Separate Partition
108108
logvol /srv --fstype=xfs --name=srv --vgname=VolGroup --size=1024 --fsoptions="nodev,nosuid"
109109
# Ensure /home Located On Separate Partition
110-
logvol /home --fstype=xfs --name=home --vgname=VolGroup --size=1024 --fsoptions="nodev"
110+
logvol /home --fstype=xfs --name=home --vgname=VolGroup --size=1024 --fsoptions="nodev,nosuid,noexec"
111111
# Ensure /tmp Located On Separate Partition
112112
logvol /tmp --fstype=xfs --name=tmp --vgname=VolGroup --size=1024 --fsoptions="nodev,nosuid,noexec"
113113
# Ensure /var/tmp Located On Separate Partition
114114
logvol /var/tmp --fstype=xfs --name=vartmp --vgname=VolGroup --size=1024 --fsoptions="nodev,nosuid,noexec"
115115
# Ensure /var Located On Separate Partition
116-
logvol /var --fstype=xfs --name=var --vgname=VolGroup --size=3072 --fsoptions="nodev"
116+
logvol /var --fstype=xfs --name=var --vgname=VolGroup --size=3072 --fsoptions="nodev,nosuid,noexec"
117117
# Ensure /var/log Located On Separate Partition
118118
logvol /var/log --fstype=xfs --name=varlog --vgname=VolGroup --size=1024 --fsoptions="nodev,nosuid,noexec"
119119
# Ensure /var/log/audit Located On Separate Partition

products/rhel9/kickstart/ssg-rhel9-anssi_bp28_intermediary-ks.cfg

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -103,13 +103,13 @@ logvol /opt --fstype=xfs --name=opt --vgname=VolGroup --size=1024 --fsoptions="n
103103
# Ensure /srv Located On Separate Partition
104104
logvol /srv --fstype=xfs --name=srv --vgname=VolGroup --size=1024 --fsoptions="nodev,nosuid"
105105
# Ensure /home Located On Separate Partition
106-
logvol /home --fstype=xfs --name=home --vgname=VolGroup --size=1024 --fsoptions="nodev"
106+
logvol /home --fstype=xfs --name=home --vgname=VolGroup --size=1024 --fsoptions="nodev,nosuid,noexec"
107107
# Ensure /tmp Located On Separate Partition
108108
logvol /tmp --fstype=xfs --name=tmp --vgname=VolGroup --size=1024 --fsoptions="nodev,nosuid,noexec"
109109
# Ensure /var/tmp Located On Separate Partition
110110
logvol /var/tmp --fstype=xfs --name=vartmp --vgname=VolGroup --size=1024 --fsoptions="nodev,nosuid,noexec"
111111
# Ensure /var Located On Separate Partition
112-
logvol /var --fstype=xfs --name=var --vgname=VolGroup --size=3072 --fsoptions="nodev"
112+
logvol /var --fstype=xfs --name=var --vgname=VolGroup --size=3072 --fsoptions="nodev,nosuid,noexec"
113113
# Ensure /var/log Located On Separate Partition
114114
logvol /var/log --fstype=xfs --name=varlog --vgname=VolGroup --size=1024 --fsoptions="nodev,nosuid,noexec"
115115
# Ensure /var/log/audit Located On Separate Partition

products/rhel9/kickstart/ssg-rhel9-ccn_advanced-ks.cfg

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -87,7 +87,7 @@ clearpart --linux --initlabel
8787
reqpart
8888

8989
# Create primary system partitions (required for installs)
90-
part /boot --fstype=xfs --size=2048
90+
part /boot --fstype=xfs --size=2048 --fsoptions="nodev,nosuid,noexec"
9191
part pv.01 --grow --size=1
9292

9393
# Create a Logical Volume Management (LVM) group (optional)

products/rhel9/kickstart/ssg-rhel9-ccn_basic-ks.cfg

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -87,7 +87,7 @@ clearpart --linux --initlabel
8787
reqpart
8888

8989
# Create primary system partitions (required for installs)
90-
part /boot --fstype=xfs --size=2048
90+
part /boot --fstype=xfs --size=2048 --fsoptions="nodev,nosuid,noexec"
9191
part pv.01 --grow --size=1
9292

9393
# Create a Logical Volume Management (LVM) group (optional)

products/rhel9/kickstart/ssg-rhel9-ccn_intermediate-ks.cfg

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -87,7 +87,7 @@ clearpart --linux --initlabel
8787
reqpart
8888

8989
# Create primary system partitions (required for installs)
90-
part /boot --fstype=xfs --size=2048
90+
part /boot --fstype=xfs --size=2048 --fsoptions="nodev,nosuid,noexec"
9191
part pv.01 --grow --size=1
9292

9393
# Create a Logical Volume Management (LVM) group (optional)

products/rhel9/kickstart/ssg-rhel9-cis-ks.cfg

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -99,17 +99,17 @@ volgroup VolGroup pv.01
9999
# Create particular logical volumes (optional)
100100
logvol / --fstype=xfs --name=root --vgname=VolGroup --size=5120 --grow
101101
# Ensure /home Located On Separate Partition
102-
logvol /home --fstype=xfs --name=home --vgname=VolGroup --size=1024 --fsoptions="nodev"
102+
logvol /home --fstype=xfs --name=home --vgname=VolGroup --size=1024 --fsoptions="nodev,nosuid"
103103
# Ensure /tmp Located On Separate Partition
104104
logvol /tmp --fstype=xfs --name=tmp --vgname=VolGroup --size=1024 --fsoptions="nodev,noexec,nosuid"
105105
# Ensure /var/tmp Located On Separate Partition
106106
logvol /var/tmp --fstype=xfs --name=vartmp --vgname=VolGroup --size=1024 --fsoptions="nodev,nosuid,noexec"
107107
# Ensure /var Located On Separate Partition
108-
logvol /var --fstype=xfs --name=var --vgname=VolGroup --size=3072
108+
logvol /var --fstype=xfs --name=var --vgname=VolGroup --size=3072 --fsoptions="nodev,nosuid"
109109
# Ensure /var/log Located On Separate Partition
110-
logvol /var/log --fstype=xfs --name=varlog --vgname=VolGroup --size=1024
110+
logvol /var/log --fstype=xfs --name=varlog --vgname=VolGroup --size=1024 --fsoptions="nodev,nosuid,noexec"
111111
# Ensure /var/log/audit Located On Separate Partition
112-
logvol /var/log/audit --fstype=xfs --name=varlogaudit --vgname=VolGroup --size=512
112+
logvol /var/log/audit --fstype=xfs --name=varlogaudit --vgname=VolGroup --size=512 --fsoptions="nodev,nosuid,noexec"
113113
logvol swap --name=swap --vgname=VolGroup --size=2016
114114

115115

products/rhel9/kickstart/ssg-rhel9-cis_server_l1-ks.cfg

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -99,17 +99,17 @@ volgroup VolGroup pv.01
9999
# Create particular logical volumes (optional)
100100
logvol / --fstype=xfs --name=root --vgname=VolGroup --size=5120 --grow
101101
# Ensure /home Located On Separate Partition
102-
logvol /home --fstype=xfs --name=home --vgname=VolGroup --size=1024 --fsoptions="nodev"
102+
logvol /home --fstype=xfs --name=home --vgname=VolGroup --size=1024 --fsoptions="nodev,nosuid"
103103
# Ensure /tmp Located On Separate Partition
104104
logvol /tmp --fstype=xfs --name=tmp --vgname=VolGroup --size=1024 --fsoptions="nodev,noexec,nosuid"
105105
# Ensure /var/tmp Located On Separate Partition
106106
logvol /var/tmp --fstype=xfs --name=vartmp --vgname=VolGroup --size=1024 --fsoptions="nodev,nosuid,noexec"
107107
# Ensure /var Located On Separate Partition
108-
logvol /var --fstype=xfs --name=var --vgname=VolGroup --size=3072
108+
logvol /var --fstype=xfs --name=var --vgname=VolGroup --size=3072 --fsoptions="nodev,nosuid"
109109
# Ensure /var/log Located On Separate Partition
110-
logvol /var/log --fstype=xfs --name=varlog --vgname=VolGroup --size=1024
110+
logvol /var/log --fstype=xfs --name=varlog --vgname=VolGroup --size=1024 --fsoptions="nodev,nosuid,noexec"
111111
# Ensure /var/log/audit Located On Separate Partition
112-
logvol /var/log/audit --fstype=xfs --name=varlogaudit --vgname=VolGroup --size=512
112+
logvol /var/log/audit --fstype=xfs --name=varlogaudit --vgname=VolGroup --size=512 --fsoptions="nodev,nosuid,noexec"
113113
logvol swap --name=swap --vgname=VolGroup --size=2016
114114

115115

products/rhel9/kickstart/ssg-rhel9-cis_workstation_l1-ks.cfg

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -99,17 +99,17 @@ volgroup VolGroup pv.01
9999
# Create particular logical volumes (optional)
100100
logvol / --fstype=xfs --name=root --vgname=VolGroup --size=5120 --grow
101101
# Ensure /home Located On Separate Partition
102-
logvol /home --fstype=xfs --name=home --vgname=VolGroup --size=1024 --fsoptions="nodev"
102+
logvol /home --fstype=xfs --name=home --vgname=VolGroup --size=1024 --fsoptions="nodev,nosuid"
103103
# Ensure /tmp Located On Separate Partition
104104
logvol /tmp --fstype=xfs --name=tmp --vgname=VolGroup --size=1024 --fsoptions="nodev,noexec,nosuid"
105105
# Ensure /var/tmp Located On Separate Partition
106106
logvol /var/tmp --fstype=xfs --name=vartmp --vgname=VolGroup --size=1024 --fsoptions="nodev,nosuid,noexec"
107107
# Ensure /var Located On Separate Partition
108-
logvol /var --fstype=xfs --name=var --vgname=VolGroup --size=3072
108+
logvol /var --fstype=xfs --name=var --vgname=VolGroup --size=3072 --fsoptions="nodev,nosuid"
109109
# Ensure /var/log Located On Separate Partition
110-
logvol /var/log --fstype=xfs --name=varlog --vgname=VolGroup --size=1024
110+
logvol /var/log --fstype=xfs --name=varlog --vgname=VolGroup --size=1024 --fsoptions="nodev,nosuid,noexec"
111111
# Ensure /var/log/audit Located On Separate Partition
112-
logvol /var/log/audit --fstype=xfs --name=varlogaudit --vgname=VolGroup --size=512
112+
logvol /var/log/audit --fstype=xfs --name=varlogaudit --vgname=VolGroup --size=512 --fsoptions="nodev,nosuid,noexec"
113113
logvol swap --name=swap --vgname=VolGroup --size=2016
114114

115115

products/rhel9/kickstart/ssg-rhel9-cis_workstation_l2-ks.cfg

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -99,17 +99,17 @@ volgroup VolGroup pv.01
9999
# Create particular logical volumes (optional)
100100
logvol / --fstype=xfs --name=root --vgname=VolGroup --size=5120 --grow
101101
# Ensure /home Located On Separate Partition
102-
logvol /home --fstype=xfs --name=home --vgname=VolGroup --size=1024 --fsoptions="nodev"
102+
logvol /home --fstype=xfs --name=home --vgname=VolGroup --size=1024 --fsoptions="nodev,nosuid"
103103
# Ensure /tmp Located On Separate Partition
104104
logvol /tmp --fstype=xfs --name=tmp --vgname=VolGroup --size=1024 --fsoptions="nodev,noexec,nosuid"
105105
# Ensure /var/tmp Located On Separate Partition
106106
logvol /var/tmp --fstype=xfs --name=vartmp --vgname=VolGroup --size=1024 --fsoptions="nodev,nosuid,noexec"
107107
# Ensure /var Located On Separate Partition
108-
logvol /var --fstype=xfs --name=var --vgname=VolGroup --size=3072
108+
logvol /var --fstype=xfs --name=var --vgname=VolGroup --size=3072 --fsoptions="nodev,nosuid"
109109
# Ensure /var/log Located On Separate Partition
110-
logvol /var/log --fstype=xfs --name=varlog --vgname=VolGroup --size=1024
110+
logvol /var/log --fstype=xfs --name=varlog --vgname=VolGroup --size=1024 --fsoptions="nodev,nosuid,noexec"
111111
# Ensure /var/log/audit Located On Separate Partition
112-
logvol /var/log/audit --fstype=xfs --name=varlogaudit --vgname=VolGroup --size=512
112+
logvol /var/log/audit --fstype=xfs --name=varlogaudit --vgname=VolGroup --size=512 --fsoptions="nodev,nosuid,noexec"
113113
logvol swap --name=swap --vgname=VolGroup --size=2016
114114

115115

0 commit comments

Comments
 (0)