Skip to content

Commit 91ecc19

Browse files
committed
Merge pull request #39 from hardening-io/su_mode
Add mode to su-binary task. Fix #38
2 parents b05517c + 1ff939d commit 91ecc19

File tree

2 files changed

+3
-3
lines changed

2 files changed

+3
-3
lines changed

.travis.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -11,4 +11,4 @@ install:
1111

1212
script:
1313
- ansible-playbook --syntax-check spec/travis.yml
14-
- ansible-playbook --sudo -v --diff spec/travis.yml --skip-tags "sysctl"
14+
- ansible-playbook --sudo -v --diff spec/travis.yml --skip-tags "sysctl" --extra-vars "os_security_users_allow=change_user"

roles/ansible-os-hardening/tasks/minimize_access.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -14,5 +14,5 @@
1414
file: dest='/etc/shadow' owner=root group=root mode=0600
1515

1616
- name: change su-binary to only be accessible to user and group root
17-
file: dest='/bin/su' owner=root group=root mode
18-
when: security_users_allow|default(None) != None
17+
file: dest='/bin/su' owner=root group=root mode=0750
18+
when: os_security_users_allow != None

0 commit comments

Comments
 (0)