add hardening templating and several enhancements

This commit is contained in:
Stéphane Lesimple
2017-05-18 18:40:09 +02:00
committed by Stéphane Lesimple
parent 2ef500298b
commit 676b17c54f
386 changed files with 701 additions and 449 deletions

View File

@ -0,0 +1 @@
*.cfg

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,4 +0,0 @@
# Configuration for script of same name
status=disabled
# Put here your exceptions concerning admin accounts shells separated by spaces
EXCEPTIONS=""

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,5 +0,0 @@
# Configuration for script of same name
status=disabled
# Put Here your valid suid binaries so that they do not appear during the audit
EXCEPTIONS="/bin/mount /bin/ping /bin/ping6 /bin/su /bin/umount /usr/bin/chfn /usr/bin/chsh /usr/bin/fping /usr/bin/fping6 /usr/bin/gpasswd /usr/bin/mtr /usr/bin/newgrp /usr/bin/passwd /usr/bin/sudo /usr/bin/sudoedit /usr/lib/openssh/ssh-keysign /usr/lib/pt_chown /usr/bin/at"

View File

@ -1,4 +0,0 @@
# Configuration for script of same name
status=disabled
# Put here valid binaries with sgid enabled separated by spaces
EXCEPTIONS="/sbin/unix_chkpwd /usr/bin/bsd-write /usr/bin/chage /usr/bin/crontab /usr/bin/expiry /usr/bin/mutt_dotlock /usr/bin/screen /usr/bin/ssh-agent /usr/bin/wall /usr/sbin/postdrop /usr/sbin/postqueue /usr/bin/at /usr/bin/dotlockfile /usr/bin/mail-lock /usr/bin/mail-touchlock /usr/bin/mail-unlock"

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,4 +0,0 @@
# Configuration for script of same name
status=disabled
# Put here valid accounts with uid 0 separated by spaces
EXCEPTIONS=""

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,4 +0,0 @@
# Configuration for script of same name
status=disabled
# Put here user home directories exceptions, separated by spaces
EXCEPTIONS=""

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

View File

@ -1,2 +0,0 @@
# Configuration for script of same name
status=disabled

Some files were not shown because too many files have changed in this diff Show More