Damcava35/deb12 scripts 5 (#289)

* refacto: systemd is-active / is-enabled

Manage different object types (service, socket, timer...) in a generic way.

* feat: add debian12 scripts

ufw_is_installed.sh				-> 4.1.1
iptables_persistent_is_not_installed.sh		-> 4.1.2
ufw_is_enabled					-> 4.1.3
nftables_not_installed_with_iptables.sh		-> 4.3.1.2
libpam_runtime_is_version 			-> 5.3.1.1

---------

Co-authored-by: damien cavagnini <damien.cavagnini@corp.ovh.com>
This commit is contained in:
damcav35
2025-08-14 12:25:25 +02:00
committed by GitHub
parent 94f110d9b3
commit 8aeb22fb60
11 changed files with 562 additions and 19 deletions

View File

@@ -0,0 +1,23 @@
# shellcheck shell=bash
# run-shellcheck
test_audit() {
describe set up successful check
apt remove -y ufw iptables-persistent
describe Running success test
register_test retvalshouldbe 0
# shellcheck disable=2154
run failure "${CIS_CHECKS_DIR}/${script}.sh" --audit-all
describe set up failed check
DEBIAN_FRONTEND='noninteractive' apt -o Dpkg::Options::="--force-confdef" -o Dpkg::Options::="--force-confold" install iptables-persistent apt-utils -y
describe running failed check
register_test retvalshouldbe 1
# shellcheck disable=2154
run success "${CIS_CHECKS_DIR}/${script}.sh" --audit-all
apt remove -y iptables-persistent
apt autoremove -y
}

View File

@@ -0,0 +1,10 @@
# shellcheck shell=bash
# run-shellcheck
test_audit() {
# at the time of writing, there is only one version of libpam-runtime available
describe Checking on blank host
register_test retvalshouldbe 0
# shellcheck disable=2154
run blank "${CIS_CHECKS_DIR}/${script}.sh" --audit-all
}

View File

@@ -0,0 +1,24 @@
# shellcheck shell=bash
# run-shellcheck
test_audit() {
describe set up successful check
apt remove -y nftables
apt install -y iptables
describe Running success test
register_test retvalshouldbe 0
# shellcheck disable=2154
run success "${CIS_CHECKS_DIR}/${script}.sh" --audit-all
describe set up failed check
DEBIAN_FRONTEND='noninteractive' apt -o Dpkg::Options::="--force-confdef" -o Dpkg::Options::="--force-confold" install nftables apt-utils -y
describe running failed check
register_test retvalshouldbe 1
# shellcheck disable=2154
run failed "${CIS_CHECKS_DIR}/${script}.sh" --audit-all
apt remove -y nftables iptables
apt autoremove -y
}

View File

@@ -0,0 +1,11 @@
# shellcheck shell=bash
# run-shellcheck
test_audit() {
# not much to test here, we are running in a container, we wont check service state
describe Checking blank host
register_test retvalshouldbe 1
# shellcheck disable=2154
run blank "${CIS_CHECKS_DIR}/${script}.sh" --audit-all
}

View File

@@ -0,0 +1,39 @@
# shellcheck shell=bash
# run-shellcheck
test_audit() {
describe set up failed check
apt remove -y ufw iptables-persistent
describe Running failed test
register_test retvalshouldbe 1
# shellcheck disable=2154
run failed "${CIS_CHECKS_DIR}/${script}.sh" --audit-all
describe set up failed resolution
DEBIAN_FRONTEND='noninteractive' apt -o Dpkg::Options::="--force-confdef" -o Dpkg::Options::="--force-confold" install iptables-persistent apt-utils -y
sed -i 's/audit/enabled/' "${CIS_CONF_DIR}/conf.d/${script}.cfg"
describe running failed resolution
# shellcheck disable=2154
"${CIS_CHECKS_DIR}/${script}.sh" --apply || true
describe running failed run after apply
register_test retvalshouldbe 1
# shellcheck disable=2154
run failed "${CIS_CHECKS_DIR}/${script}.sh" --audit-all
describe fix resolution
apt remove -y iptables-persistent
describe running successfull resolution
# shellcheck disable=2154
"${CIS_CHECKS_DIR}/${script}.sh" --apply || true
describe running successfull audit
register_test retvalshouldbe 0
# shellcheck disable=2154
run success "${CIS_CHECKS_DIR}/${script}.sh" --audit-all
apt remove -y ufw
apt autoremove -y
}