diff --git a/tests/hardening/99.1_timeout_tty.sh b/tests/hardening/99.1_timeout_tty.sh index b333419..0b57e6a 100644 --- a/tests/hardening/99.1_timeout_tty.sh +++ b/tests/hardening/99.1_timeout_tty.sh @@ -6,5 +6,11 @@ test_audit() { # shellcheck disable=2154 run blank /opt/debian-cis/bin/hardening/"${script}".sh --audit-all + echo "TMOUT=600" > /etc/profile.d/CIS_99.1_timeout.sh + + describe compliant + register_test retvalshouldbe 0 + run compliant /opt/debian-cis/bin/hardening/"${script}".sh --audit-all + # TODO fill comprehensive tests } diff --git a/tests/hardening/99.2_disable_usb_devices.sh b/tests/hardening/99.2_disable_usb_devices.sh index dbeda10..5226d33 100644 --- a/tests/hardening/99.2_disable_usb_devices.sh +++ b/tests/hardening/99.2_disable_usb_devices.sh @@ -1,7 +1,7 @@ # run-shellcheck test_audit() { - mkdir /etc/udev/rules.d + mkdir /etc/udev/rules.d || true chmod -R 700 /etc/udev describe Running on blank host diff --git a/tests/hardening/99.5.4_ssh_keys_from.sh b/tests/hardening/99.5.4_ssh_keys_from.sh index f830b5b..85ebb1a 100644 --- a/tests/hardening/99.5.4_ssh_keys_from.sh +++ b/tests/hardening/99.5.4_ssh_keys_from.sh @@ -45,6 +45,8 @@ test_audit() { register_test retvalshouldbe 0 run allwdfromip /opt/debian-cis/bin/hardening/"${script}".sh --audit-all + # Cleanup userdel jeantestuser + rm -f /tmp/key1 /tmp/key1.pub }