Files
debian-cis/tests/hardening/ufw_is_installed.sh
damcav35 8aeb22fb60 Damcava35/deb12 scripts 5 (#289)
* refacto: systemd is-active / is-enabled

Manage different object types (service, socket, timer...) in a generic way.

* feat: add debian12 scripts

ufw_is_installed.sh				-> 4.1.1
iptables_persistent_is_not_installed.sh		-> 4.1.2
ufw_is_enabled					-> 4.1.3
nftables_not_installed_with_iptables.sh		-> 4.3.1.2
libpam_runtime_is_version 			-> 5.3.1.1

---------

Co-authored-by: damien cavagnini <damien.cavagnini@corp.ovh.com>
2025-08-14 12:25:25 +02:00

40 lines
1.2 KiB
Bash

# shellcheck shell=bash
# run-shellcheck
test_audit() {
describe set up failed check
apt remove -y ufw iptables-persistent
describe Running failed test
register_test retvalshouldbe 1
# shellcheck disable=2154
run failed "${CIS_CHECKS_DIR}/${script}.sh" --audit-all
describe set up failed resolution
DEBIAN_FRONTEND='noninteractive' apt -o Dpkg::Options::="--force-confdef" -o Dpkg::Options::="--force-confold" install iptables-persistent apt-utils -y
sed -i 's/audit/enabled/' "${CIS_CONF_DIR}/conf.d/${script}.cfg"
describe running failed resolution
# shellcheck disable=2154
"${CIS_CHECKS_DIR}/${script}.sh" --apply || true
describe running failed run after apply
register_test retvalshouldbe 1
# shellcheck disable=2154
run failed "${CIS_CHECKS_DIR}/${script}.sh" --audit-all
describe fix resolution
apt remove -y iptables-persistent
describe running successfull resolution
# shellcheck disable=2154
"${CIS_CHECKS_DIR}/${script}.sh" --apply || true
describe running successfull audit
register_test retvalshouldbe 0
# shellcheck disable=2154
run success "${CIS_CHECKS_DIR}/${script}.sh" --audit-all
apt remove -y ufw
apt autoremove -y
}