Changeset 198

Show
Ignore:
Timestamp:
06/11/08 13:35:44 (4 months ago)
Author:
slawrence
Message:

- Remove 'quiet' option from pam_tally. It isn't a valid option.
- Stop 'mesg n' from being written to /etc/environment.
- Stop clip rpm from overwriting the changes the kickstart/stigs make to audit.rules.

Files:

Legend:

Unmodified
Added
Removed
Modified
Copied
Moved
  • trunk/RHEL5.2/RPM/clip.spec

    r133 r198  
    3737%defattr(-,root,root,-) 
    3838/usr/share/clip/conf/audit/auditd.conf 
    39 /usr/share/clip/conf/audit/audit.rules 
     39#/usr/share/clip/conf/audit/audit.rules 
    4040/usr/share/clip/conf/pam/login.pam 
    4141/usr/share/clip/conf/pam/newrole.pam 
  • trunk/RHEL5.2/conf/audit/Makefile

    r1 r198  
    11install: 
    22        test -d $(DESTDIR)$(CONFDIR)/audit | install -d -m 755 $(DESTDIR)$(CONFDIR)/audit  
    3         install -m 644 *.conf *.rules $(DESTDIR)$(CONFDIR)/audit 
     3#       install -m 644 *.conf *.rules $(DESTDIR)$(CONFDIR)/audit 
     4        install -m 644 *.conf $(DESTDIR)$(CONFDIR)/audit 
  • trunk/RHEL5.2/kickstart/clip.ks

    r197 r198  
    362362# User changes will be destroyed the next time authconfig is run. 
    363363#5 login attempts within 30 seconds.  Locked out for 60 seconds if fail 
    364 auth        required      pam_tally.so deny=3 onerr=fail unlock_time=900 quiet 
     364auth        required      pam_tally.so deny=3 onerr=fail unlock_time=900 
    365365auth        required      pam_env.so 
    366366auth        sufficient    pam_unix.so nullok try_first_pass audit 
     
    525525## (GEN001780: CAT III) (Previously – G112) The SA will ensure global 
    526526## initialization files contain the command mesg –n. 
    527 for FILE in /etc/{profile,bashrc,environment}; do 
     527for FILE in /etc/{profile,bashrc}; do 
    528528        echo "mesg n" >> $FILE 
    529529done; 
  • trunk/RHEL5.2/scripts/installer.in

    r193 r198  
    3939InstallAudit() { 
    4040    Copy $AUDITDIR/auditd.conf /etc/audit/auditd.conf 
    41     Copy $AUDITDIR/audit.rules /etc/audit/audit.rules 
     41#    Copy $AUDITDIR/audit.rules /etc/audit/audit.rules 
    4242    auditctl -R /etc/audit/audit.rules 
    4343} 
  • trunk/RHEL5.2/scripts/stig-fix/cat2/gen000460.sh

    r196 r198  
    1313# User changes will be destroyed the next time authconfig is run. 
    1414#5 login attempts within 30 seconds.  Locked out for 60 seconds if fail 
    15 auth        required      pam_tally.so deny=3 onerr=fail unlock_time=900 quiet 
     15auth        required      pam_tally.so deny=3 onerr=fail unlock_time=900 
    1616auth        required      pam_env.so 
    1717auth        sufficient    pam_unix.so nullok try_first_pass audit 
  • trunk/RHEL5.2/scripts/stig-fix/cat3/gen001780.sh

    r144 r198  
    77echo '                    initialization files' 
    88echo '===================================================' 
    9 for FILE in /etc/{profile,bashrc,environment}; do 
     9for FILE in /etc/{profile,bashrc}; do 
    1010        echo "mesg n" >> $FILE 
    1111done;