|
5 | 5 | # disruption = low |
6 | 6 |
|
7 | 7 | # Copied and modified from `file_permissions/ansible.yml` template |
| 8 | +# |
| 9 | +# Sets mode 0600 and ownership root:root on all audit config files. |
| 10 | +# Installs an auditd.service dropin to restore 0600 on audit.rules after augenrules |
| 11 | +# rewrites it to 0640 when /etc/audit/rules.d/ content changes (RHEL 8/9 only, not containers). |
8 | 12 |
|
9 | | -- name: Ensure audit config files are not more permissive than 0600 |
| 13 | +- name: Set /etc/audit/audit.rules and /etc/audit/auditd.conf to 0600, owned by root |
| 14 | + ansible.builtin.file: |
| 15 | + path: "{{ item }}" |
| 16 | + mode: '0600' |
| 17 | + owner: root |
| 18 | + group: root |
| 19 | + state: file |
| 20 | + loop: |
| 21 | + - /etc/audit/audit.rules |
| 22 | + - /etc/audit/auditd.conf |
| 23 | + failed_when: false |
| 24 | + |
| 25 | +- name: Set /etc/audit/rules.d/*.rules files to 0600, owned by root |
| 26 | + ansible.builtin.file: |
| 27 | + path: "{{ item }}" |
| 28 | + mode: '0600' |
| 29 | + owner: root |
| 30 | + group: root |
| 31 | + state: file |
| 32 | + with_fileglob: |
| 33 | + - /etc/audit/rules.d/*.rules |
| 34 | + |
| 35 | +- name: Install ExecStartPost dropin on auditd.service |
10 | 36 | block: |
11 | | - - name: Set /etc/audit/audit.rules and /etc/audit/auditd.conf to 0600 |
12 | | - ansible.builtin.file: |
13 | | - path: "{{ item }}" |
14 | | - mode: '0600' |
15 | | - state: file |
16 | | - loop: |
17 | | - - /etc/audit/audit.rules |
18 | | - - /etc/audit/auditd.conf |
19 | | - failed_when: false |
20 | | - |
21 | | - - name: Set /etc/audit/rules.d/*.rules files to 0600 |
22 | | - ansible.builtin.file: |
23 | | - path: "{{ item }}" |
24 | | - mode: '0600' |
25 | | - state: file |
26 | | - with_fileglob: |
27 | | - - /etc/audit/rules.d/*.rules |
28 | | - |
29 | | - # augenrules --load hardcodes chmod 0640 on audit.rules on every rewrite of the rules.d files. |
30 | | - # Install ExecStartPost in auditd.service to restore 0600 after each run. |
31 | | - # Runs inside the auditd_t SELinux domain which has write access to auditd_etc_t files. |
32 | | - # On RHEL 8/9, augenrules is called via ExecStartPost in auditd.service directly. |
33 | 37 | - name: Create dropin directory /etc/systemd/system/auditd.service.d |
34 | 38 | ansible.builtin.file: |
35 | 39 | path: /etc/systemd/system/auditd.service.d |
36 | 40 | state: directory |
37 | 41 | mode: '0755' |
38 | 42 |
|
39 | | - - name: Install /etc/systemd/system/auditd.service.d/permissions.conf - chmod audit.rules to 0600 after augenrules runs |
| 43 | + - name: Install /etc/systemd/system/auditd.service.d/permissions.conf |
40 | 44 | ansible.builtin.copy: |
41 | 45 | dest: /etc/systemd/system/auditd.service.d/permissions.conf |
42 | 46 | content: | |
43 | 47 | [Service] |
44 | 48 | ExecStartPost=/usr/bin/chmod 0600 /etc/audit/audit.rules |
45 | 49 | mode: '0644' |
46 | 50 |
|
| 51 | + - name: Restore SELinux context on /etc/systemd/system/auditd.service.d/permissions.conf |
| 52 | + ansible.builtin.command: restorecon /etc/systemd/system/auditd.service.d/permissions.conf |
| 53 | + changed_when: false |
| 54 | + |
47 | 55 | - name: Reload systemd daemon to pick up permissions.conf |
48 | 56 | ansible.builtin.systemd: |
49 | 57 | daemon_reload: true |
|
0 commit comments