Skip to content

Commit

Permalink
Update to file_permissions_etc_chrony_keys
Browse files Browse the repository at this point in the history
Make it so that chrony can still read it once it drops root
  • Loading branch information
Mab879 committed Oct 22, 2024
1 parent b439aa5 commit 396c235
Showing 1 changed file with 6 additions and 6 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@ documentation_complete: true

title: Verify Permissions On /etc/chrony.keys File

description: '{{{ describe_file_permissions(file="/etc/chrony.keys", perms="0600") }}}'
description: '{{{ describe_file_permissions(file="/etc/chrony.keys", perms="0644") }}}'

rationale: |-
Setting correct permissions on the /etc/chrony.keys file is important
Expand All @@ -17,17 +17,17 @@ identifiers:
cce@rhel9: CCE-86384-5
cce@rhel10: CCE-88155-7

ocil_clause: '{{{ ocil_clause_file_permissions(file="/etc/chrony.keys", perms="0600") }}}'
ocil_clause: '{{{ ocil_clause_file_permissions(file="/etc/chrony.keys", perms="0644") }}}'

ocil: |-
{{{ ocil_file_permissions(file="/etc/chrony.keys", perms="0600") }}}
{{{ ocil_file_permissions(file="/etc/chrony.keys", perms="0644") }}}
fixtext: '{{{ fixtext_file_permissions(file="/etc/chrony.keys", mode="0600") }}}'
fixtext: '{{{ fixtext_file_permissions(file="/etc/chrony.keys", mode="0644") }}}'

srg_requirement: '{{{ srg_requirement_file_permission(file="/etc/chrony.keys", mode="0600") }}}'
srg_requirement: '{{{ srg_requirement_file_permission(file="/etc/chrony.keys", mode="0644") }}}'

template:
name: file_permissions
vars:
filepath: /etc/chrony.keys
filemode: '0600'
filemode: '0644'

0 comments on commit 396c235

Please sign in to comment.