auditd 5.2.3.12 logins should refer to /var/run/faillock #114
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Overall Review of Changes:
In templates/audit/ubtu20cis_5_2_3_12_logins.rules.j2, auditd 5.2.3.12 logins should refer to /var/run/faillock and not /var/log/faillock.
From CIS:
From
man pam_faillock
Issue Fixes:
Fixes #115
Enhancements:
None
How has this been tested?:
This has been tested by cross-checking the configuration created by this ansible role with the CIS Security Configuration Assessment for Ubuntu 20 in Wazuh SIEM (which is based on Ubuntu 20.04 CIS v2.0.0)