ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Securing Linux with Ansible

    IT Discussion
    ansible linux security
    6
    13
    1.1k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      Alex Sage
      last edited by scottalanmiller

      This video is focused on OpenStack however it works with and without OpenStack. Supports RHEL 7, CentOS 7 and Ubuntu 16.04.

      You successfully pitched an OpenStack cloud to your company. Great! But wait -- here comes the security team and the auditors! What do you do now? Help is on the way (in the form of an Ansible role)! The openstack-ansible-security role, first unveiled at the Austin Summit, applies security controls from the Security Technical Implementation Guide (STIG) across OpenStack clouds using Ansible...

      Youtube Video

      1 Reply Last reply Reply Quote 1
      • ObsolesceO
        Obsolesce
        last edited by

        I made a really good SaltStack state for Linux hardening. Works great, and now pass OpenVAS with flying colours for example.

        A scottalanmillerS 2 Replies Last reply Reply Quote 3
        • A
          Alex Sage @Obsolesce
          last edited by

          @tim_g said in Securing Linux with Ansible:

          I made a really good SaltStack state for Linux hardening. Works great, and now pass OpenVAS with flying colours for example.

          Did you post it here? If so, I missed it...

          1 Reply Last reply Reply Quote 3
          • scottalanmillerS
            scottalanmiller @Obsolesce
            last edited by

            @tim_g said in Securing Linux with Ansible:

            I made a really good SaltStack state for Linux hardening. Works great, and now pass OpenVAS with flying colours for example.

            Where is the ML article about that? πŸ˜‰

            ObsolesceO NashBrydgesN 2 Replies Last reply Reply Quote 4
            • ObsolesceO
              Obsolesce @scottalanmiller
              last edited by

              @scottalanmiller said in Securing Linux with Ansible:

              @tim_g said in Securing Linux with Ansible:

              I made a really good SaltStack state for Linux hardening. Works great, and now pass OpenVAS with flying colours for example.

              Where is the ML article about that? πŸ˜‰

              I can paste it here for now if ya like... but I have a lot of stuff saved up to put in some blog post drafts I have going. I usually put stuff here afterwards.

              1 Reply Last reply Reply Quote 2
              • NashBrydgesN
                NashBrydges @scottalanmiller
                last edited by

                @scottalanmiller said in Securing Linux with Ansible:

                @tim_g said in Securing Linux with Ansible:

                I made a really good SaltStack state for Linux hardening. Works great, and now pass OpenVAS with flying colours for example.

                Where is the ML article about that? πŸ˜‰

                Damn! I can only upvote this once.

                1 Reply Last reply Reply Quote 1
                • scottalanmillerS
                  scottalanmiller
                  last edited by

                  Where is the ML article on that?

                  Now we can upvote it twice πŸ˜‰

                  NashBrydgesN 1 Reply Last reply Reply Quote 2
                  • NashBrydgesN
                    NashBrydges @scottalanmiller
                    last edited by

                    @scottalanmiller Done :grinning_face_with_smiling_eyes:

                    1 Reply Last reply Reply Quote 0
                    • KellyK
                      Kelly
                      last edited by

                      And this is why we need a way to post articles/how-to's in something other than a discussion thread. They get lost and forgotten.

                      ObsolesceO 1 Reply Last reply Reply Quote 0
                      • ObsolesceO
                        Obsolesce @Kelly
                        last edited by

                        @kelly said in Securing Linux with Ansible:

                        And this is why we need a way to post articles/how-to's in something other than a discussion thread. They get lost and forgotten.

                        Tags help a TON with this. Look up SaltStack tag for example.

                        KellyK 1 Reply Last reply Reply Quote 1
                        • KellyK
                          Kelly @Obsolesce
                          last edited by

                          @tim_g said in Securing Linux with Ansible:

                          @kelly said in Securing Linux with Ansible:

                          And this is why we need a way to post articles/how-to's in something other than a discussion thread. They get lost and forgotten.

                          Tags help a TON with this. Look up SaltStack tag for example.

                          It helps, but overtime it will still get buried. In addition, if, as happens frequently, the original post receives input from replies, it may no longer be 100% accurate. There is no way to deduce that without reading the entire comment chain. Forums are terrible places to store knowledge imo.

                          scottalanmillerS 1 Reply Last reply Reply Quote 0
                          • scottalanmillerS
                            scottalanmiller @Kelly
                            last edited by

                            @kelly said in Securing Linux with Ansible:

                            @tim_g said in Securing Linux with Ansible:

                            @kelly said in Securing Linux with Ansible:

                            And this is why we need a way to post articles/how-to's in something other than a discussion thread. They get lost and forgotten.

                            Tags help a TON with this. Look up SaltStack tag for example.

                            It helps, but overtime it will still get buried. In addition, if, as happens frequently, the original post receives input from replies, it may no longer be 100% accurate. There is no way to deduce that without reading the entire comment chain. Forums are terrible places to store knowledge imo.

                            That's mostly true, although there are ways to make it work better. Like the Linux Admin book.

                            1 Reply Last reply Reply Quote 0
                            • stacksofplatesS
                              stacksofplates
                              last edited by

                              Here’s mine based off of the DISA STIGS.

                              https://mangolassi.it/topic/15041/ansible-hardening-role

                              1 Reply Last reply Reply Quote 0
                              • 1 / 1
                              • First post
                                Last post