ansible-lockdown/RHEL8-STIG

Allow exceptions for RHEL-08-010380 enforcement

prestonSeaman2 opened this issue · 2 comments

Feature Request or Enhancement

  • Feature [x]
  • Enhancement []

Summary of Request
When the RHEL-08-010380 task runs it removes the NOPASSWD from certain sudoers file. This causes an issue in some cases when it comes to privilege escalation. For example when 010381 is run because it is asking for a password to authenticate privilege escalation attempt.

Describe Alternatives You've Considered
Give option to allow exceptions to the RHEL-08-010380 task.

hi @prestonSeaman2

Great idea, i am looking to implement now for the next release.

Thanks

uk-bolly