Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-102658

Add Support for Setting Policy Rules

Linking RHIVOS CVEs to...Migration: Automation ...SWIFT: POC ConversionSync from "Extern...XMLWordPrintable

    • None
    • rhel-system-roles
    • 0
    • False
    • False
    • Hide

      None

      Show
      None
    • Yes
    • Red Hat Enterprise Linux
    • None
    • None
    • None
    • Feature
    • Hide
      Feature, enhancement:
      Reason:
      Result:
      Show
      Feature, enhancement: Reason: Result:
    • Proposed
    • Unspecified
    • Unspecified
    • Unspecified
    • None

      Feature request - Add support for setting policy rules by creating `/etc/fapolicyd/rules.d/` rules files.

      I would imagine this could work similarly to how the [fedora.linux_system_roles.sudo](https://github.com/linux-system-roles/sudo?tab=readme-ov-file#sudo_sudoers_files) role works for setting `/etc/sudoers.d/` includes.

      Currently, if any policies are to be set devoted tasks outside of the role are needed, for example:

      ```yaml

      • name: Fapolicyd
        hosts: all
        become: true
        vars:
        fapolicyd_setup_permissive: true
        fapolicyd_setup_integrity: none
        fapolicyd_setup_trust: rpmdb,file

      pre_tasks:

      1. Default deny all except whitelisted. DISA STIG RHEL-09-433016
      • name: Ensure deny-all, permit-by-exception policy
        ansible.builtin.copy:
        dest: /etc/fapolicyd/rules.d/99-deny-all.rules
        content: |
      1. Ansible managed
      2. RHEL-09-433016 - deny-all, permit-by-exception policy
        deny perm=any all : all
        owner: root
        group: root
        mode: '0640'

      roles:

      • fedora.linux_system_roles.fapolicyd

      ```

              rsroka@redhat.com Radovan Sroka (Inactive)
              rmeggins@redhat.com Richard Megginson
              Richard Megginson Richard Megginson
              David Jez David Jez
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

                Created:
                Updated: