|
21 | 21 | name: autofs |
22 | 22 | state: absent |
23 | 23 | purge: "{{ ubtu22cis_purge_apt }}" |
| 24 | + lock_timeout: "{{ ubtu22cis_apt_lock_timeout }}" |
24 | 25 |
|
25 | 26 | - name: "2.1.1 | PATCH | Ensure autofs services are not in use | Mask service" |
26 | 27 | when: |
27 | 28 | - not ubtu22cis_autofs_services |
28 | 29 | - ubtu22cis_autofs_mask |
29 | 30 | ansible.builtin.systemd: |
30 | 31 | name: autofs |
| 32 | + enabled: "{{ ('autofs' in ansible_facts.packages) | ternary(false, omit) }}" |
| 33 | + state: "{{ ('autofs' in ansible_facts.packages) | ternary('stopped', omit) }}" |
31 | 34 | masked: true |
32 | 35 | notify: Systemd daemon reload |
33 | 36 |
|
|
51 | 54 | - avahi |
52 | 55 | state: absent |
53 | 56 | purge: "{{ ubtu22cis_purge_apt }}" |
| 57 | + lock_timeout: "{{ ubtu22cis_apt_lock_timeout }}" |
54 | 58 |
|
55 | 59 | - name: "2.1.2 | PATCH | Ensure avahi daemon services are not in use | Mask service" |
56 | 60 | when: |
|
86 | 90 | name: isc-dhcp-server |
87 | 91 | state: absent |
88 | 92 | purge: "{{ ubtu22cis_purge_apt }}" |
| 93 | + lock_timeout: "{{ ubtu22cis_apt_lock_timeout }}" |
89 | 94 |
|
90 | 95 | - name: "2.1.3 | PATCH | Ensure dhcp server services are not in use | Mask service" |
91 | 96 | when: |
|
121 | 126 | name: bind9 |
122 | 127 | state: absent |
123 | 128 | purge: "{{ ubtu22cis_purge_apt }}" |
| 129 | + lock_timeout: "{{ ubtu22cis_apt_lock_timeout }}" |
124 | 130 |
|
125 | 131 | - name: "2.1.4 | PATCH | Ensure dns server services are not in use | Mask service" |
126 | 132 | when: |
|
151 | 157 | name: dnsmasq |
152 | 158 | state: absent |
153 | 159 | purge: "{{ ubtu22cis_purge_apt }}" |
| 160 | + lock_timeout: "{{ ubtu22cis_apt_lock_timeout }}" |
154 | 161 |
|
155 | 162 | - name: "2.1.5 | PATCH | Ensure dnsmasq services are not in use | Mask service" |
156 | 163 | when: |
|
182 | 189 | name: vsftpd |
183 | 190 | state: absent |
184 | 191 | purge: "{{ ubtu22cis_purge_apt }}" |
| 192 | + lock_timeout: "{{ ubtu22cis_apt_lock_timeout }}" |
185 | 193 |
|
186 | 194 | - name: "2.1.6 | PATCH | Ensure ftp server services are not in use | Mask service" |
187 | 195 | when: |
|
212 | 220 | name: slapd |
213 | 221 | state: absent |
214 | 222 | purge: "{{ ubtu22cis_purge_apt }}" |
| 223 | + lock_timeout: "{{ ubtu22cis_apt_lock_timeout }}" |
215 | 224 |
|
216 | 225 | - name: "2.1.7 | PATCH | Ensure ldap server services are not in use | Mask service" |
217 | 226 | when: |
|
246 | 255 | - dovecot-imapd |
247 | 256 | state: absent |
248 | 257 | purge: "{{ ubtu22cis_purge_apt }}" |
| 258 | + lock_timeout: "{{ ubtu22cis_apt_lock_timeout }}" |
249 | 259 |
|
250 | 260 | - name: "2.1.8 | PATCH | Ensure message access server services are not in use | Mask service" |
251 | 261 | when: |
|
283 | 293 | name: nfs-kernel-server |
284 | 294 | state: absent |
285 | 295 | purge: "{{ ubtu22cis_purge_apt }}" |
| 296 | + lock_timeout: "{{ ubtu22cis_apt_lock_timeout }}" |
286 | 297 |
|
287 | 298 | - name: "2.1.9 | PATCH | Ensure network file system services are not in use | Mask service" |
288 | 299 | when: |
|
314 | 325 | name: ypserv |
315 | 326 | state: absent |
316 | 327 | purge: "{{ ubtu22cis_purge_apt }}" |
| 328 | + lock_timeout: "{{ ubtu22cis_apt_lock_timeout }}" |
317 | 329 |
|
318 | 330 | - name: "2.1.10 | PATCH | Ensure nis server services are not in use | Mask service" |
319 | 331 | when: |
|
343 | 355 | name: cups |
344 | 356 | state: absent |
345 | 357 | purge: "{{ ubtu22cis_purge_apt }}" |
| 358 | + lock_timeout: "{{ ubtu22cis_apt_lock_timeout }}" |
346 | 359 |
|
347 | 360 | - name: "2.1.11 | PATCH | Ensure print server services are not in use | Mask service" |
348 | 361 | when: |
|
379 | 392 | name: rpcbind |
380 | 393 | state: absent |
381 | 394 | purge: "{{ ubtu22cis_purge_apt }}" |
| 395 | + lock_timeout: "{{ ubtu22cis_apt_lock_timeout }}" |
382 | 396 |
|
383 | 397 | - name: "2.1.12 | PATCH | Ensure rpcbind services are not in use | Mask service" |
384 | 398 | when: |
|
414 | 428 | name: rsync |
415 | 429 | state: absent |
416 | 430 | purge: "{{ ubtu22cis_purge_apt }}" |
| 431 | + lock_timeout: "{{ ubtu22cis_apt_lock_timeout }}" |
417 | 432 |
|
418 | 433 | - name: "2.1.13 | PATCH | Ensure rsync services are not in use | Mask service" |
419 | 434 | when: |
|
445 | 460 | name: samba |
446 | 461 | state: absent |
447 | 462 | purge: "{{ ubtu22cis_purge_apt }}" |
| 463 | + lock_timeout: "{{ ubtu22cis_apt_lock_timeout }}" |
448 | 464 |
|
449 | 465 | - name: "2.1.14 | PATCH | Ensure samba file server services are not in use | Mask service" |
450 | 466 | when: |
|
476 | 492 | name: snmpd |
477 | 493 | state: absent |
478 | 494 | purge: "{{ ubtu22cis_purge_apt }}" |
| 495 | + lock_timeout: "{{ ubtu22cis_apt_lock_timeout }}" |
479 | 496 |
|
480 | 497 | - name: "2.1.15 | PATCH | Ensure snmp services are not in use | Mask service" |
481 | 498 | when: |
|
506 | 523 | name: tftpd-hpa |
507 | 524 | state: absent |
508 | 525 | purge: "{{ ubtu22cis_purge_apt }}" |
| 526 | + lock_timeout: "{{ ubtu22cis_apt_lock_timeout }}" |
509 | 527 |
|
510 | 528 | - name: "2.1.16 | PATCH | Ensure tftp server services are not in use | Mask service" |
511 | 529 | when: |
|
536 | 554 | name: squid |
537 | 555 | state: absent |
538 | 556 | purge: "{{ ubtu22cis_purge_apt }}" |
| 557 | + lock_timeout: "{{ ubtu22cis_apt_lock_timeout }}" |
539 | 558 |
|
540 | 559 | - name: "2.1.17 | PATCH | Ensure web proxy server services are not in use | Mask service" |
541 | 560 | when: |
|
568 | 587 | name: apache2 |
569 | 588 | state: absent |
570 | 589 | purge: "{{ ubtu22cis_purge_apt }}" |
| 590 | + lock_timeout: "{{ ubtu22cis_apt_lock_timeout }}" |
571 | 591 |
|
572 | 592 | - name: "2.1.18 | PATCH | Ensure web server services are not in use | Remove nginx server" |
573 | 593 | when: |
|
577 | 597 | name: nginx |
578 | 598 | state: absent |
579 | 599 | purge: "{{ ubtu22cis_purge_apt }}" |
| 600 | + lock_timeout: "{{ ubtu22cis_apt_lock_timeout }}" |
580 | 601 |
|
581 | 602 | - name: "2.1.18 | PATCH | Ensure web server services are not in use | Mask httpd service" |
582 | 603 | when: |
|
623 | 644 | name: xinetd |
624 | 645 | purge: "{{ ubtu22cis_purge_apt }}" |
625 | 646 | state: absent |
| 647 | + lock_timeout: "{{ ubtu22cis_apt_lock_timeout }}" |
626 | 648 |
|
627 | 649 | - name: "2.1.19 | PATCH | Ensure xinetd services are not in use | Mask service" |
628 | 650 | when: |
|
649 | 671 | name: xorg-x11-server-common |
650 | 672 | state: absent |
651 | 673 | purge: "{{ ubtu22cis_purge_apt }}" |
| 674 | + lock_timeout: "{{ ubtu22cis_apt_lock_timeout }}" |
652 | 675 |
|
653 | 676 | - name: "2.1.21 | PATCH | Ensure mail transfer agent is configured for local-only mode" |
654 | 677 | when: |
|
0 commit comments