Saltstack Official Linux Formula
Du kan inte välja fler än 25 ämnen Ämnen måste starta med en bokstav eller siffra, kan innehålla bindestreck ('-') och vara max 35 tecken långa.

cis-3-5-2.yml 1.1KB

1234567891011121314151617181920212223242526272829303132333435363738394041
  1. # 3.5.2 Ensure SCTP is disabled
  2. #
  3. # Description
  4. # ===========
  5. # The Stream Control Transmission Protocol (SCTP) is a transport layer
  6. # protocol used to support message oriented communication, with several
  7. # streams of messages in one connection. It serves a similar function as
  8. # TCP and UDP, incorporating features of both. It is message-oriented
  9. # like UDP, and ensures reliable in-sequence transport of messages with
  10. # congestion control like TCP.
  11. #
  12. # Rationale
  13. # =========
  14. # If the protocol is not being used, it is recommended that kernel module
  15. # not be loaded, disabling the service to reduce the potential attack surface.
  16. #
  17. # Audit
  18. # =====
  19. # Run the following commands and verify the output is as indicated:
  20. #
  21. # # modprobe -n -v sctp
  22. # install /bin/true
  23. # # lsmod | grep sctp
  24. # <No output>
  25. #
  26. # Remediation
  27. # ===========
  28. #
  29. # Edit or create the file /etc/modprobe.d/CIS.conf and add the following line:
  30. #
  31. # install sctp /bin/true
  32. #
  33. parameters:
  34. linux:
  35. system:
  36. kernel:
  37. module:
  38. sctp:
  39. install:
  40. command: /bin/true