Saltstack Official Linux Formula
You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

37 lines
811B

  1. # 1.1.1.4 Ensure mounting of hfs filesystems is disabled
  2. #
  3. # Description
  4. # ===========
  5. # The hfs filesystem type is a hierarchical filesystem that allows
  6. # you to mount Mac OS filesystems.
  7. #
  8. # Rationale
  9. # =========
  10. # Removing support for unneeded filesystem types reduces the local attack
  11. # surface of the system. If this filesystem type is not needed, disable it.
  12. #
  13. # Audit
  14. # =====
  15. # Run the following commands and verify the output is as indicated:
  16. #
  17. # # modprobe -n -v hfs
  18. # install /bin/true
  19. # # lsmod | grep hfs
  20. # <No output>
  21. #
  22. # Remediation
  23. # ===========
  24. # Edit or create the file /etc/modprobe.d/CIS.conf and add the following line:
  25. #
  26. # install hfs /bin/true
  27. #
  28. parameters:
  29. linux:
  30. system:
  31. kernel:
  32. module:
  33. hfs:
  34. install:
  35. command: /bin/true