ansible-hardening/doc/metadata/rhel7/RHEL-07-020230.rst
Major Hayden 0eef112699 Refactor login.defs adjustments [+Docs]
This patch refactors the login.defs adjustments into a single task
that loops over a variable. It also adds tasks for RHEL-07-010200,
RHEL-07-010420, and RHEL-07-020230.

Documentation is included.

Implements: blueprint security-rhel7-stig
Change-Id: I7c1f869d87338547da8943d5aa506ceb871cee68
2016-12-02 13:38:27 +00:00

372 B

---id: RHEL-07-020230 status: implemented tag: auth ---

The umask for authenticated users is set to 077 by the tasks in the security role. This is the default for Ubuntu, CentOS, and Red Hat Enterprise Linux already.

Deployers can choose a different umask value by setting the following Ansible variable:

security_shadow_utils_umask: 077