ansible-hardening/doc/metadata/rhel6/V-38675.rst
Major Hayden e57593dfd4 Automate the STIG documentation
With the upcoming changes to rebase onto the RHEL 7 STIG controls,
there needs to be a new solution for documentation that is easier
to manage and filter. This patch automates the generation of the STIG
control documentation in the following way:

* A Sphinx extension runs early in the doc build process that writes
  all of the individual STIG control docs as well as ToC pages.
* ToC pages are now sorted by severity, tag, and implementation status.
* A giant listing of controls is easier to navigate now.
* Docs are generated from metadata in the /doc/metadata directory. New
  documentation only needs to be added there. (Will explain this in
  the developer notes in a subsequent patch.)

Implements: blueprint security-rhel7-stig
Change-Id: I455af1121049f52193e98e2c9cb1ba5d4c292386
2016-09-09 14:43:30 +00:00

378 B

---id: V-38675 status: implemented tag: misc ---

The security role will add a file in /etc/security/limits.d/ that disables core dumps for all users. Although this setting is more secure, it can prevent users from debugging kernel errors.

To opt-out of this change, set the following Ansible variable to no:

security_disable_core_dumps: no