Skip to content

Commit 2cf76cd

Browse files
authored
Thanks to Paul O'Keefe <paul@megabelle.net> for the commit email
1 parent e463022 commit 2cf76cd

File tree

1 file changed

+4
-3
lines changed

1 file changed

+4
-3
lines changed

tasks/level-1/5.4.4.yml

Lines changed: 4 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -4,9 +4,10 @@
44
# 5.4.4 Ensure default user umask is 027 or more restrictive
55

66
- name: 5.4.4 - Ensure default user umask is 027 or more restrictive
7-
lineinfile:
8-
dest: "{{ item }}"
9-
line: "{{ cis_umask_default }}"
7+
replace:
8+
path: "{{ item }}"
9+
regexp: '(^\s+umask) (002|022)'
10+
replace: '\1 {{ cis_umask_default }}'
1011
with_items: "{{ cis_umask_shell_files }}"
1112
tags:
1213
- level-1

0 commit comments

Comments
 (0)