We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
1 parent e463022 commit 2cf76cdCopy full SHA for 2cf76cd
tasks/level-1/5.4.4.yml
@@ -4,9 +4,10 @@
4
# 5.4.4 Ensure default user umask is 027 or more restrictive
5
6
- name: 5.4.4 - Ensure default user umask is 027 or more restrictive
7
- lineinfile:
8
- dest: "{{ item }}"
9
- line: "{{ cis_umask_default }}"
+ replace:
+ path: "{{ item }}"
+ regexp: '(^\s+umask) (002|022)'
10
+ replace: '\1 {{ cis_umask_default }}'
11
with_items: "{{ cis_umask_shell_files }}"
12
tags:
13
- level-1
0 commit comments