Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add /dev/shm to CIS Kickstarts #10286

Merged
merged 8 commits into from
Mar 16, 2023
4 changes: 3 additions & 1 deletion products/rhel7/kickstart/ssg-rhel7-cis-ks.cfg
Original file line number Diff line number Diff line change
Expand Up @@ -104,7 +104,7 @@ part pv.01 --grow --size=1
volgroup VolGroup --pesize=4096 pv.01

# Create particular logical volumes (optional)
logvol / --fstype=xfs --name=LogVol06 --vgname=VolGroup --size=11264 --grow
logvol / --fstype=xfs --name=LogVol06 --vgname=VolGroup --size=10752 --grow
# Ensure /home Located On Separate Partition
logvol /home --fstype=xfs --name=LogVol02 --vgname=VolGroup --size=1024 --fsoptions="nodev"
# Ensure /tmp Located On Separate Partition
Expand All @@ -117,6 +117,8 @@ logvol /var --fstype=xfs --name=LogVol03 --vgname=VolGroup --size=2048
logvol /var/log --fstype=xfs --name=LogVol04 --vgname=VolGroup --size=1024
# Ensure /var/log/audit Located On Separate Partition
logvol /var/log/audit --fstype=xfs --name=LogVol05 --vgname=VolGroup --size=512
# Ensure /dev/shm Located on Separate Partition
logvol /dev/shm --name=LogVol8 --vgname=VolGroup --size=512 --fsoptions="nodev,nosuid,noexec"
logvol swap --name=lv_swap --vgname=VolGroup --size=2016


Expand Down
4 changes: 3 additions & 1 deletion products/rhel7/kickstart/ssg-rhel7-cis_server_l1-ks.cfg
Original file line number Diff line number Diff line change
Expand Up @@ -104,9 +104,11 @@ part pv.01 --grow --size=1
volgroup VolGroup --pesize=4096 pv.01

# Create particular logical volumes (optional)
logvol / --fstype=xfs --name=LogVol06 --vgname=VolGroup --size=11264 --grow
logvol / --fstype=xfs --name=LogVol06 --vgname=VolGroup --size=10752 --grow
# Ensure /tmp Located On Separate Partition
logvol /tmp --fstype=xfs --name=LogVol01 --vgname=VolGroup --size=1024 --fsoptions="nodev,noexec,nosuid"
# Ensure /dev/shm Located on Separate Partition
logvol /dev/shm --name=LogVol8 --vgname=VolGroup --size=512 --fsoptions="nodev,nosuid,noexec"
logvol swap --name=lv_swap --vgname=VolGroup --size=2016


Expand Down
4 changes: 3 additions & 1 deletion products/rhel7/kickstart/ssg-rhel7-cis_workstation_l1-ks.cfg
Original file line number Diff line number Diff line change
Expand Up @@ -104,9 +104,11 @@ part pv.01 --grow --size=1
volgroup VolGroup --pesize=4096 pv.01

# Create particular logical volumes (optional)
logvol / --fstype=xfs --name=LogVol06 --vgname=VolGroup --size=11264 --grow
logvol / --fstype=xfs --name=LogVol06 --vgname=VolGroup --size=10752 --grow
# Ensure /tmp Located On Separate Partition
logvol /tmp --fstype=xfs --name=LogVol01 --vgname=VolGroup --size=1024 --fsoptions="nodev,noexec,nosuid"
# Ensure /dev/shm Located on Separate Partition
logvol /dev/shm --name=LogVol8 --vgname=VolGroup --size=512 --fsoptions="nodev,nosuid,noexec"
logvol swap --name=lv_swap --vgname=VolGroup --size=2016


Expand Down
4 changes: 3 additions & 1 deletion products/rhel7/kickstart/ssg-rhel7-cis_workstation_l2-ks.cfg
Original file line number Diff line number Diff line change
Expand Up @@ -104,7 +104,7 @@ part pv.01 --grow --size=1
volgroup VolGroup --pesize=4096 pv.01

# Create particular logical volumes (optional)
logvol / --fstype=xfs --name=LogVol06 --vgname=VolGroup --size=11264 --grow
logvol / --fstype=xfs --name=LogVol06 --vgname=VolGroup --size=10752 --grow
# Ensure /home Located On Separate Partition
logvol /home --fstype=xfs --name=LogVol02 --vgname=VolGroup --size=1024 --fsoptions="nodev"
# Ensure /tmp Located On Separate Partition
Expand All @@ -117,6 +117,8 @@ logvol /var --fstype=xfs --name=LogVol03 --vgname=VolGroup --size=2048
logvol /var/log --fstype=xfs --name=LogVol04 --vgname=VolGroup --size=1024
# Ensure /var/log/audit Located On Separate Partition
logvol /var/log/audit --fstype=xfs --name=LogVol05 --vgname=VolGroup --size=512
# Ensure /dev/shm Located on Separate Partition
logvol /dev/shm --name=LogVol8 --vgname=VolGroup --size=512 --fsoptions="nodev,nosuid,noexec"
logvol swap --name=lv_swap --vgname=VolGroup --size=2016


Expand Down
5 changes: 4 additions & 1 deletion products/rhel9/kickstart/ssg-rhel9-cis-ks.cfg
Original file line number Diff line number Diff line change
Expand Up @@ -91,11 +91,14 @@ clearpart --linux --initlabel
part /boot --fstype=xfs --size=512
part pv.01 --grow --size=1

# Ensure /dev/shm is a separate partition
part /dev/shm --fstype=tmpfs --fsoptions="nodev,nosuid,noexec" --size=512

# Create a Logical Volume Management (LVM) group (optional)
volgroup VolGroup --pesize=4096 pv.01

# Create particular logical volumes (optional)
logvol / --fstype=xfs --name=LogVol06 --vgname=VolGroup --size=10240 --grow
logvol / --fstype=xfs --name=LogVol06 --vgname=VolGroup --size=9728 --grow
# Ensure /home Located On Separate Partition
logvol /home --fstype=xfs --name=LogVol02 --vgname=VolGroup --size=1024 --fsoptions="nodev"
# Ensure /tmp Located On Separate Partition
Expand Down
5 changes: 4 additions & 1 deletion products/rhel9/kickstart/ssg-rhel9-cis_server_l1-ks.cfg
Original file line number Diff line number Diff line change
Expand Up @@ -91,11 +91,14 @@ clearpart --linux --initlabel
part /boot --fstype=xfs --size=512
part pv.01 --grow --size=1

# Ensure /dev/shm is a separate partition
part /dev/shm --fstype=tmpfs --fsoptions="nodev,nosuid,noexec" --size=512

# Create a Logical Volume Management (LVM) group (optional)
volgroup VolGroup --pesize=4096 pv.01

# Create particular logical volumes (optional)
logvol / --fstype=xfs --name=LogVol06 --vgname=VolGroup --size=16896 --grow
logvol / --fstype=xfs --name=LogVol06 --vgname=VolGroup --size=16384 --grow
# Ensure /tmp Located On Separate Partition
logvol /tmp --fstype=xfs --name=LogVol01 --vgname=VolGroup --size=1024 --fsoptions="nodev,noexec,nosuid"
logvol swap --name=lv_swap --vgname=VolGroup --size=2016
Expand Down
5 changes: 4 additions & 1 deletion products/rhel9/kickstart/ssg-rhel9-cis_workstation_l1-ks.cfg
Original file line number Diff line number Diff line change
Expand Up @@ -91,11 +91,14 @@ clearpart --linux --initlabel
part /boot --fstype=xfs --size=512
part pv.01 --grow --size=1

# Ensure /dev/shm is a separate partition
part /dev/shm --fstype=tmpfs --fsoptions="nodev,nosuid,noexec" --size=512

# Create a Logical Volume Management (LVM) group (optional)
volgroup VolGroup --pesize=4096 pv.01

# Create particular logical volumes (optional)
logvol / --fstype=xfs --name=LogVol06 --vgname=VolGroup --size=16896 --grow
logvol / --fstype=xfs --name=LogVol06 --vgname=VolGroup --size=16384 --grow
# Ensure /tmp Located On Separate Partition
logvol /tmp --fstype=xfs --name=LogVol01 --vgname=VolGroup --size=1024 --fsoptions="nodev,noexec,nosuid"
logvol swap --name=lv_swap --vgname=VolGroup --size=2016
Expand Down
5 changes: 4 additions & 1 deletion products/rhel9/kickstart/ssg-rhel9-cis_workstation_l2-ks.cfg
Original file line number Diff line number Diff line change
Expand Up @@ -91,11 +91,14 @@ clearpart --linux --initlabel
part /boot --fstype=xfs --size=512
part pv.01 --grow --size=1

# Ensure /dev/shm is a separate partition
part /dev/shm --fstype=tmpfs --fsoptions="nodev,nosuid,noexec" --size=512

# Create a Logical Volume Management (LVM) group (optional)
volgroup VolGroup --pesize=4096 pv.01

# Create particular logical volumes (optional)
logvol / --fstype=xfs --name=LogVol06 --vgname=VolGroup --size=10240 --grow
logvol / --fstype=xfs --name=LogVol06 --vgname=VolGroup --size=9728 --grow
# Ensure /home Located On Separate Partition
logvol /home --fstype=xfs --name=LogVol02 --vgname=VolGroup --size=1024 --fsoptions="nodev"
# Ensure /tmp Located On Separate Partition
Expand Down