Граф коммитов

6 Коммитов

Автор SHA1 Сообщение Дата
Minghe Ren e519da0abd
Security changes to meet Azure security baseline (#3713)
* first commit of MarinerFedRamp2.0

* first commit for FedRAMP2.0

* patched all the asc cases in source code

* address Daniel's review comments for Mariner 2.0 FedRAMP

* move dsiabling ICMP redirect from source to packer

* Update SPECS/shadow-utils/shadow-utils.spec

Co-authored-by: Christopher Co <35273088+christopherco@users.noreply.github.com>

* Update SPECS/fedramp/fedramp.spec

Co-authored-by: Christopher Co <35273088+christopherco@users.noreply.github.com>

* address the comments in 2nd round reviews

* add asc.spec to replace fedramp.spec

* delete fedramp spec

* fix typo and remove changes for system-password

* update manifest file

* remove some unnecessary changes

* add empty line at end

* update to pass PR check

* address 1st round review comments

* update changelog for license

* address review comments

* remove ssh access

Co-authored-by: rmhsawyer <mingheren@gmail.com>
Co-authored-by: Christopher Co <35273088+christopherco@users.noreply.github.com>
2022-09-13 11:33:30 -07:00
Andrew Phelps 801b122599
Move su from shadow-utils to util-linux (#3336)
* move su from shadow-utils to util-linux

* update manifests

* remove su pam config from shadow-utils

* restore su pam from shadow-utils

* fix su file

* fix shadow-utils BR

* update changelog

* update based on PR feedback
2022-07-08 13:08:25 -07:00
Chris PeBenito 1e2e1afe61 shadow-utils: Make pam_loginuid optional.
This requires audit, which isn't used on all systems.
2021-10-26 17:56:25 +00:00
Chris PeBenito f4a923205f shadow-utils: Update SELinux and loginuid session entries.
The current pam.d config sets the loginuid by su/sudo. The loginuid should
always reflect the UID that the user logged in as.

Add pam_selinux.so to login configs so users will have the correct SELinux
context on their session.

Signed-off-by: Chris PeBenito <Christopher.PeBenito@microsoft.com>
2021-09-16 18:46:13 +00:00
Thomas Crain 0b47438614
Use pam_pwquality in system-password PAM config (#1392) 2021-09-13 14:10:47 -07:00
Jon Slobodzian b877013b27 Initial CBL-Mariner commit to GitHub 2020-08-06 20:17:52 -07:00