aboutsummaryrefslogtreecommitdiffstats
path: root/conf/level.fileserver
diff options
context:
space:
mode:
authorEugeni Dodonov <eugeni@mandriva.org>2010-02-18 18:17:04 +0000
committerEugeni Dodonov <eugeni@mandriva.org>2010-02-18 18:17:04 +0000
commit0b879f1ccd0d3da358ba5cceeddc6bc1101d683f (patch)
tree8ba8b43c1784f8d0b85949fb0a00014b3d448c03 /conf/level.fileserver
parent14d32c3ad700d1e57f8d8e99a5680a29b1990977 (diff)
downloadmsec-0b879f1ccd0d3da358ba5cceeddc6bc1101d683f.tar
msec-0b879f1ccd0d3da358ba5cceeddc6bc1101d683f.tar.gz
msec-0b879f1ccd0d3da358ba5cceeddc6bc1101d683f.tar.bz2
msec-0b879f1ccd0d3da358ba5cceeddc6bc1101d683f.tar.xz
msec-0b879f1ccd0d3da358ba5cceeddc6bc1101d683f.zip
Added policy for 'fileserver' security level.
Diffstat (limited to 'conf/level.fileserver')
-rw-r--r--conf/level.fileserver67
1 files changed, 67 insertions, 0 deletions
diff --git a/conf/level.fileserver b/conf/level.fileserver
new file mode 100644
index 0000000..2ed7f74
--- /dev/null
+++ b/conf/level.fileserver
@@ -0,0 +1,67 @@
+BASE_LEVEL=fileserver
+ALLOW_X_CONNECTIONS=no
+CHECK_WRITABLE=weekly
+ENABLE_IP_SPOOFING_PROTECTION=yes
+MAIL_EMPTY_CONTENT=no
+ACCEPT_BROADCASTED_ICMP_ECHO=yes
+CHECK_PERMS=daily
+CHECK_PERMS_ENFORCE=yes
+CHECK_SECTOOL=weekly
+CHECK_SECTOOL_LEVEL=3
+CHECK_USER_FILES=daily
+ENABLE_SUDO=wheel
+ALLOW_XSERVER_TO_LISTEN=no
+CHECK_CHKROOTKIT=weekly
+SHELL_HISTORY_SIZE=-1
+ALLOW_REBOOT=yes
+CHECK_SUID_ROOT=weekly
+SYSLOG_WARN=yes
+ENABLE_AT_CRONTAB=yes
+ACCEPT_BOGUS_ERROR_RESPONSES=no
+CHECK_PASSWD=daily
+PASSWORD_HISTORY=0
+CHECK_SUID_MD5=weekly
+CHECK_SHOSTS=daily
+MAIL_USER=root
+ALLOW_AUTOLOGIN=no
+ENABLE_PAM_WHEEL_FOR_SU=no
+CHECK_SHADOW=daily
+ALLOW_ROOT_LOGIN=yes
+CHECK_UNOWNED=weekly
+FIX_UNOWNED=yes
+CHECK_USERS=daily
+CHECK_GROUPS=daily
+ENABLE_CONSOLE_LOG=yes
+ALLOW_USER_LIST=yes
+ENABLE_DNS_SPOOFING_PROTECTION=yes
+CREATE_SERVER_LINK=remote
+ENABLE_PASSWORD=yes
+NOTIFY_WARN=no
+WIN_PARTS_UMASK=000
+CHECK_OPEN_PORT=daily
+CHECK_FIREWALL=daily
+SHELL_TIMEOUT=0
+ALLOW_REMOTE_ROOT_LOGIN=without-password
+ENABLE_LOG_STRANGE_PACKETS=yes
+USER_UMASK=022
+CHECK_RPM_PACKAGES=weekly
+CHECK_RPM_INTEGRITY=monthly
+SECURE_TMP=yes
+ENABLE_SULOGIN=yes
+ENABLE_PAM_ROOT_FROM_WHEEL=no
+MAIL_WARN=yes
+ALLOW_XAUTH_FROM_ROOT=no
+CHECK_SECURITY=yes
+ACCEPT_ICMP_ECHO=yes
+PASSWORD_LENGTH=6,0,0
+AUTHORIZE_SERVICES=yes
+ROOT_UMASK=022
+ENABLE_MSEC_CRON=yes
+TTY_WARN=no
+CHECK_SGID=weekly
+CHECK_PROMISC=daily
+ENABLE_STARTUP_MSEC=yes
+ENABLE_STARTUP_PERMS=yes
+ALLOW_CURDIR_IN_PATH=no
+CHECK_ON_BATTERY=no
+LOG_RETENTION=24