/srv/irclogs.ubuntu.com/2021/07/14/#ubuntu-security.txt

polarpinguinansible-hardening for Ubuntu 20.04 help?  Best path to script?18:26
polarpinguinDISA STIG specific18:26
sarnoldpolarpinguin: seen this? https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux18:28
polarpinguinYes I have the STIG but trying to automate the STIG tasks to systems.18:29
polarpinguinwas looking at https://github.com/openstack/ansible-hardening18:30
polarpinguinanybody used this?18:31
polarpinguinfor 20.04?18:31
cipherboypolarpinguin: \o greetings :)18:46
cipherboypolarpinguin: We're actively working on STIG automation; it'll be a paid offering similar to our present CIS offering (see https://security-certs.docs.ubuntu.com/en/cis and https://ubuntu.com/security/certifications).18:47
cipherboypolarpinguin: That said, we're basing our STIG automation around the github.com/ComplianceAsCode/content project and are actively contributing there (see for instance, https://github.com/ComplianceAsCode/content/pull/7220). 18:48
ubottuPull 7220 in ComplianceAsCode/content "Add initial Ubuntu 20.04 STIG Profile" [Open]18:48
cipherboypolarpinguin: This is an upstream, community effort and not everything that ends up in our paid offering will land upstream... but you're more than welcome to contribute there if the (future) paid offering isn't of interest to you. The CaC project mostly hang out on #openscap here on Libera.18:49
polarpinguincipherboy: Thank you very much for the info18:54
cipherboypolarpinguin: I guess I should also say that Red Hat has contributed a lot of Ansible tooling to CaC but Canonical mostly focuses on Bash... so Ansible+Ubuntu content will certainly be welcomed by the upstream community. 18:58

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!