diff --git a/files/ansible-hardening-disable-dccp.conf b/files/ansible-hardening-disable-dccp.conf new file mode 100644 index 00000000..341c5f7e --- /dev/null +++ b/files/ansible-hardening-disable-dccp.conf @@ -0,0 +1,2 @@ +install dccp /bin/true +install dccp_diag /bin/true \ No newline at end of file diff --git a/tasks/rhel7stig/kernel.yml b/tasks/rhel7stig/kernel.yml index 23e0c814..512d4eb8 100644 --- a/tasks/rhel7stig/kernel.yml +++ b/tasks/rhel7stig/kernel.yml @@ -98,10 +98,9 @@ - V-72067 - name: V-77821 - Datagram Congestion Control Protocol (DCCP) kernel module must be disabled - lineinfile: + copy: + src: ansible-hardening-disable-dccp.conf dest: /etc/modprobe.d/ansible-hardening-disable-dccp.conf - line: install dccp /bin/true - create: yes when: - security_rhel7_disable_dccp | bool tags: