Puppet Class: security_baseline::rules::common::sec_jffs2
- Defined in:
- manifests/rules/common/sec_jffs2.pp
Summary
Ensure mounting of jffs2 filesystems is disabled (Scored)Overview
The jffs2 (journaling flash filesystem 2) filesystem type is a log-structured filesystem used in flash memory devices.
Rationale: Removing support for unneeded filesystem types reduces the local attack surface of the system. If this filesystem type is not needed, disable it.
28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 |
# File 'manifests/rules/common/sec_jffs2.pp', line 28
class security_baseline::rules::common::sec_jffs2 (
Boolean $enforce = true,
String $message = '',
String $log_level = ''
) {
if $enforce {
kmod::install { 'jffs2':
command => '/bin/true',
}
} else {
if($facts['security_baseline']['kernel_modules']['jffs2']) {
echo { 'jffs2':
message => $message,
loglevel => $log_level,
withpath => false,
}
}
}
}
|