Drop firewalld default zone and sshd port fixes #2328
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
The proper fix for #2202 is to have a remediation for
firewalld_sshd_port_enabledwhich set ups a firewalld zone with SSH and an interface assigned to it.But providing a good fix for
firewalld_sshd_port_enabledcan be very complicatedand will very likely not fit to everyone's use case. And because of that
we will drop remediation for
set_firewalld_default_zone, which is causing theremediated machine to lock down and refuse all connections.
Existent test cases for 'firewalld_sshd_port_enabled' are kept because they are still useful to test the OVAL definition.