Add parameter to suppress the '--config /etc/aide.conf' argument in the cron job. #14
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
I'm working with 3rd party vendors doing CIS and security checking. The current CRON job:
0 0 * * * root nice ionice -c3 /usr/sbin/aide --config /etc/aide.conf --check
fails the regex tests that the vendors do for AIDE due to '--config /etc/aide.conf' being specified. I figure it's easier to update this module than to convince the vendors to update their regular expressions.
The regex used by CIS/STIG is:
pattern:
^\s*([^#]+\s+)?\/usr\/sbin\/aide\s(--?\S+\s)*--(check|update)\b.*$I propose an option to exclude the '--config /etc/aide' part of the CRON job and just let aide use its default of /etc/aide.conf.