blob: f84b56f33118150c3d673c0380ecb69f2e1ba230 [file] [log] [blame]
Dmitry Teselkinee7b8112018-08-22 12:46:08 +03001# 1.1.1.2 Ensure mounting of freevxfs filesystems is disabled
2#
3# Description
4# ===========
5# The freevxfs filesystem type is a free version of the Veritas type
6# filesystem. This is the primary filesystem type for HP-UX operating systems.
7#
8# Rationale
9# =========
10# Removing support for unneeded filesystem types reduces the local attack
11# surface of the system. If this filesystem type is not needed, disable it.
12#
13# Audit
14# =====
15# Run the following commands and verify the output is as indicated:
16#
17# # modprobe -n -v freevxfs
18# install /bin/true
19# # lsmod | grep freevxfs
20# <No output>
21#
22# Remediation
23# ===========
24# Edit or create the file /etc/modprobe.d/CIS.conf and add the following line:
25#
26# install freevxfs /bin/true
27#
28parameters:
29 linux:
30 system:
31 kernel:
32 module:
33 freevxfs:
34 install:
35 command: /bin/true
36