{"repo":"dev-sec/chef-os-hardening","free":true,"listed":false,"github":"https://github.com/dev-sec/chef-os-hardening","clone":"git clone https://github.com/dev-sec/chef-os-hardening.git","description":"This chef cookbook provides numerous security-related configurations, providing all-round base protection.","language":"Ruby","stars":452,"topics":["hardening","devops","linux","security","chef","chef-cookbook"],"license":"Apache-2.0","category":"security-tools","readme_excerpt":"os-hardening (Chef cookbook) [ ][1] [ ][2] Description This cookbook provides numerous security-related configurations, providing all-round base protection. It configures: Configures package management e.g. allows only signed packages Remove packages with known issues Configures pam and pam limits module Shadow password suite configuration Configures system path permissions Disable core dumps via soft limits Restrict Root Logins to System Console Set SUIDs Configures kernel parameters via sysctl It will not: Update system packages Install security patches Requirements Chef = 14.13.11 Platform - Ubuntu 20.04, 22.04, 24.04, 26.04 - CentOS Stream 9, 10 - AlmaLinux 8, 9, 10 - Rocky Linux 8, 9, 10 - Oracle Linux 8, 9, 10 - Debian 13 - Fedora 43, 44 Attributes ['os-hardening']['components'][COMPONENT NAME] - allows the fine control over which components should be executed via default recipe. See below for more details ['os-hardening']['desktop']['enable'] = false true if this is a desktop system, ie Xorg, KDE/GNOME/Unity/etc ['os-hardening']['network']['forwarding'] = false true if this system requires packet forwarding (eg Router), false otherwise ['os-hardening']['network']['ipv6']['enable'] = false ['os-hardening']['network']['arp']['restricted'] = true true if you want the behavior of announcing and replying to ARP to be restricted, false otherwise ['os-hardening']['env']['extra user paths'] = [] add additional paths to the user's PATH variable (default is empty). ['os-hardenin","default_branch":null,"files":null,"tree":[],"storefront":"/r/dev-sec","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/dev-sec/chef-os-hardening/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}