[RFC cip-dev][isar-cip-core][PATCH 13/14] Add Kconfig option to select cis-validation
Quirin Gylstorff <[email protected]> Mon, 27 Jul 2026 15:13:07 +0200
| Newsgroups | org.cip-project.lists.cip-dev |
|---|---|
| Message-ID | <[email protected]> |
This is for testing the cis-validation. The following rules are failing as the prerequisites are intentionally not installed: 1.3.1 install sudo 3.5.1.1 enable firewall 3.5.4.1.1 net_fw_default_policy_drop 5.3.1 enable pwquality Signed-off-by: Quirin Gylstorff <[email protected]> --- Kconfig | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/Kconfig b/Kconfig index 438234c..6790dab 100644 --- a/Kconfig +++ b/Kconfig @@ -364,6 +364,12 @@ config FACTORY_RESET This adds the necessary packages to request and execute a factory reset of the persistent partition. See also ./doc/README.factory-reset.= md. =20 +config CIS_HARDENING + bool "Harden image according CIS rules" + depends on DEBIAN_TRIXIE + help + This hardens the image according the CIS Debian Linux Benchmarks + config KAS_INCLUDE_DATA_ENCRYPTION string default "kas/opt/encrypt-data.yml" if IMAGE_DATA_ENCRYPTION @@ -380,6 +386,10 @@ config KAS_INCLUDE_FACTORY_RESET string default "kas/opt/factory-reset.yml" if FACTORY_RESET =20 +config KAS_INCLUDE_CIS_HARDENING + string + default "kas/opt/cis-validation.yml" if CIS_HARDENING + config WDOG_TIMEOUT int "EFI Boot Guard watchdog timeout in seconds" default 60 --=20 2.53.0