diff --git a/tasks/section5.yml b/tasks/section5.yml index e4868511..e89a0ee9 100644 --- a/tasks/section5.yml +++ b/tasks/section5.yml @@ -435,7 +435,11 @@ - rule_5.5 - name: "SCORED | 5.6 | PATCH | Ensure access to the su command is restricted" - command: /bin/true + lineinfile: + state: present + dest: /etc/pam.d/su + regexp: '^#auth\s+required\s+pam_wheel\.so' + line: 'auth required pam_wheel.so use_uid' tags: - level1 - level2