Skip to content

Latest commit

 

History

History
89 lines (62 loc) · 1.66 KB

README.md

File metadata and controls

89 lines (62 loc) · 1.66 KB

Lynis Cookbook

This cookbook installs Lynis and can also execute the security audit report if instructed.

What is Lynis?

Lynis is a software component to audit Unix based systems. Lynis Enterprise uses Lynis to gather data from machines. Additionally it has an administration interface, reporting, implementation plans, hardening guidance and more. For more details, refer to - https://cisofy.com/lynis-enterprise/

Requirements

Depends on cookbooks

  • apt
  • apt-transport-https

Platforms

  • Tested on ubuntu-16.04 only

Chef

  • Chef 12.0 or later

Attributes

None

Usage

Lynis::default

This would install lynis and execute the audit report

e.g. Just include Lynis in your node's run_list:

{
  "name":"my_node",
  "run_list": [
    "recipe[Lynis]"
  ]
}

Lynis::install

This would install lynis only

e.g. Just include Lynis::install in your node's run_list:

{
  "name":"my_node",
  "run_list": [
    "recipe[Lynis::install]"
  ]
}

Lynis::audit

This would execute the security audit report. It would also check if the lynis package is installed. The report is generated by default under /var/log/. The 2 report files are -

  • lynis.log
  • lynis-report.dat

e.g. Just include Lynis::audit in your node's run_list:

{
  "name":"my_node",
  "run_list": [
    "recipe[Lynis::audit]"
  ]
}

Contributing

  1. Create a branch of the repository on Bitbucket
  2. Create a named feature branch (like add_component_x)
  3. Write your change
  4. Write tests for your change (if applicable)
  5. Run the tests, ensuring they all pass
  6. Submit a Pull Request using Bitbucket

License and Authors

Authors: Mrinal Mukherjee