Skip to content

Commit e829dfb

Browse files
arlimusDominik Richter
authored andcommitted
bugfix: add missing: ipv6 accept_ra = 0
This was uncovered by @igoraj at dev-sec/puppet-os-hardening#56 .
1 parent d53f3e2 commit e829dfb

1 file changed

Lines changed: 8 additions & 0 deletions

File tree

default/serverspec/sysctl_spec.rb

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -167,6 +167,14 @@
167167
its(:value) { should eq 0 }
168168
end
169169

170+
context linux_kernel_parameter('net.ipv6.conf.all.accept_ra') do
171+
its(:value) { should eq 0 }
172+
end
173+
174+
context linux_kernel_parameter('net.ipv6.conf.default.accept_ra') do
175+
its(:value) { should eq 0 }
176+
end
177+
170178
context linux_kernel_parameter('net.ipv6.conf.default.autoconf') do
171179
its(:value) { should eq 0 }
172180
end

0 commit comments

Comments
 (0)