diff --git a/tasks/limits.yml b/tasks/limits.yml index fb1a733c3..ed7878027 100644 --- a/tasks/limits.yml +++ b/tasks/limits.yml @@ -31,12 +31,4 @@ file: path: /etc/security/limits.d/10.hardcore.conf state: absent - -- name: create sane limits.conf | sysctl-31a, sysctl-31b - template: - src: 'etc/security/limits.d/limits.conf.j2' - dest: '/etc/security/limits.d/10.hardcore.conf' - owner: 'root' - group: 'root' - mode: '0440' when: 'os_security_kernel_enable_core_dump' diff --git a/templates/etc/security/limits.d/limits.conf.j2 b/templates/etc/security/limits.d/limits.conf.j2 deleted file mode 100644 index 2a55592db..000000000 --- a/templates/etc/security/limits.d/limits.conf.j2 +++ /dev/null @@ -1,3 +0,0 @@ -# {{ ansible_managed | comment }} -# Prevent core dumps for all users. These are usually only needed by developers and may contain sensitive information. -* hard core 0 diff --git a/tests/test.yml b/tests/test.yml index dd3d7b30c..dfcad0729 100644 --- a/tests/test.yml +++ b/tests/test.yml @@ -12,7 +12,7 @@ shell: "rm -f /usr/bin/zzz && ln -s /usr/bin /usr/bin/zzz" vars: os_security_users_allow: change_user - os_security_kernel_enable_core_dump: false + os_security_kernel_enable_core_dump: true os_security_suid_sgid_remove_from_unknown: true os_auth_pam_passwdqc_enable: false os_desktop_enable: true