RHEL 9 CIS Hardening Playbook
- Instant download
- Lifetime updates
- Secure Stripe checkout
- EU VAT invoice
RHEL 9 CIS Hardening Playbook
Production-ready Ansible automation to bring RHEL 9 fleets into CIS Level 1 or Level 2 compliance — the field manual we use to ship 500 hardened hosts before the next audit window. Idempotent, reversi
- Production-tested examples you can copy-paste today
- PDF format, optimized for screen and print
- Free updates whenever the source CLI changes
- Search-friendly, code-block heavy, no fluff
About this ebook
Production-ready Ansible automation to bring RHEL 9 fleets into CIS Level 1 or Level 2 compliance — the field manual we use to ship 500 hardened hosts before the next audit window. Idempotent, reversible, fully tagged.
What's inside:
• All six CIS RHEL 9 benchmark sections: filesystems, services, network, auditing, access (SSH/PAM/users), and file/group permissions.
• Copy-paste Ansible task blocks with correct `when:` guards, tags, and handler notifications - drop them into your role today.
• Per-rule and per-section toggles (`rhel9cis_rule_X_Y_Z`) so you deploy one control or the whole benchmark.
• SSH hardening template (sshd_config) with modern ciphers, MACs, KexAlgorithms tested against RHEL 9 OpenSSH defaults.
• PAM, pwquality.conf, and faillock.conf hardened to CIS Level 2 with `even_deny_root` + 24-cycle pwhistory.
• SELinux chapter: enforcing targeted policy, booleans, custom seport/sefcontext labels, SETroubleshoot + audit2allow workflow.
• Crypto policies and FIPS mode walkthrough (DEFAULT, FUTURE, DEFAULT:NO-SHA1, fips-mode-setup).
• AIDE baseline + nightly systemd timer + S3 off-host shipping.
• OpenSCAP pre and post-remediation scan workflow with ssg-rhel9-ds.xml, ARF + HTML report capture.
• Deviations register (YAML) doubling as audit evidence; every disabled rule tracked with reason, approver, review date.
• Molecule scenarios (Podman + EC2 drivers), GitHub Actions pipeline (lint -> molecule -> staging -> canary -> fleet).
• Drift detection via daily systemd-timer scans uploaded to S3 with 13-month retention.
• Common pitfalls quick reference: Docker breaks after IP forwarding off, SSH lockout from cipher whitelist, AIDE noise after first run, faillock locking root, and seven more.
Mapped to the Ansible Lockdown RHEL9-CIS role and the CIS Red Hat Enterprise Linux 9 Benchmark v1.0.0. Tested against RHEL 9, AlmaLinux 9, and Rocky Linux 9. Lifetime updates while the benchmark is maintained, delivered via /library.
Before you buy
- Instant digital delivery — by completing checkout you consent to immediate access. See the digital delivery policy.
- Refunds available within 14 days if you have not yet downloaded the file. Full terms in the refund policy.
- Your purchase email becomes your library sign-in. Tax is calculated and shown on the next step.