Skip to main content
🎤 Luca Berton is speaking at Red Hat Summit & KubeCon EU 2026!Learn more →
  • Instant download
  • Lifetime updates
  • Secure Stripe checkout
  • EU VAT invoice
Ebook
CopyPasteLearn

RHEL 9 CIS Hardening Playbook

Production-ready Ansible automation to bring RHEL 9 fleets into CIS Level 1 or Level 2 compliance — the field manual we use to ship 500 hardened hosts before the next audit window. Idempotent, reversi

Loved by DevOps practitioners
One-time purchase
€49.00EUR
Tax shown at checkout · No subscription
  • Production-tested examples you can copy-paste today
  • PDF format, optimized for screen and print
  • Free updates whenever the source CLI changes
  • Search-friendly, code-block heavy, no fluff

About this ebook

Production-ready Ansible automation to bring RHEL 9 fleets into CIS Level 1 or Level 2 compliance — the field manual we use to ship 500 hardened hosts before the next audit window. Idempotent, reversible, fully tagged.

What's inside:

• All six CIS RHEL 9 benchmark sections: filesystems, services, network, auditing, access (SSH/PAM/users), and file/group permissions.

• Copy-paste Ansible task blocks with correct `when:` guards, tags, and handler notifications - drop them into your role today.

• Per-rule and per-section toggles (`rhel9cis_rule_X_Y_Z`) so you deploy one control or the whole benchmark.

• SSH hardening template (sshd_config) with modern ciphers, MACs, KexAlgorithms tested against RHEL 9 OpenSSH defaults.

• PAM, pwquality.conf, and faillock.conf hardened to CIS Level 2 with `even_deny_root` + 24-cycle pwhistory.

• SELinux chapter: enforcing targeted policy, booleans, custom seport/sefcontext labels, SETroubleshoot + audit2allow workflow.

• Crypto policies and FIPS mode walkthrough (DEFAULT, FUTURE, DEFAULT:NO-SHA1, fips-mode-setup).

• AIDE baseline + nightly systemd timer + S3 off-host shipping.

• OpenSCAP pre and post-remediation scan workflow with ssg-rhel9-ds.xml, ARF + HTML report capture.

• Deviations register (YAML) doubling as audit evidence; every disabled rule tracked with reason, approver, review date.

• Molecule scenarios (Podman + EC2 drivers), GitHub Actions pipeline (lint -> molecule -> staging -> canary -> fleet).

• Drift detection via daily systemd-timer scans uploaded to S3 with 13-month retention.

• Common pitfalls quick reference: Docker breaks after IP forwarding off, SSH lockout from cipher whitelist, AIDE noise after first run, faillock locking root, and seven more.

Mapped to the Ansible Lockdown RHEL9-CIS role and the CIS Red Hat Enterprise Linux 9 Benchmark v1.0.0. Tested against RHEL 9, AlmaLinux 9, and Rocky Linux 9. Lifetime updates while the benchmark is maintained, delivered via /library.

Before you buy

  • Instant digital delivery — by completing checkout you consent to immediate access. See the digital delivery policy.
  • Refunds available within 14 days if you have not yet downloaded the file. Full terms in the refund policy.
  • Your purchase email becomes your library sign-in. Tax is calculated and shown on the next step.