Used primarily to STIG a plain ubuntu 18.04 unstallation, which can then be packaged into a base image for later use.
Right now the provisioning / STIG'ing process is imperfect and requires some manual configuration.
- gl_tech
- bm_tech
- so_tech
- ia_scanner
apt-get install auditd audispd-plugins aide apparmor-utils
ansible-playbook -i stig.inventory -l aws.new-bastion.dvidshub.net stig-ubuntu-16-04.yml
ufw limit 22/tcp ufw enable
aa-logprof