CIS Benchmark Fail - /tmp, /var, /var/tmp, /var/log/, /var/log/audit and /home Parition Configuration

Septim

New Member
Aug 24, 2021
13
0
1
34
Greetings. I have found that Proxmox VE does not pass the following CIS Benchmarks related to the /tmp location:

2507 - Ensure /tmp is configured
2508 - Ensure nodev option set on /tmp partition
2509 - Ensure nosuid option set on /tmp partition
2510 - Ensure noexec option set on /tmp partition
2511 - Ensure separate partition exists for /var
2512 - Ensure separate partition exists for /var/tmp
2513 - Ensure nodev option set on /var/tmp partition
2514 - Ensure nosuid option set on /var/tmp partition
2515 - Ensure noexec option set on /var/tmp partition
2516 - Ensure separate partition exists for /var/log
2517 - Ensure separate partition exists for /var/log/audit
2518 - Ensure separate partition exists for /home
2519 - Ensure nodev option set on /home partition

Is the mounting of the /tmp, /var, /var/tmp, /var/log/, /var/log/audit and /home directories as separate partitions impossible while maintaining the correct functioning of PVE? Could the previous options be set on these partitions without affecting the working of the system?

Thank you in advance!
 
Last edited:

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!