Ideas for automatic or manual tests:

  • Test presence of critical items in smb.conf:
    • prexec/postexec commands
  • Test presence of critical users and groups in /etc/passwd and /etc/group:
    • ens
    • All user categories
  • Test presence of critical rules in iptables (both tables), and absence of SuSE rules

Other things:

  • Make files in /etc/lll/security and /etc/squid config/noreplace, or otherwise guarantee that they won't be overwritten.