From 839a1363931126f3bdf11708eaad63e2d9da67de5dad802cf968e5e82dd8129e Mon Sep 17 00:00:00 2001 From: Heath Petersen Date: Sat, 25 Jul 2026 11:00:19 -0500 Subject: [PATCH] update sshd configuration --- bootstrap.yml | 40 ++++++++++++++++++++++++++++ files/etc/ssh/sshd_config.d/hpf.conf | 3 +++ scraps/TODO.txt | 35 +++++++++++++----------- 3 files changed, 62 insertions(+), 16 deletions(-) create mode 100644 files/etc/ssh/sshd_config.d/hpf.conf diff --git a/bootstrap.yml b/bootstrap.yml index 3a59c64..dbd0023 100644 --- a/bootstrap.yml +++ b/bootstrap.yml @@ -79,6 +79,29 @@ backup: true validate: /usr/sbin/visudo -csf %s +## New + - name: Make sure /etc/ssh/sshd_config.d exists + become: true + ansible.builtin.file: + path: /etc/ssh/sshd_config.d + state: directory + owner: root + group: root + mode: u=rwx,go=rx + +## New + - name: Get /etc/ssh/sshd_config.d/hpf.conf + become: true + ansible.builtin.copy: + src: etc/ssh/sshd_config.d/hpf.conf + dest: /etc/ssh/sshd_config.d/hpf.conf + owner: root + group: root + mode: u=rwx,go=rx + backup: yes + validate: /usr/sbin/sshd -t -f %s + notify: Restart sshd + - name: Make sure /etc/skel/.profile.d exists become: true ansible.builtin.file: @@ -175,6 +198,16 @@ group: root mode: u=rwx,go= + - name: Remove packages installed as dependencies that are no longer required and purge their configuration files + ansible.builtin.apt: + autoremove: yes + purge: true + + - name: Remove old downloaded packages + ansible.builtin.apt: + clean: yes + + # - name: Create ansible-pull.sh crontab entry # become: true # ansible.builtin.cron: @@ -182,3 +215,10 @@ # minute: "*/27" # job: $HOME/bin/ansible-pull.sh # backup: true + + handlers: + + - name: Restart sshd + ansible.builtin.service: + name: sshd + state: restarted diff --git a/files/etc/ssh/sshd_config.d/hpf.conf b/files/etc/ssh/sshd_config.d/hpf.conf new file mode 100644 index 0000000..9e00717 --- /dev/null +++ b/files/etc/ssh/sshd_config.d/hpf.conf @@ -0,0 +1,3 @@ + PermitRootLogin proibit_password # Key based root login required for some software like Proxmox + PasswordAuthentication no + PermitEmptyPasswords no \ No newline at end of file diff --git a/scraps/TODO.txt b/scraps/TODO.txt index 88cd295..2ade85a 100644 --- a/scraps/TODO.txt +++ b/scraps/TODO.txt @@ -1,3 +1,22 @@ +* root + * authorized_keys = heath +* hpf-ans + * system user + * /usr/bin/bash + * member of hpf-sudo-ntp + * authorized_keys = hpf-ans +* first + * normal user + * /usr/bin/bash + * member of hpf-sudo + * authorized_keys = heath, first +* heath + * normal user + * /usr/bin/bash + * member of hpf-sudo + * authorized_keys = heath + + @@ -61,21 +80,6 @@ # use: systemd -- name: Copy a new sudoers file into place, after passing validation with visudo - ansible.builtin.template: - src: /mine/sudoers - dest: /etc/sudoers - validate: /usr/sbin/visudo -cf %s - -- name: Update sshd configuration safely, avoid locking yourself out - ansible.builtin.template: - src: etc/ssh/sshd_config.j2 - dest: /etc/ssh/sshd_config - owner: root - group: root - mode: '0600' - validate: /usr/sbin/sshd -t -f %s - backup: yes proxmox-clients @@ -85,7 +89,6 @@ hw: pve-kvm: -users: first, heath, hpf-ans ~heath/.ssh/heath ## WARNING - SeCrEt! - Make sure this is not in the repo! - Does this need to be on every machine? ~heath/.ssh/authorized_keys