update sshd configuration
This commit is contained in:
@@ -79,6 +79,29 @@
|
|||||||
backup: true
|
backup: true
|
||||||
validate: /usr/sbin/visudo -csf %s
|
validate: /usr/sbin/visudo -csf %s
|
||||||
|
|
||||||
|
## New
|
||||||
|
- name: Make sure /etc/ssh/sshd_config.d exists
|
||||||
|
become: true
|
||||||
|
ansible.builtin.file:
|
||||||
|
path: /etc/ssh/sshd_config.d
|
||||||
|
state: directory
|
||||||
|
owner: root
|
||||||
|
group: root
|
||||||
|
mode: u=rwx,go=rx
|
||||||
|
|
||||||
|
## New
|
||||||
|
- name: Get /etc/ssh/sshd_config.d/hpf.conf
|
||||||
|
become: true
|
||||||
|
ansible.builtin.copy:
|
||||||
|
src: etc/ssh/sshd_config.d/hpf.conf
|
||||||
|
dest: /etc/ssh/sshd_config.d/hpf.conf
|
||||||
|
owner: root
|
||||||
|
group: root
|
||||||
|
mode: u=rwx,go=rx
|
||||||
|
backup: yes
|
||||||
|
validate: /usr/sbin/sshd -t -f %s
|
||||||
|
notify: Restart sshd
|
||||||
|
|
||||||
- name: Make sure /etc/skel/.profile.d exists
|
- name: Make sure /etc/skel/.profile.d exists
|
||||||
become: true
|
become: true
|
||||||
ansible.builtin.file:
|
ansible.builtin.file:
|
||||||
@@ -175,6 +198,16 @@
|
|||||||
group: root
|
group: root
|
||||||
mode: u=rwx,go=
|
mode: u=rwx,go=
|
||||||
|
|
||||||
|
- name: Remove packages installed as dependencies that are no longer required and purge their configuration files
|
||||||
|
ansible.builtin.apt:
|
||||||
|
autoremove: yes
|
||||||
|
purge: true
|
||||||
|
|
||||||
|
- name: Remove old downloaded packages
|
||||||
|
ansible.builtin.apt:
|
||||||
|
clean: yes
|
||||||
|
|
||||||
|
|
||||||
# - name: Create ansible-pull.sh crontab entry
|
# - name: Create ansible-pull.sh crontab entry
|
||||||
# become: true
|
# become: true
|
||||||
# ansible.builtin.cron:
|
# ansible.builtin.cron:
|
||||||
@@ -182,3 +215,10 @@
|
|||||||
# minute: "*/27"
|
# minute: "*/27"
|
||||||
# job: $HOME/bin/ansible-pull.sh
|
# job: $HOME/bin/ansible-pull.sh
|
||||||
# backup: true
|
# backup: true
|
||||||
|
|
||||||
|
handlers:
|
||||||
|
|
||||||
|
- name: Restart sshd
|
||||||
|
ansible.builtin.service:
|
||||||
|
name: sshd
|
||||||
|
state: restarted
|
||||||
|
|||||||
@@ -0,0 +1,3 @@
|
|||||||
|
PermitRootLogin proibit_password # Key based root login required for some software like Proxmox
|
||||||
|
PasswordAuthentication no
|
||||||
|
PermitEmptyPasswords no
|
||||||
+19
-16
@@ -1,3 +1,22 @@
|
|||||||
|
* root
|
||||||
|
* authorized_keys = heath
|
||||||
|
* hpf-ans
|
||||||
|
* system user
|
||||||
|
* /usr/bin/bash
|
||||||
|
* member of hpf-sudo-ntp
|
||||||
|
* authorized_keys = hpf-ans
|
||||||
|
* first
|
||||||
|
* normal user
|
||||||
|
* /usr/bin/bash
|
||||||
|
* member of hpf-sudo
|
||||||
|
* authorized_keys = heath, first
|
||||||
|
* heath
|
||||||
|
* normal user
|
||||||
|
* /usr/bin/bash
|
||||||
|
* member of hpf-sudo
|
||||||
|
* authorized_keys = heath
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
@@ -61,21 +80,6 @@
|
|||||||
# use: systemd
|
# use: systemd
|
||||||
|
|
||||||
|
|
||||||
- name: Copy a new sudoers file into place, after passing validation with visudo
|
|
||||||
ansible.builtin.template:
|
|
||||||
src: /mine/sudoers
|
|
||||||
dest: /etc/sudoers
|
|
||||||
validate: /usr/sbin/visudo -cf %s
|
|
||||||
|
|
||||||
- name: Update sshd configuration safely, avoid locking yourself out
|
|
||||||
ansible.builtin.template:
|
|
||||||
src: etc/ssh/sshd_config.j2
|
|
||||||
dest: /etc/ssh/sshd_config
|
|
||||||
owner: root
|
|
||||||
group: root
|
|
||||||
mode: '0600'
|
|
||||||
validate: /usr/sbin/sshd -t -f %s
|
|
||||||
backup: yes
|
|
||||||
|
|
||||||
|
|
||||||
proxmox-clients
|
proxmox-clients
|
||||||
@@ -85,7 +89,6 @@ hw:
|
|||||||
pve-kvm:
|
pve-kvm:
|
||||||
|
|
||||||
|
|
||||||
users: first, heath, hpf-ans
|
|
||||||
|
|
||||||
~heath/.ssh/heath ## WARNING - SeCrEt! - Make sure this is not in the repo! - Does this need to be on every machine?
|
~heath/.ssh/heath ## WARNING - SeCrEt! - Make sure this is not in the repo! - Does this need to be on every machine?
|
||||||
~heath/.ssh/authorized_keys
|
~heath/.ssh/authorized_keys
|
||||||
|
|||||||
Reference in New Issue
Block a user