update sshd configuration
This commit is contained in:
@@ -79,6 +79,29 @@
|
||||
backup: true
|
||||
validate: /usr/sbin/visudo -csf %s
|
||||
|
||||
## New
|
||||
- name: Make sure /etc/ssh/sshd_config.d exists
|
||||
become: true
|
||||
ansible.builtin.file:
|
||||
path: /etc/ssh/sshd_config.d
|
||||
state: directory
|
||||
owner: root
|
||||
group: root
|
||||
mode: u=rwx,go=rx
|
||||
|
||||
## New
|
||||
- name: Get /etc/ssh/sshd_config.d/hpf.conf
|
||||
become: true
|
||||
ansible.builtin.copy:
|
||||
src: etc/ssh/sshd_config.d/hpf.conf
|
||||
dest: /etc/ssh/sshd_config.d/hpf.conf
|
||||
owner: root
|
||||
group: root
|
||||
mode: u=rwx,go=rx
|
||||
backup: yes
|
||||
validate: /usr/sbin/sshd -t -f %s
|
||||
notify: Restart sshd
|
||||
|
||||
- name: Make sure /etc/skel/.profile.d exists
|
||||
become: true
|
||||
ansible.builtin.file:
|
||||
@@ -175,6 +198,16 @@
|
||||
group: root
|
||||
mode: u=rwx,go=
|
||||
|
||||
- name: Remove packages installed as dependencies that are no longer required and purge their configuration files
|
||||
ansible.builtin.apt:
|
||||
autoremove: yes
|
||||
purge: true
|
||||
|
||||
- name: Remove old downloaded packages
|
||||
ansible.builtin.apt:
|
||||
clean: yes
|
||||
|
||||
|
||||
# - name: Create ansible-pull.sh crontab entry
|
||||
# become: true
|
||||
# ansible.builtin.cron:
|
||||
@@ -182,3 +215,10 @@
|
||||
# minute: "*/27"
|
||||
# job: $HOME/bin/ansible-pull.sh
|
||||
# backup: true
|
||||
|
||||
handlers:
|
||||
|
||||
- name: Restart sshd
|
||||
ansible.builtin.service:
|
||||
name: sshd
|
||||
state: restarted
|
||||
|
||||
@@ -0,0 +1,3 @@
|
||||
PermitRootLogin proibit_password # Key based root login required for some software like Proxmox
|
||||
PasswordAuthentication no
|
||||
PermitEmptyPasswords no
|
||||
+19
-16
@@ -1,3 +1,22 @@
|
||||
* root
|
||||
* authorized_keys = heath
|
||||
* hpf-ans
|
||||
* system user
|
||||
* /usr/bin/bash
|
||||
* member of hpf-sudo-ntp
|
||||
* authorized_keys = hpf-ans
|
||||
* first
|
||||
* normal user
|
||||
* /usr/bin/bash
|
||||
* member of hpf-sudo
|
||||
* authorized_keys = heath, first
|
||||
* heath
|
||||
* normal user
|
||||
* /usr/bin/bash
|
||||
* member of hpf-sudo
|
||||
* authorized_keys = heath
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
@@ -61,21 +80,6 @@
|
||||
# use: systemd
|
||||
|
||||
|
||||
- name: Copy a new sudoers file into place, after passing validation with visudo
|
||||
ansible.builtin.template:
|
||||
src: /mine/sudoers
|
||||
dest: /etc/sudoers
|
||||
validate: /usr/sbin/visudo -cf %s
|
||||
|
||||
- name: Update sshd configuration safely, avoid locking yourself out
|
||||
ansible.builtin.template:
|
||||
src: etc/ssh/sshd_config.j2
|
||||
dest: /etc/ssh/sshd_config
|
||||
owner: root
|
||||
group: root
|
||||
mode: '0600'
|
||||
validate: /usr/sbin/sshd -t -f %s
|
||||
backup: yes
|
||||
|
||||
|
||||
proxmox-clients
|
||||
@@ -85,7 +89,6 @@ hw:
|
||||
pve-kvm:
|
||||
|
||||
|
||||
users: first, heath, hpf-ans
|
||||
|
||||
~heath/.ssh/heath ## WARNING - SeCrEt! - Make sure this is not in the repo! - Does this need to be on every machine?
|
||||
~heath/.ssh/authorized_keys
|
||||
|
||||
Reference in New Issue
Block a user