2019-11-02 18:10:39 +00:00
|
|
|
---
|
2022-01-26 20:02:28 +00:00
|
|
|
- name: Gather package facts
|
2024-02-18 12:22:43 +00:00
|
|
|
ansible.builtin.package_facts:
|
2022-01-26 20:02:28 +00:00
|
|
|
check_mode: False
|
|
|
|
|
2024-02-18 12:22:43 +00:00
|
|
|
- name: Hardening sshd config
|
|
|
|
ansible.builtin.template:
|
|
|
|
src: etc/ssh/sshd_config.j2
|
|
|
|
dest: /etc/ssh/sshd_config
|
|
|
|
owner: root
|
|
|
|
group: root
|
|
|
|
mode: "0600"
|
|
|
|
notify: __sshd_restart
|
2019-11-02 18:10:39 +00:00
|
|
|
|
2024-02-18 12:22:43 +00:00
|
|
|
- name: Check if /etc/ssh/moduli contains weak DH parameters
|
|
|
|
ansible.builtin.shell: awk '$5 < {{ sshd_moduli_minimum }}' /etc/ssh/moduli
|
|
|
|
register: __sshd_register_moduli
|
|
|
|
changed_when: False
|
|
|
|
check_mode: False
|
2019-11-02 18:10:39 +00:00
|
|
|
|
2024-02-18 12:22:43 +00:00
|
|
|
- name: Remove all small primes
|
|
|
|
ansible.builtin.shell:
|
|
|
|
awk '$5 >= {{ sshd_moduli_minimum }}' /etc/ssh/moduli > /etc/ssh/moduli.new ;
|
|
|
|
[ -r /etc/ssh/moduli.new -a -s /etc/ssh/moduli.new ] && mv /etc/ssh/moduli.new /etc/ssh/moduli || true
|
2024-08-19 14:06:14 +00:00
|
|
|
register: __sshd_register_moduli
|
|
|
|
changed_when: __sshd_register_moduli.rc != 0
|
2024-02-18 12:22:43 +00:00
|
|
|
notify: __sshd_restart
|
|
|
|
when: __sshd_register_moduli.stdout
|
2019-11-02 18:10:39 +00:00
|
|
|
|
2024-02-18 12:22:43 +00:00
|
|
|
- name: Create SSH usergroup
|
|
|
|
ansible.builtin.group:
|
|
|
|
name: "{{ item }}"
|
|
|
|
state: present
|
|
|
|
loop: "{{ sshd_allow_groups }}"
|
2022-01-26 20:02:28 +00:00
|
|
|
|
2024-02-18 12:22:43 +00:00
|
|
|
- name: Configure SSH crypto policy usage
|
|
|
|
ansible.builtin.template:
|
|
|
|
src: etc/sysconfig/sshd.j2
|
|
|
|
dest: /etc/sysconfig/sshd
|
|
|
|
owner: root
|
|
|
|
group: root
|
|
|
|
mode: "0640"
|
|
|
|
when: ('crypto-policies' in ansible_facts.packages)
|
2024-09-16 08:23:43 +00:00
|
|
|
|
|
|
|
- name: Ensure seport matches sshd config
|
2024-09-29 12:15:58 +00:00
|
|
|
community.general.seport:
|
2024-09-16 08:23:43 +00:00
|
|
|
ports: "{{ sshd_port }}"
|
|
|
|
proto: "tcp"
|
|
|
|
setype: "ssh_port_t"
|
|
|
|
state: "present"
|
|
|
|
when:
|
|
|
|
- ansible_selinux is defined
|
|
|
|
- ansible_selinux.status == "enabled"
|