Sudoers include defined as file

This commit is contained in:
danielkubat 2020-12-12 03:28:20 +01:00
parent 458d5db418
commit af0b20f7a8
2 changed files with 11 additions and 10 deletions

View File

@ -0,0 +1,2 @@
Defaults use_pty
Defaults logfile="/var/log/sudo.log"

View File

@ -7,15 +7,15 @@
sysctl_config: '{{ sysctl_config | combine(sysctl_overwrite) }}' sysctl_config: '{{ sysctl_config | combine(sysctl_overwrite) }}'
when: sysctl_overwrite | default() when: sysctl_overwrite | default()
- name: sysctl - name: Kernel parameters
sysctl: sysctl:
name: '{{ item.key }}' name: "{{ item.key }}"
value: '{{ item.value }}' value: "{{ item.value }}"
state: present state: present
ignoreerrors: true ignoreerrors: true
sysctl_set: true sysctl_set: true
sysctl_file: /etc/sysctl.d/99-ansible.conf sysctl_file: /etc/sysctl.d/99-ansible.conf
with_dict: '{{ sysctl_config }}' with_dict: "{{ sysctl_config }}"
tags: tags:
- harden - harden
- kernel - kernel
@ -103,6 +103,7 @@
tags: tags:
- harden - harden
# TODO: Use pamd module to establish password policy
- name: pwquality - minlen - name: pwquality - minlen
lineinfile: lineinfile:
line: "minlen = 14" line: "minlen = 14"
@ -188,7 +189,7 @@
name: "{{ item }}" name: "{{ item }}"
enabled: false enabled: false
state: stopped state: stopped
with_items: "{{ disable_svc }}" loop: "{{ disable_svc }}"
register: service_check register: service_check
failed_when: service_check is failed and not 'Could not find the requested service' in service_check.msg failed_when: service_check is failed and not 'Could not find the requested service' in service_check.msg
tags: tags:
@ -230,15 +231,13 @@
tags: tags:
- harden - harden
- name: cis sudoers configuration - name: CIS sudoers configuration
copy: copy:
dest: /etc/sudoers.d/cis src: "etc/sudoers.d/cis"
dest: "/etc/sudoers.d/cis"
owner: root owner: root
group: root group: root
mode: '0440' mode: '0440'
content: |
Defaults use_pty
Defaults logfile="/var/log/sudo.log"
tags: tags:
- harden - harden