From 87a216322a8a858b35ffb1a426ebbadc1395c0df Mon Sep 17 00:00:00 2001 From: spmfox Date: Wed, 23 Apr 2025 22:22:39 -0400 Subject: Added handler logic in host role, added ssh hardening --- roles/host/tasks/ssh-harden.yml | 9 +++++++++ 1 file changed, 9 insertions(+) create mode 100644 roles/host/tasks/ssh-harden.yml (limited to 'roles/host/tasks/ssh-harden.yml') diff --git a/roles/host/tasks/ssh-harden.yml b/roles/host/tasks/ssh-harden.yml new file mode 100644 index 0000000..2df5bb2 --- /dev/null +++ b/roles/host/tasks/ssh-harden.yml @@ -0,0 +1,9 @@ +- name: Disable SSH password authentication + ansible.builtin.lineinfile: + dest: "/etc/ssh/sshd_config" + regexp: "^PasswordAuthentication" + line: "PasswordAuthentication no" + state: "present" + validate: "sshd -t -f %s" + notify: + - Restart sshd -- cgit