new readme + cleanup

This commit is contained in:
holger 2026-07-15 18:41:17 +02:00
parent afeb33ebf0
commit a51ac359db
2 changed files with 26 additions and 24 deletions

View file

@ -44,42 +44,57 @@ The 'private' part should NEVER leave the user's PC.
## ssh: ## ssh:
Check permissions in the users home. All files must be owned by the user, Check permissions in the users home. All files must be owned by the user,
# sudo find ~alice -ls ```bash
sudo find ~alice -ls
4 drwxr-x--- 6 alice alice 4096 Jul 15 16:59 /home/alice 4 drwxr-x--- 6 alice alice 4096 Jul 15 16:59 /home/alice
4 drwx------ 2 alice alice 4096 Jul 15 16:58 /home/alice/.ssh 4 drwx------ 2 alice alice 4096 Jul 15 16:58 /home/alice/.ssh
4 -rw------- 1 alice alice 709 Jul 15 16:58 /home/alice/.ssh/authorized_keys 4 -rw------- 1 alice alice 709 Jul 15 16:58 /home/alice/.ssh/authorized_keys
```
(only showing the important files ) Note, ssh may fail, if permission are too open, DONT do chmod 777 ... (only showing the important files ) Note, ssh may fail, if permission are too open, DONT do chmod 777 ...
check groups: ( look for ssh_login ) check groups: ( look for ssh_login )
# id alice ```bash
id alice
uid=1005(alice) gid=1007(alice) groups=1007(alice),27(sudo),1005(ssh_login),1006(admin),1010(floss_sudo),1011(floss_admin) uid=1005(alice) gid=1007(alice) groups=1007(alice),27(sudo),1005(ssh_login),1006(admin),1010(floss_sudo),1011(floss_admin)
```
check that sshd is running check that sshd is running
# sudo systemctl status ssh # (or ps -ef | grep sshd ) ```bash
sudo systemctl status ssh # (or ps -ef | grep sshd )
and the config is ok: and the config is ok:
# sudo sshd -t ( no output is good ) sudo sshd -t # ( no output is good )
restart with: restart with:
# sudo systemctl status ssh sudo systemctl status ssh
```
## sudo: ## sudo:
check groups ( look for floss_sudo and/or floss_admin ) check groups ( look for floss_sudo and/or floss_admin )
```bash
id alice
uid=1005(alice) gid=1007(alice) groups=1007(alice),27(sudo),1005(ssh_login),1006(admin),1010(floss_sudo),1011(floss_admin)
```
check the sudoers file: check the sudoers file:
# visudo -cf /etc/sudoers.d/floss-sudo ```bash
visudo -cf /etc/sudoers.d/floss-sudo
/etc/sudoers.d/floss-sudo: parsed OK /etc/sudoers.d/floss-sudo: parsed OK
```
Try to redeploy, if it was changed. Try to redeploy, if it was changed.
# About the role: # About the role:
# Users Ansible Role ## Users Ansible Role
This role manages local Linux users, groups, SSH access, SSH keys, and sudo permissions. This role manages local Linux users, groups, SSH access, SSH keys, and sudo permissions.
The role is designed to be multi-distribution and does not rely on distro-specific groups such as `sudo` or `wheel`. The role is designed to be multi-distribution and does not rely on distro-specific groups such as `sudo` or `wheel`.
## Managed groups ## Managed groups
The role uses these groups: The role uses these groups:
| Group | Purpose | | Group | Purpose |
@ -91,12 +106,11 @@ The role uses these groups:
Additional groups can be added as required. Additional groups can be added as required.
License ##License
------- -------
BSD BSD
Author Information ##Author Information
------------------ ------------------
version 1: holger + chatgpt version 1: holger + chatgpt

View file

@ -1,12 +0,0 @@
---
- name: Configure passwordless sudo for sudo group
ansible.builtin.copy:
dest: /etc/sudoers.d/floss-sudo
content: |
%sudo ALL=(ALL:ALL) NOPASSWD: ALL
owner: root
group: root
mode: "0440"
validate: "/usr/sbin/visudo -cf %s"