new readme + cleanup
This commit is contained in:
parent
afeb33ebf0
commit
a51ac359db
2 changed files with 26 additions and 24 deletions
36
README.md
36
README.md
|
|
@ -44,42 +44,57 @@ The 'private' part should NEVER leave the user's PC.
|
||||||
|
|
||||||
## ssh:
|
## ssh:
|
||||||
Check permissions in the users home. All files must be owned by the user,
|
Check permissions in the users home. All files must be owned by the user,
|
||||||
# sudo find ~alice -ls
|
```bash
|
||||||
|
sudo find ~alice -ls
|
||||||
4 drwxr-x--- 6 alice alice 4096 Jul 15 16:59 /home/alice
|
4 drwxr-x--- 6 alice alice 4096 Jul 15 16:59 /home/alice
|
||||||
4 drwx------ 2 alice alice 4096 Jul 15 16:58 /home/alice/.ssh
|
4 drwx------ 2 alice alice 4096 Jul 15 16:58 /home/alice/.ssh
|
||||||
4 -rw------- 1 alice alice 709 Jul 15 16:58 /home/alice/.ssh/authorized_keys
|
4 -rw------- 1 alice alice 709 Jul 15 16:58 /home/alice/.ssh/authorized_keys
|
||||||
|
```
|
||||||
(only showing the important files ) Note, ssh may fail, if permission are too open, DONT do chmod 777 ...
|
(only showing the important files ) Note, ssh may fail, if permission are too open, DONT do chmod 777 ...
|
||||||
|
|
||||||
check groups: ( look for ssh_login )
|
check groups: ( look for ssh_login )
|
||||||
# id alice
|
```bash
|
||||||
|
id alice
|
||||||
uid=1005(alice) gid=1007(alice) groups=1007(alice),27(sudo),1005(ssh_login),1006(admin),1010(floss_sudo),1011(floss_admin)
|
uid=1005(alice) gid=1007(alice) groups=1007(alice),27(sudo),1005(ssh_login),1006(admin),1010(floss_sudo),1011(floss_admin)
|
||||||
|
```
|
||||||
|
|
||||||
check that sshd is running
|
check that sshd is running
|
||||||
# sudo systemctl status ssh # (or ps -ef | grep sshd )
|
```bash
|
||||||
|
sudo systemctl status ssh # (or ps -ef | grep sshd )
|
||||||
|
|
||||||
and the config is ok:
|
and the config is ok:
|
||||||
# sudo sshd -t ( no output is good )
|
sudo sshd -t # ( no output is good )
|
||||||
|
|
||||||
restart with:
|
restart with:
|
||||||
# sudo systemctl status ssh
|
sudo systemctl status ssh
|
||||||
|
```
|
||||||
|
|
||||||
## sudo:
|
## sudo:
|
||||||
check groups ( look for floss_sudo and/or floss_admin )
|
check groups ( look for floss_sudo and/or floss_admin )
|
||||||
|
|
||||||
|
```bash
|
||||||
|
id alice
|
||||||
|
uid=1005(alice) gid=1007(alice) groups=1007(alice),27(sudo),1005(ssh_login),1006(admin),1010(floss_sudo),1011(floss_admin)
|
||||||
|
```
|
||||||
|
|
||||||
check the sudoers file:
|
check the sudoers file:
|
||||||
# visudo -cf /etc/sudoers.d/floss-sudo
|
```bash
|
||||||
|
visudo -cf /etc/sudoers.d/floss-sudo
|
||||||
|
|
||||||
/etc/sudoers.d/floss-sudo: parsed OK
|
/etc/sudoers.d/floss-sudo: parsed OK
|
||||||
|
```
|
||||||
|
|
||||||
Try to redeploy, if it was changed.
|
Try to redeploy, if it was changed.
|
||||||
|
|
||||||
|
|
||||||
# About the role:
|
# About the role:
|
||||||
# Users Ansible Role
|
## Users Ansible Role
|
||||||
|
|
||||||
This role manages local Linux users, groups, SSH access, SSH keys, and sudo permissions.
|
This role manages local Linux users, groups, SSH access, SSH keys, and sudo permissions.
|
||||||
|
|
||||||
The role is designed to be multi-distribution and does not rely on distro-specific groups such as `sudo` or `wheel`.
|
The role is designed to be multi-distribution and does not rely on distro-specific groups such as `sudo` or `wheel`.
|
||||||
|
|
||||||
## Managed groups
|
## Managed groups
|
||||||
|
|
||||||
The role uses these groups:
|
The role uses these groups:
|
||||||
|
|
||||||
| Group | Purpose |
|
| Group | Purpose |
|
||||||
|
|
@ -91,12 +106,11 @@ The role uses these groups:
|
||||||
Additional groups can be added as required.
|
Additional groups can be added as required.
|
||||||
|
|
||||||
|
|
||||||
License
|
##License
|
||||||
-------
|
-------
|
||||||
|
|
||||||
BSD
|
BSD
|
||||||
|
|
||||||
Author Information
|
##Author Information
|
||||||
------------------
|
------------------
|
||||||
version 1: holger + chatgpt
|
version 1: holger + chatgpt
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -1,12 +0,0 @@
|
||||||
|
|
||||||
---
|
|
||||||
- name: Configure passwordless sudo for sudo group
|
|
||||||
ansible.builtin.copy:
|
|
||||||
dest: /etc/sudoers.d/floss-sudo
|
|
||||||
content: |
|
|
||||||
%sudo ALL=(ALL:ALL) NOPASSWD: ALL
|
|
||||||
owner: root
|
|
||||||
group: root
|
|
||||||
mode: "0440"
|
|
||||||
validate: "/usr/sbin/visudo -cf %s"
|
|
||||||
|
|
||||||
Loading…
Add table
Reference in a new issue