new readme + cleanup

This commit is contained in:
holger 2026-07-15 18:41:17 +02:00
parent afeb33ebf0
commit a51ac359db
2 changed files with 26 additions and 24 deletions

View file

@ -44,42 +44,57 @@ The 'private' part should NEVER leave the user's PC.
## ssh:
Check permissions in the users home. All files must be owned by the user,
# sudo find ~alice -ls
```bash
sudo find ~alice -ls
4 drwxr-x--- 6 alice alice 4096 Jul 15 16:59 /home/alice
4 drwx------ 2 alice alice 4096 Jul 15 16:58 /home/alice/.ssh
4 -rw------- 1 alice alice 709 Jul 15 16:58 /home/alice/.ssh/authorized_keys
```
(only showing the important files ) Note, ssh may fail, if permission are too open, DONT do chmod 777 ...
check groups: ( look for ssh_login )
# id alice
```bash
id alice
uid=1005(alice) gid=1007(alice) groups=1007(alice),27(sudo),1005(ssh_login),1006(admin),1010(floss_sudo),1011(floss_admin)
```
check that sshd is running
# sudo systemctl status ssh # (or ps -ef | grep sshd )
```bash
sudo systemctl status ssh # (or ps -ef | grep sshd )
and the config is ok:
# sudo sshd -t ( no output is good )
sudo sshd -t # ( no output is good )
restart with:
# sudo systemctl status ssh
sudo systemctl status ssh
```
## sudo:
check groups ( look for floss_sudo and/or floss_admin )
```bash
id alice
uid=1005(alice) gid=1007(alice) groups=1007(alice),27(sudo),1005(ssh_login),1006(admin),1010(floss_sudo),1011(floss_admin)
```
check the sudoers file:
# visudo -cf /etc/sudoers.d/floss-sudo
```bash
visudo -cf /etc/sudoers.d/floss-sudo
/etc/sudoers.d/floss-sudo: parsed OK
```
Try to redeploy, if it was changed.
# About the role:
# Users Ansible Role
## Users Ansible Role
This role manages local Linux users, groups, SSH access, SSH keys, and sudo permissions.
The role is designed to be multi-distribution and does not rely on distro-specific groups such as `sudo` or `wheel`.
## Managed groups
The role uses these groups:
| Group | Purpose |
@ -91,12 +106,11 @@ The role uses these groups:
Additional groups can be added as required.
License
##License
-------
BSD
Author Information
##Author Information
------------------
version 1: holger + chatgpt

View file

@ -1,12 +0,0 @@
---
- name: Configure passwordless sudo for sudo group
ansible.builtin.copy:
dest: /etc/sudoers.d/floss-sudo
content: |
%sudo ALL=(ALL:ALL) NOPASSWD: ALL
owner: root
group: root
mode: "0440"
validate: "/usr/sbin/visudo -cf %s"