new readme + cleanup
This commit is contained in:
parent
afeb33ebf0
commit
a51ac359db
2 changed files with 26 additions and 24 deletions
36
README.md
36
README.md
|
|
@ -44,42 +44,57 @@ The 'private' part should NEVER leave the user's PC.
|
|||
|
||||
## ssh:
|
||||
Check permissions in the users home. All files must be owned by the user,
|
||||
# sudo find ~alice -ls
|
||||
```bash
|
||||
sudo find ~alice -ls
|
||||
4 drwxr-x--- 6 alice alice 4096 Jul 15 16:59 /home/alice
|
||||
4 drwx------ 2 alice alice 4096 Jul 15 16:58 /home/alice/.ssh
|
||||
4 -rw------- 1 alice alice 709 Jul 15 16:58 /home/alice/.ssh/authorized_keys
|
||||
```
|
||||
(only showing the important files ) Note, ssh may fail, if permission are too open, DONT do chmod 777 ...
|
||||
|
||||
check groups: ( look for ssh_login )
|
||||
# id alice
|
||||
```bash
|
||||
id alice
|
||||
uid=1005(alice) gid=1007(alice) groups=1007(alice),27(sudo),1005(ssh_login),1006(admin),1010(floss_sudo),1011(floss_admin)
|
||||
```
|
||||
|
||||
check that sshd is running
|
||||
# sudo systemctl status ssh # (or ps -ef | grep sshd )
|
||||
```bash
|
||||
sudo systemctl status ssh # (or ps -ef | grep sshd )
|
||||
|
||||
and the config is ok:
|
||||
# sudo sshd -t ( no output is good )
|
||||
sudo sshd -t # ( no output is good )
|
||||
|
||||
restart with:
|
||||
# sudo systemctl status ssh
|
||||
sudo systemctl status ssh
|
||||
```
|
||||
|
||||
## sudo:
|
||||
check groups ( look for floss_sudo and/or floss_admin )
|
||||
|
||||
```bash
|
||||
id alice
|
||||
uid=1005(alice) gid=1007(alice) groups=1007(alice),27(sudo),1005(ssh_login),1006(admin),1010(floss_sudo),1011(floss_admin)
|
||||
```
|
||||
|
||||
check the sudoers file:
|
||||
# visudo -cf /etc/sudoers.d/floss-sudo
|
||||
```bash
|
||||
visudo -cf /etc/sudoers.d/floss-sudo
|
||||
|
||||
/etc/sudoers.d/floss-sudo: parsed OK
|
||||
```
|
||||
|
||||
Try to redeploy, if it was changed.
|
||||
|
||||
|
||||
# About the role:
|
||||
# Users Ansible Role
|
||||
## Users Ansible Role
|
||||
|
||||
This role manages local Linux users, groups, SSH access, SSH keys, and sudo permissions.
|
||||
|
||||
The role is designed to be multi-distribution and does not rely on distro-specific groups such as `sudo` or `wheel`.
|
||||
|
||||
## Managed groups
|
||||
|
||||
The role uses these groups:
|
||||
|
||||
| Group | Purpose |
|
||||
|
|
@ -91,12 +106,11 @@ The role uses these groups:
|
|||
Additional groups can be added as required.
|
||||
|
||||
|
||||
License
|
||||
##License
|
||||
-------
|
||||
|
||||
BSD
|
||||
|
||||
Author Information
|
||||
##Author Information
|
||||
------------------
|
||||
version 1: holger + chatgpt
|
||||
|
||||
|
|
|
|||
|
|
@ -1,12 +0,0 @@
|
|||
|
||||
---
|
||||
- name: Configure passwordless sudo for sudo group
|
||||
ansible.builtin.copy:
|
||||
dest: /etc/sudoers.d/floss-sudo
|
||||
content: |
|
||||
%sudo ALL=(ALL:ALL) NOPASSWD: ALL
|
||||
owner: root
|
||||
group: root
|
||||
mode: "0440"
|
||||
validate: "/usr/sbin/visudo -cf %s"
|
||||
|
||||
Loading…
Add table
Reference in a new issue