117 lines
2.7 KiB
Markdown
117 lines
2.7 KiB
Markdown
|
|
# How to use:
|
|
|
|
## Adding a new user
|
|
To create a ssh key pair on the new users PC:
|
|
```bash
|
|
ssh-keygen -f new_floss_key
|
|
```
|
|
|
|
The 'private' part should NEVER leave the user's PC.
|
|
( It is a good idea to add a keyphrase to protect the key, if the client PC is ever stolen or hacked.)
|
|
|
|
- You only need: new_floss_key.pub
|
|
- open inventory/group_vars/all/users.yaml
|
|
- add a new entry:
|
|
```yaml
|
|
- username: alice
|
|
groups:
|
|
- ssh_login
|
|
- floss_sudo
|
|
- floss_admin
|
|
ssh_keys:
|
|
- ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAA... alice@laptop
|
|
- replace this ^^^^ line, with new_floss_key.pub...
|
|
```
|
|
|
|
### Deploy with:
|
|
```bash
|
|
- ansible-playbook site.yaml
|
|
```
|
|
|
|
## Delete user:
|
|
- open inventory/group_vars/all/users.yaml
|
|
- add:
|
|
```yaml
|
|
- username: alice
|
|
__state: absent__
|
|
- run:
|
|
```yaml
|
|
ansible-playbook site.yaml
|
|
```
|
|
|
|
|
|
# Troubleshoot:
|
|
|
|
## ssh:
|
|
Check permissions in the users home. All files must be owned by the user,
|
|
```bash
|
|
sudo find ~alice -ls
|
|
4 drwxr-x--- 6 alice alice 4096 Jul 15 16:59 /home/alice
|
|
4 drwx------ 2 alice alice 4096 Jul 15 16:58 /home/alice/.ssh
|
|
4 -rw------- 1 alice alice 709 Jul 15 16:58 /home/alice/.ssh/authorized_keys
|
|
```
|
|
(only showing the important files ) Note, ssh may fail, if permission are too open, DONT do chmod 777 ...
|
|
|
|
check groups: ( look for ssh_login )
|
|
```bash
|
|
id alice
|
|
uid=1005(alice) gid=1007(alice) groups=1007(alice),27(sudo),1005(ssh_login),1006(admin),1010(floss_sudo),1011(floss_admin)
|
|
```
|
|
|
|
check that sshd is running
|
|
```bash
|
|
sudo systemctl status ssh # (or ps -ef | grep sshd )
|
|
|
|
and the config is ok:
|
|
sudo sshd -t # ( no output is good )
|
|
|
|
restart with:
|
|
sudo systemctl status ssh
|
|
```
|
|
|
|
## sudo:
|
|
check groups ( look for floss_sudo and/or floss_admin )
|
|
|
|
```bash
|
|
id alice
|
|
uid=1005(alice) gid=1007(alice) groups=1007(alice),27(sudo),1005(ssh_login),1006(admin),1010(floss_sudo),1011(floss_admin)
|
|
```
|
|
|
|
check the sudoers file:
|
|
```bash
|
|
visudo -cf /etc/sudoers.d/floss-sudo
|
|
|
|
/etc/sudoers.d/floss-sudo: parsed OK
|
|
```
|
|
|
|
Try to redeploy, if it was changed.
|
|
|
|
|
|
# About the role:
|
|
## Users Ansible Role
|
|
|
|
This role manages local Linux users, groups, SSH access, SSH keys, and sudo permissions.
|
|
|
|
The role is designed to be multi-distribution and does not rely on distro-specific groups such as `sudo` or `wheel`.
|
|
|
|
## Managed groups
|
|
The role uses these groups:
|
|
|
|
| Group | Purpose |
|
|
|---|---|
|
|
| `ssh_login` | Users in this group are allowed to log in via SSH |
|
|
| `floss_sudo` | Users in this group get passwordless sudo/root access |
|
|
| `floss_admin` | Users in this group get limited administrative commands |
|
|
|
|
Additional groups can be added as required.
|
|
|
|
|
|
##License
|
|
-------
|
|
BSD
|
|
|
|
##Author Information
|
|
------------------
|
|
version 1: holger + chatgpt
|
|
|