diff --git a/README.md b/README.md index 6349413..f25ce30 100644 --- a/README.md +++ b/README.md @@ -44,42 +44,57 @@ The 'private' part should NEVER leave the user's PC. ## ssh: Check permissions in the users home. All files must be owned by the user, - # sudo find ~alice -ls +```bash +sudo find ~alice -ls 4 drwxr-x--- 6 alice alice 4096 Jul 15 16:59 /home/alice 4 drwx------ 2 alice alice 4096 Jul 15 16:58 /home/alice/.ssh 4 -rw------- 1 alice alice 709 Jul 15 16:58 /home/alice/.ssh/authorized_keys +``` (only showing the important files ) Note, ssh may fail, if permission are too open, DONT do chmod 777 ... check groups: ( look for ssh_login ) - # id alice +```bash +id alice uid=1005(alice) gid=1007(alice) groups=1007(alice),27(sudo),1005(ssh_login),1006(admin),1010(floss_sudo),1011(floss_admin) +``` check that sshd is running - # sudo systemctl status ssh # (or ps -ef | grep sshd ) +```bash +sudo systemctl status ssh # (or ps -ef | grep sshd ) + and the config is ok: - # sudo sshd -t ( no output is good ) +sudo sshd -t # ( no output is good ) + restart with: - # sudo systemctl status ssh +sudo systemctl status ssh +``` ## sudo: check groups ( look for floss_sudo and/or floss_admin ) +```bash +id alice + uid=1005(alice) gid=1007(alice) groups=1007(alice),27(sudo),1005(ssh_login),1006(admin),1010(floss_sudo),1011(floss_admin) +``` + check the sudoers file: - # visudo -cf /etc/sudoers.d/floss-sudo - /etc/sudoers.d/floss-sudo: parsed OK +```bash +visudo -cf /etc/sudoers.d/floss-sudo + +/etc/sudoers.d/floss-sudo: parsed OK +``` Try to redeploy, if it was changed. # About the role: -# Users Ansible Role +## Users Ansible Role This role manages local Linux users, groups, SSH access, SSH keys, and sudo permissions. The role is designed to be multi-distribution and does not rely on distro-specific groups such as `sudo` or `wheel`. ## Managed groups - The role uses these groups: | Group | Purpose | @@ -91,12 +106,11 @@ The role uses these groups: Additional groups can be added as required. -License +##License ------- - BSD -Author Information +##Author Information ------------------ version 1: holger + chatgpt diff --git a/users/roles/users/tasks/sudoers.yaml~ b/users/roles/users/tasks/sudoers.yaml~ deleted file mode 100644 index 411a807..0000000 --- a/users/roles/users/tasks/sudoers.yaml~ +++ /dev/null @@ -1,12 +0,0 @@ - ---- -- name: Configure passwordless sudo for sudo group - ansible.builtin.copy: - dest: /etc/sudoers.d/floss-sudo - content: | - %sudo ALL=(ALL:ALL) NOPASSWD: ALL - owner: root - group: root - mode: "0440" - validate: "/usr/sbin/visudo -cf %s" -