#4 # How to use: ## Adding a new user To create a ssh key pair on the new users PC: ```bash ssh-keygen -f new_floss_key ``` The 'private' part should NEVER leave the user's PC. ( It is a good idea to add a keyphrase to protect the key, if the client PC is ever stolen or hacked.) - You only need: new_floss_key.pub - open inventory/group_vars/all/users.yaml - add a new entry: ```yaml - username: alice groups: - ssh_login - floss_sudo - floss_admin ssh_keys: - ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAA... alice@laptop - replace this ^^^^ line, with new_floss_key.pub... ``` ### Deploy with: ```bash - ansible-playbook site.yaml ``` ## Delete user: - open inventory/group_vars/all/users.yaml - add: ```yaml - username: alice __state: absent__ - run: ```yaml ansible-playbook site.yaml ``` # Troubleshoot: ## ssh: Check permissions in the users home. All files must be owned by the user, ```bash sudo find ~alice -ls 4 drwxr-x--- 6 alice alice 4096 Jul 15 16:59 /home/alice 4 drwx------ 2 alice alice 4096 Jul 15 16:58 /home/alice/.ssh 4 -rw------- 1 alice alice 709 Jul 15 16:58 /home/alice/.ssh/authorized_keys ``` (only showing the important files ) Note, ssh may fail, if permission are too open, DONT do chmod 777 ... check groups: ( look for ssh_login ) ```bash id alice uid=1005(alice) gid=1007(alice) groups=1007(alice),27(sudo),1005(ssh_login),1006(admin),1010(floss_sudo),1011(floss_admin) ``` check that sshd is running ```bash sudo systemctl status ssh # (or ps -ef | grep sshd ) and the config is ok: sudo sshd -t # ( no output is good ) restart with: sudo systemctl status ssh ``` ## sudo: check groups ( look for floss_sudo and/or floss_admin ) ```bash id alice uid=1005(alice) gid=1007(alice) groups=1007(alice),27(sudo),1005(ssh_login),1006(admin),1010(floss_sudo),1011(floss_admin) ``` check the sudoers file: ```bash visudo -cf /etc/sudoers.d/floss-sudo /etc/sudoers.d/floss-sudo: parsed OK ``` Try to redeploy, if it was changed. # About the role: ## Users Ansible Role This role manages local Linux users, groups, SSH access, SSH keys, and sudo permissions. The role is designed to be multi-distribution and does not rely on distro-specific groups such as `sudo` or `wheel`. ## Managed groups The role uses these groups: | Group | Purpose | |---|---| | `ssh_login` | Users in this group are allowed to log in via SSH | | `floss_sudo` | Users in this group get passwordless sudo/root access | | `floss_admin` | Users in this group get limited administrative commands | Additional groups can be added as required. ##License ------- BSD ##Author Information ------------------ version 1: holger + chatgpt