- Timestamp:
- 24 Apr 2016, 15:05:32 (9 years ago)
- File:
-
- 1 edited
Legend:
- Unmodified
- Added
- Removed
-
main/waeup-ansible/bootstrap.yml
r13848 r13849 17 17 deploy_user: 'deploy' 18 18 deploy_public_key: "{{ lookup('file', 'files/id-deploy.pub') }}" 19 20 handlers: 21 - name: "restart sshd" 22 service: 23 name="ssh" 24 enabled=yes 25 state=restarted 26 19 27 tasks: 20 21 28 - name: "bootstrap | create 'deploy' user" 22 29 user: … … 44 51 regexp='^HostKey /etc/ssh/ssh_host_dsa_key' 45 52 state=present 53 notify: "restart sshd" 46 54 47 55 - name: "bootstrap | disable ecdsa keys in sshd_config" … … 52 60 regexp='^HostKey /etc/ssh/ssh_host_ecdsa_key' 53 61 state=present 62 notify: "restart sshd" 54 63 55 64 - name: "bootstrap | set key bits in sshd_config to 4096" … … 60 69 regexp='^ServerKeyBits 1024' 61 70 state=present 71 notify: "restart sshd" 62 72 63 73 - name: "bootstrap | remove short moduli (<2048 bits) from /etc/ssh/moduli" … … 65 75 dest=/etc/ssh/moduli 66 76 regexp='^([0-9]+\s){4}(1[0-9]{3}\s)' 67 68 - name: "bootstrap | restart sshd" 69 service: 70 name="ssh" 71 enabled=yes 72 state=restarted 77 notify: "restart sshd"
Note: See TracChangeset for help on using the changeset viewer.