Commit ba309011 authored by Tobias Stein
Disable sshd PasswordAuth

* Add handler reload ssh
* Add task to disable ssh PasswordAuthentication
parent 9449d1a0
......@@ -7,6 +7,12 @@
name: cron
state: restarted
- name: reload ssh
become: true
name: ssh
state: reloaded
- name: trigger udev
become: true
command: udevadm trigger
......@@ -31,4 +31,19 @@
- dhparam
- dhparam_create
- name: "Security - disable ssh password auth"
become: true
path: "/etc/ssh/sshd_config"
regexp: '#PasswordAuthentication (yes|no)$'
line: "PasswordAuthentication no"
- ssh is defined
- ssh.PasswordAuthentication is defined
- ssh.PasswordAuthentication |bool == false
- ssh_password_auth
- reload ssh
# vim: et:noai:ts=2:sw=2
