davidalger.sshd_lockdown
Ansible Role: sshd-lockdown
Replaces sshd config on EL 7 with a secured sshd config template which adheres to the following practices:
PermitRootLoginis disabled.PasswordAuthenticationis disabled.GSSAPIAuthenticationis disabled.sshusersgroup is added andsshdconfigured such that only members of this group will be authorized.
Requirements
None.
Role Variables
sshd_lockdown_config_template: sshd_config
Change this to specify an alternate template to use for the sshd_config file deployed to the server.
sshd_additional_config_lines: []
Add lines of additional custom config to sshd service.
sshd_sftp_subsystem: /usr/libexec/openssh/sftp-server
Variable for specifying alternate subsystem for use with sftp.
sshd_access_users:
- someotheruser
- another_user
- unprivileged_ssh_suer
List of users added to the sshusers group for access to the system.
Dependencies
None.
Example Playbook
- hosts: all
roles:
- { role: davidalger.sshd_lockdown }
Example Playbook with Legacy Admin
For use on servers managed by Rackspace, the legacy rack user must be detected and added to the sshusers group and allowed an exception allowing it to use password authentication.
- hosts: all
vars:
sshd_pass_auth_exception: true
sshd_pass_auth_exception_user: rack
roles:
- { role: davidalger.sshd_lockdown }
License
This work is licensed under the MIT license. See LICENSE file for details.
Author Information
This role was created in 2016 by David Alger with contributions from Matt Johnson.
Install
ansible-galaxy install davidalger.sshd_lockdownLicense
mit
Downloads
181
Owner
Principal SRE, Software Engineer, Infrastructure, DevOps, Magento Master, Cloud Architect, AWS, GCP, Terraform, Ansible, Kubernetes
