fabric: disable less-than-sane Cumulus SSH default options
Why no ed25519 keys?
This commit is contained in:
		
							parent
							
								
									82b10e8133
								
							
						
					
					
						commit
						c741b90981
					
				
					 2 changed files with 14 additions and 0 deletions
				
			
		| 
						 | 
				
			
			@ -1,3 +1,9 @@
 | 
			
		|||
- name: reload sshd
 | 
			
		||||
  service:
 | 
			
		||||
    name: ssh@mgmt
 | 
			
		||||
    state: reloaded
 | 
			
		||||
  when: "'handler' not in ansible_skip_tags"
 | 
			
		||||
 | 
			
		||||
- name: reload switchd
 | 
			
		||||
  service:
 | 
			
		||||
    name: switchd
 | 
			
		||||
| 
						 | 
				
			
			
 | 
			
		|||
| 
						 | 
				
			
			@ -64,6 +64,14 @@
 | 
			
		|||
    mode: 0644
 | 
			
		||||
  notify: reload interfaces
 | 
			
		||||
 | 
			
		||||
- name: Unoverride Cumulus SSH options
 | 
			
		||||
  lineinfile:
 | 
			
		||||
    path: /etc/ssh/sshd_config
 | 
			
		||||
    regexp: '^(PubkeyAcceptedKeyTypes .*)'
 | 
			
		||||
    line: '#\1'
 | 
			
		||||
    backrefs: yes
 | 
			
		||||
  notify: reload sshd
 | 
			
		||||
 | 
			
		||||
- name: Disable SSH in default VRF
 | 
			
		||||
  service:
 | 
			
		||||
    name: ssh
 | 
			
		||||
| 
						 | 
				
			
			
 | 
			
		|||
		Loading…
	
	Add table
		Add a link
		
	
		Reference in a new issue