fabric: disable less-than-sane Cumulus SSH default options
Why no ed25519 keys?
This commit is contained in:
parent
82b10e8133
commit
c741b90981
|
@ -1,3 +1,9 @@
|
|||
- name: reload sshd
|
||||
service:
|
||||
name: ssh@mgmt
|
||||
state: reloaded
|
||||
when: "'handler' not in ansible_skip_tags"
|
||||
|
||||
- name: reload switchd
|
||||
service:
|
||||
name: switchd
|
||||
|
|
|
@ -64,6 +64,14 @@
|
|||
mode: 0644
|
||||
notify: reload interfaces
|
||||
|
||||
- name: Unoverride Cumulus SSH options
|
||||
lineinfile:
|
||||
path: /etc/ssh/sshd_config
|
||||
regexp: '^(PubkeyAcceptedKeyTypes .*)'
|
||||
line: '#\1'
|
||||
backrefs: yes
|
||||
notify: reload sshd
|
||||
|
||||
- name: Disable SSH in default VRF
|
||||
service:
|
||||
name: ssh
|
||||
|
|
Loading…
Reference in a new issue