security setting role 추가 및 script 수정

This commit is contained in:
ByeonJungHun
2024-01-10 16:14:53 +09:00
parent 349cd3ff7a
commit b1f72b0a10
3 changed files with 30 additions and 2 deletions

View File

@@ -0,0 +1,26 @@
---
- name: shadow mode change
file:
path: /etc/shadow
mode: 0400
- name: hosts mode change
file:
path: /etc/hosts
#mode: u=rw,g=r,o=r
mode: 0600
- name: rsyslog mode change
file:
path: /etc/rsyslog.conf
mode: 0640
- name: crontab mode change [1]
file:
path: /usr/bin/crontab
mode: 0750
- name: crontab mode change [2]
file:
path: /bin/crontab
mode: 0640

View File

@@ -5,4 +5,6 @@
- include: all_setting_root_ssh.yml
- include: debian_setting_password_rule.yml
when: ansible_facts.os_family == 'Debian'
when: ansible_facts.os_family == 'Debian'
- include: all_setting_mode_change.yml