mirror of
https://github.com/ruanbekker/rpi-ansible.git
synced 2026-09-05 05:50:41 +02:00
add ssh hostkey deployment
This commit is contained in:
@@ -11,6 +11,7 @@
|
||||
tags:
|
||||
- raspi
|
||||
- sw
|
||||
- sshd
|
||||
|
||||
- name: store MAC address
|
||||
set_fact:
|
||||
@@ -18,6 +19,7 @@
|
||||
tags:
|
||||
- raspi
|
||||
- sw
|
||||
- sshd
|
||||
|
||||
- name: store system configuration
|
||||
set_fact:
|
||||
@@ -25,6 +27,7 @@
|
||||
tags:
|
||||
- raspi
|
||||
- sw
|
||||
- sshd
|
||||
|
||||
- name: set hostname
|
||||
shell: "raspi-config nonint do_hostname {{ myconfig.hostname }}"
|
||||
@@ -79,6 +82,7 @@
|
||||
- raspi
|
||||
|
||||
# Other tasks
|
||||
- include: sshd.yml
|
||||
- include: software.yml
|
||||
- include: users.yml
|
||||
- include: raspi-config.yml
|
||||
|
||||
@@ -0,0 +1,83 @@
|
||||
---
|
||||
# Set ssh host keys
|
||||
- name: initialize list of host keys to copy over
|
||||
set_fact:
|
||||
ssh_host_keyfiles: []
|
||||
tags: [ sshd ]
|
||||
|
||||
- name: find local copy of dsa host key
|
||||
delegate_to: localhost
|
||||
stat:
|
||||
path: roles/common/files/etc/ssh/ssh_host_dsa_key.{{ myconfig.hostname }}
|
||||
register: result
|
||||
tags: [ sshd ]
|
||||
|
||||
- name: add dsa key to list if found
|
||||
set_fact:
|
||||
ssh_host_keyfiles: "{{ ssh_host_keyfiles }} + [ 'etc/ssh/ssh_host_dsa_key.{{ myconfig.hostname }}' ]"
|
||||
when: result.stat.exists == true
|
||||
tags: [ sshd ]
|
||||
|
||||
- name: find local copy of rsa host key
|
||||
delegate_to: localhost
|
||||
stat:
|
||||
path: roles/common/files/etc/ssh/ssh_host_rsa_key.{{ myconfig.hostname }}
|
||||
register: result
|
||||
tags: [ sshd ]
|
||||
|
||||
- name: add rsa key to list if found
|
||||
set_fact:
|
||||
ssh_host_keyfiles: "{{ ssh_host_keyfiles }} + [ 'etc/ssh/ssh_host_rsa_key.{{ myconfig.hostname }}' ]"
|
||||
when: result.stat.exists == true
|
||||
tags: [ sshd ]
|
||||
|
||||
- name: find local copy of ed25519 host key
|
||||
delegate_to: localhost
|
||||
stat:
|
||||
path: roles/common/files/etc/ssh/ssh_host_ed25519_key.{{ myconfig.hostname }}
|
||||
register: result
|
||||
tags: [ sshd ]
|
||||
- name: add ed25519 key to list if found
|
||||
set_fact:
|
||||
ssh_host_keyfiles: "{{ ssh_host_keyfiles }} + [ 'etc/ssh/ssh_host_ed25519_key.{{ myconfig.hostname }}' ]"
|
||||
when: result.stat.exists == true
|
||||
tags: [ sshd ]
|
||||
|
||||
- name: find local copy of ecdsa host key
|
||||
delegate_to: localhost
|
||||
stat:
|
||||
path: roles/common/files/etc/ssh/ssh_host_ecdsa_key.{{ myconfig.hostname }}
|
||||
register: result
|
||||
tags: [ sshd ]
|
||||
- name: add ecdsa key to list if found
|
||||
set_fact:
|
||||
ssh_host_keyfiles: "{{ ssh_host_keyfiles }} + [ 'etc/ssh/ssh_host_ecdsa_key.{{ myconfig.hostname }}' ]"
|
||||
when: result.stat.exists == true
|
||||
tags: [ sshd ]
|
||||
|
||||
- name: set SSH host keys
|
||||
copy:
|
||||
src: "{{ item }}"
|
||||
dest: "/{{ item }}"
|
||||
owner: root
|
||||
group: root
|
||||
mode: '0600'
|
||||
with_items: "{{ ssh_host_keyfiles }}"
|
||||
register: result
|
||||
tags: [ sshd ]
|
||||
|
||||
- name: remove old SSH host public keys
|
||||
file:
|
||||
path: "/{{ item }}.pub"
|
||||
state: absent
|
||||
with_items: "{{ ssh_host_keyfiles }}"
|
||||
when: result is changed
|
||||
tags: [ sshd ]
|
||||
|
||||
- name: regenerate SSH host public keys
|
||||
shell:
|
||||
cmd: "ssh-keygen -y -f /{{ item }} > /{{ item }}.pub"
|
||||
creates: "/{{ item }}.pub"
|
||||
with_items: "{{ ssh_host_keyfiles }}"
|
||||
when: result is changed
|
||||
tags: [ sshd ]
|
||||
Reference in New Issue
Block a user