Added a filter plugin that will handle the GRUB password hashing for you

Signed-off-by: Jeffrey van Pelt <jeff@vanpelt.one>
This commit is contained in:
Jeffrey van Pelt 2025-06-04 17:59:22 +02:00
parent f70821bf7e
commit d08e7380d6
No known key found for this signature in database
GPG key ID: 39EFF6AA1F5B11A0
4 changed files with 79 additions and 8 deletions

View file

@ -13,7 +13,7 @@
- NIST800-53R5_AC-3
ansible.builtin.copy:
dest: /boot/grub2/user.cfg
content: "GRUB2_PASSWORD={{ rhel9cis_bootloader_password_hash }}" # noqa template-instead-of-copy
content: "GRUB2_PASSWORD={{ rhel9cis_bootloader_password_hash | default(rhel9cis_bootloader_password | grub_hash) }}" # noqa template-instead-of-copy
owner: root
group: root
mode: 'go-rwx'