4
0
Fork 0

Check for existence of sshd_config.d/50-redhat.conf before trying to modify it

Signed-off-by: polski-g <polski_g@sent.at>
This commit is contained in:
polski_g 2025-05-08 11:17:29 -04:00 committed by polski-g
parent 9ee1498c98
commit f564135e72
No known key found for this signature in database
GPG key ID: C077F64D3FFD4D39
2 changed files with 10 additions and 0 deletions

View file

@ -276,6 +276,7 @@
notify: Restart sshd
- name: "5.1.10 | PATCH | Ensure sshd DisableForwarding is enabled | override"
when: discovered_sshd_50_redhat_file.stat.exists
ansible.builtin.lineinfile:
path: /etc/ssh/sshd_config.d/50-redhat.conf
regexp: ^(?i)(#|)\s*X11Forwarding
@ -298,6 +299,7 @@
- NIST800-53R5_IA-5
block:
- name: "5.1.11 | PATCH | Ensure sshd GSSAPIAuthentication is disabled | redhat file"
when: discovered_sshd_50_redhat_file.stat.exists
ansible.builtin.lineinfile:
path: /etc/ssh/sshd_config.d/50-redhat.conf
regexp: ^(?i)(#|)\s*GSSAPIAuthentication