ansible-edda/plays/roles/system_base/tasks/include/root.yml

11 lines
243 B
YAML
Raw Normal View History

- name: "root : disable root shell"
ansible.builtin.user:
name: "root"
shell: "/usr/sbin/nologin"
- name: "root : disable su for non-wheel users"
ansible.builtin.copy:
src: "./root/su"
dest: "/etc/pam.d/su"
mode: 0644