ansible-edda/tasks/root-shell.yml

11 lines
195 B
YAML

- name: Disable root shell
user:
name: root
shell: /usr/sbin/nologin
- name: Disable su for non-wheel users
copy:
src: ./root/etc/pam.d/su
dest: /etc/pam.d/su
mode: 0644