public-health-ch/ansible/roles/dev-sec.os-hardening/tasks/main.yml
2017-04-24 14:22:51 +02:00

43 lines
747 B
YAML

---
- name: add the OS specific variables
include_vars: "{{ ansible_os_family }}.yml"
tags: always
- include: limits.yml
tags: limits
- include: login_defs.yml
tags: login_defs
- include: minimize_access.yml
tags: minimize_acces
- include: pam.yml
tags: pam
- include: profile.yml
tags: profile
- include: securetty.yml
tags: securetty
- include: suid_sgid.yml
when: os_security_suid_sgid_enforce
tags: suid_sgid
- include: sysctl.yml
tags: sysctl
- include: user_accounts.yml
tags: user_accounts
- include: rhosts.yml
tags: rhosts
- include: yum.yml
when: ansible_os_family == 'RedHat'
tags: yum
- include: apt.yml
when: ansible_distribution == 'Debian' or ansible_distribution == 'Ubuntu'
tags: apt