diff --git a/molecule/docker/Dockerfile-ubuntu2404 b/molecule/docker/Dockerfile-ubuntu2404 new file mode 100644 index 0000000..e6cb946 --- /dev/null +++ b/molecule/docker/Dockerfile-ubuntu2404 @@ -0,0 +1,36 @@ +FROM ubuntu:24.04 + +ENV container=docker \ + LANGUAGE=en_US.UTF-8 \ + LANG=en_US.UTF-8 \ + LC_ALL=en_US.UTF-8 \ + TERM=xterm \ + DEBIAN_FRONTEND="noninteractive" + +RUN find /etc/systemd/system \ + /lib/systemd/system \ + -path '*.wants/*' \ + -not -name '*journald*' \ + -not -name '*systemd-tmpfiles*' \ + -not -name '*systemd-user-sessions*' \ + -print0 | xargs -0 rm -vf + +RUN apt-get update && \ + INSTALL_PKGS="openssh-server rsyslog software-properties-common python3 python3-pip python3-setuptools curl sudo bash ca-certificates iproute2 python3-apt aptitude apt-utils locales dbus gnupg systemd systemd-cron" && \ + apt-get install -y $INSTALL_PKGS && \ + localedef -f UTF-8 -i en_US en_US.UTF-8 + +RUN cp /bin/true /sbin/agetty + +RUN mkdir -p /etc/systemd/system/systemd-timesyncd.service.d/ +RUN bash -c 'echo -e "[Unit]\nConditionVirtualization=" > /etc/systemd/system/systemd-timesyncd.service.d/override.conf' + +# Créer un répertoire temporaire pour Ansible avec les permissions correctes +RUN mkdir -p /tmp/ansible && \ + chmod 777 /tmp/ansible + +STOPSIGNAL SIGRTMIN+3 + +VOLUME [ "/sys/fs/cgroup" ] + +CMD ["/lib/systemd/systemd"] diff --git a/tasks/ssh.yml b/tasks/ssh.yml index 525523c..7dff040 100755 --- a/tasks/ssh.yml +++ b/tasks/ssh.yml @@ -16,6 +16,27 @@ state: present notify: Restart ssh +# KbdInteractiveAuthentication only exists since OpenSSH 8.7 (Ubuntu 22.04+); +# older OS (Ubuntu <22.04, CentOS 7/8) need the legacy ChallengeResponseAuthentication name, +# otherwise sshd fails to parse the config. +# Only Ubuntu is checked here because the EL versions this role supports (see meta/main.yml: +# 7 and 8) both ship OpenSSH < 8.7 and always fall into the else branch. Revisit this condition +# if support for EL 9+ (OpenSSH >= 8.7) is ever added. +- name: Set keyboard-interactive authentication option name based on OS support + set_fact: + ssh_kbd_interactive_option_name: >- + {{ 'KbdInteractiveAuthentication' if ansible_distribution == 'Ubuntu' and ansible_distribution_version is version('22', '>=') else + 'ChallengeResponseAuthentication' }} + +# Prevents PAM from bypassing PasswordAuthentication=no via keyboard-interactive prompts +- name: Disallow keyboard-interactive authentication + lineinfile: + dest: /etc/ssh/sshd_config + regexp: "^(# *)?(ChallengeResponseAuthentication|KbdInteractiveAuthentication)" + line: "{{ ssh_kbd_interactive_option_name }} no" + state: present + notify: Restart ssh + - name: Allow agent forwarding lineinfile: dest: /etc/ssh/sshd_config diff --git a/tasks/users.yml b/tasks/users.yml index e415a12..a954b32 100755 --- a/tasks/users.yml +++ b/tasks/users.yml @@ -16,6 +16,14 @@ validate: visudo -cf %s when: basic_passwordless_sudo +- name: Log commands run through sudo with a pty (CVE-2005-4890) + lineinfile: + dest: /etc/sudoers + state: present + regexp: '^Defaults\s+use_pty' + line: 'Defaults use_pty' + validate: visudo -cf %s + - name: Creating users groups (1) group: name: "{{ item }}"