diff --git a/roles/server/tasks/sshd.yaml b/roles/server/tasks/sshd.yaml index 244182c..d741709 100644 --- a/roles/server/tasks/sshd.yaml +++ b/roles/server/tasks/sshd.yaml @@ -7,20 +7,16 @@ replace: "{{ item.value }}" notify: [restart-sshd] loop: - - name: disable root login - regex: "^.*PermitRootLogin (yes|no).*$" + - regex: "^.*PermitRootLogin (yes|no).*$" value: PermitRootLogin no - - name: disable password auth - regex: "^.*PasswordAuthentication (yes|no).*$" + - regex: "^.*PasswordAuthentication (yes|no).*$" value: PasswordAuthentication no - - name: disable challenge response auth - regex: "^.*ChallengeResponseAuthentication (yes|no).*$" + - regex: "^.*ChallengeResponseAuthentication (yes|no).*$" value: ChallengeResponseAuthentication no - - name: disable GSSAPI auth - regex: "^.*GSSAPIAuthentication (yes|no).*$" + - regex: "^.*GSSAPIAuthentication (yes|no).*$" value: GSSAPIAuthentication no loop_control: - label: "{{ item.name }}" + label: "{{ item.value }}" - name: Disable dynamic MOTD on debian systems when: ansible_os_family == "Debian"