Skip to content
Snippets Groups Projects
Commit 3c776bcb authored by Jörg Sachse's avatar Jörg Sachse
Browse files

fix: explicitely set permissions/owners for .ssh directories of SFTP chroot...

fix: explicitely set permissions/owners for .ssh directories of SFTP chroot user to make sure upload/auth via publickey works fine (this breaks again and again)
parent 654f1e67
No related branches found
No related tags found
No related merge requests found
...@@ -11,10 +11,24 @@ ...@@ -11,10 +11,24 @@
block: block:
- name: separate Berechtigungen für SFTP-chroot setzen - name: separate Berechtigungen für SFTP-chroot setzen
file: file:
path: "/home/{{ vault_sftp_upload_user }}/" path: "{{ item.path }}"
mode: "0750" mode: "{{ item.mode }}"
owner: "root" owner: "{{ item.owner }}"
group: "{{ vault_sftp_upload_group }}" group: "{{ item.group }}"
loop:
- path: "/home/{{ vault_sftp_upload_user }}/"
mode: "0750"
owner: "root"
group: "{{ vault_sftp_upload_group }}"
- path: "/home/{{ vault_sftp_upload_user }}/.ssh/"
mode: "0700"
owner: "{{ vault_sftp_upload_user }}"
group: "{{ vault_sftp_upload_group }}"
- path: "/home/{{ vault_sftp_upload_user }}/.ssh/authorized_keys"
mode: "0600"
owner: "{{ vault_sftp_upload_user }}"
group: "{{ vault_sftp_upload_group }}"
- name: Konfiguration fuer SFTP-Server einspielen (1/3) - name: Konfiguration fuer SFTP-Server einspielen (1/3)
blockinfile: blockinfile:
path: "/etc/ssh/sshd_config" path: "/etc/ssh/sshd_config"
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment