security.yml 1.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657
  1. - name: Install auto upgrades package
  2. action: ${ansible_pkg_mgr} pkg=unattended-upgrades state=installed update_cache=yes
  3. when_boolean: ${with_auto_upgrade}
  4. - name: Configure auto upgrades
  5. action: template src=apt/auto-upgrades.j2 dest=/etc/apt/apt.conf.d/20auto-upgrades owner=root group=root mode=0644
  6. when_boolean: ${with_auto_upgrade}
  7. - name: Install logcheck packages
  8. action: ${ansible_pkg_mgr} pkg=${item} state=installed update_cache=yes
  9. with_items:
  10. - logcheck
  11. - logcheck-database
  12. when_boolean: ${with_logcheck}
  13. - name: Install local configuration files for logcheck
  14. action: copy src=logcheck/${item}_local dest=/etc/logcheck/ignore.d.server/${item}_local owner=root group=root mode=0644
  15. with_items:
  16. - ansible
  17. - bind
  18. - dovecot
  19. - dropbear
  20. - git-daemon
  21. - ipmi
  22. - kernel
  23. - libpam-modules
  24. - mon
  25. - noip2
  26. - ntp
  27. - openvpn
  28. - php
  29. - postfix
  30. - pure-ftpd
  31. - redir
  32. - rsyslog
  33. - smartd
  34. - spamd
  35. - sshd
  36. - svn
  37. - sympa
  38. when_boolean: ${with_logcheck}
  39. - name: Update logcheck cron job
  40. action: template src=cron/logcheck.j2 dest=/etc/cron.d/logcheck owner=root group=root mode=0644
  41. when_boolean: ${with_logcheck}
  42. - name: Update rkhunter default/init parameters
  43. action: template src=rkhunter/default.j2 dest=/etc/default/rkhunter owner=root group=root mode=0644
  44. when_boolean: ${with_rkhunter}
  45. - name: Update rkhunter configuration
  46. action: template src=rkhunter/${ansible_lsb.codename}.conf.j2 dest=/etc/rkhunter.conf owner=root group=root mode=0644
  47. when_boolean: ${with_rkhunter}
  48. - name: Update chkrootkit configuration
  49. action: template src=chkrootkit/chkrootkit.conf.j2 dest=/etc/chkrootkit.conf owner=root group=root mode=0644
  50. when_boolean: ${with_chkrootkit}