security.yml 1.8 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061
  1. - name: Install auto upgrades package
  2. action: ${ansible_pkg_mgr} pkg=unattended-upgrades state=installed update_cache=yes
  3. when_boolean: ${with_auto_upgrade}
  4. - name: Configure auto upgrades
  5. action: template src=${item} dest=/etc/apt/apt.conf.d/20auto-upgrades owner=root group=root mode=0644
  6. first_available_file:
  7. - apt/auto-upgrades.${ansible_lsb.codename}.j2
  8. - apt/auto-upgrades.j2
  9. when_boolean: ${with_auto_upgrade}
  10. - name: Install logcheck packages
  11. action: ${ansible_pkg_mgr} pkg=${item} state=installed update_cache=yes
  12. with_items:
  13. - logcheck
  14. - logcheck-database
  15. when_boolean: ${with_logcheck}
  16. - name: Install local configuration files for logcheck
  17. action: copy src=logcheck/${item}_local dest=/etc/logcheck/ignore.d.server/${item}_local owner=root group=root mode=0644
  18. with_items:
  19. - ansible
  20. - amavisd-new
  21. - bind
  22. - dovecot
  23. - dropbear
  24. - git-daemon
  25. - ipmi
  26. - kernel
  27. - libpam-modules
  28. - mon
  29. - noip2
  30. - ntp
  31. - openvpn
  32. - php
  33. - postfix
  34. - pure-ftpd
  35. - redir
  36. - rsyslog
  37. - smartd
  38. - spamd
  39. - sshd
  40. - svn
  41. - sympa
  42. when_boolean: ${with_logcheck}
  43. - name: Update logcheck cron job
  44. action: template src=cron/logcheck.j2 dest=/etc/cron.d/logcheck owner=root group=root mode=0644
  45. when_boolean: ${with_logcheck}
  46. - name: Update rkhunter default/init parameters
  47. action: template src=rkhunter/default.j2 dest=/etc/default/rkhunter owner=root group=root mode=0644
  48. when_boolean: ${with_rkhunter}
  49. - name: Update rkhunter configuration
  50. action: template src=rkhunter/${ansible_lsb.codename}.conf.j2 dest=/etc/rkhunter.conf owner=root group=root mode=0644
  51. when_boolean: ${with_rkhunter}
  52. - name: Update chkrootkit configuration
  53. action: template src=chkrootkit/chkrootkit.conf.j2 dest=/etc/chkrootkit.conf owner=root group=root mode=0644
  54. when_boolean: ${with_chkrootkit}