REC-417 Disable root login by changing root shell 63/1663/1
authorferenc.argay <ferenc.argay@nokia.com>
Fri, 27 Sep 2019 12:53:54 +0000 (14:53 +0200)
committerferenc.argay <ferenc.argay@nokia.com>
Fri, 27 Sep 2019 12:55:45 +0000 (14:55 +0200)
Change-Id: I6ebfa359694b2ec5c3162fd85a7d7a960a79c248

roles/ops-hardening/tasks/main.yaml

index d56e893..71218a0 100644 (file)
 - name: "Direct root Logins Not Allowed"
   shell: echo > /etc/securetty
 
+- name: Change 'root' shell to nologin
+  user:
+    name: root
+    shell: /sbin/nologin
+
+- name: Lock 'root' password
+  user:
+    name: root
+    password: '!!'
+
 #
 # Configure IPv6
 #