ipa/client: Don't log IPA admin password

Signed-off-by: Nils Philippsen <nils@redhat.com>
This commit is contained in:
Nils Philippsen 2021-02-12 18:17:57 +01:00
parent f1f7d6d929
commit 193aefa78e
3 changed files with 8 additions and 1 deletions

View file

@ -14,6 +14,7 @@
state: present state: present
group: group:
- sysadmin-main - sysadmin-main
no_log: true
loop: "{{ ipa_server_admin_passwords | dict2items }}" loop: "{{ ipa_server_admin_passwords | dict2items }}"
- name: "Enable usergroup/sysadmin-main HBAC rule" - name: "Enable usergroup/sysadmin-main HBAC rule"
@ -22,6 +23,7 @@
name: "usergroup/sysadmin-main" name: "usergroup/sysadmin-main"
ipaadmin_password: "{{ item.value }}" ipaadmin_password: "{{ item.value }}"
state: enabled state: enabled
no_log: true
loop: "{{ ipa_server_admin_passwords | dict2items }}" loop: "{{ ipa_server_admin_passwords | dict2items }}"
- name: "Disable allow_all HBAC rule" - name: "Disable allow_all HBAC rule"
@ -30,6 +32,7 @@
name: allow_all name: allow_all
ipaadmin_password: "{{ item.value }}" ipaadmin_password: "{{ item.value }}"
state: disabled state: disabled
no_log: true
loop: "{{ ipa_server_admin_passwords | dict2items }}" loop: "{{ ipa_server_admin_passwords | dict2items }}"
- name: "Let everybody run sudo" - name: "Let everybody run sudo"
@ -43,6 +46,7 @@
usercategory: "all" usercategory: "all"
hbacsvcgroup: hbacsvcgroup:
- Sudo - Sudo
no_log: true
loop: "{{ ipa_server_admin_passwords | dict2items }}" loop: "{{ ipa_server_admin_passwords | dict2items }}"
- name: Add the sshd HBAC service in IPA - name: Add the sshd HBAC service in IPA
@ -51,6 +55,7 @@
name: sshd name: sshd
description: SSH daemon description: SSH daemon
ipaadmin_password: "{{ item.value }}" ipaadmin_password: "{{ item.value }}"
no_log: true
loop: "{{ ipa_server_admin_passwords | dict2items }}" loop: "{{ ipa_server_admin_passwords | dict2items }}"
- name: Add the shell-access service group in IPA - name: Add the shell-access service group in IPA
@ -61,6 +66,7 @@
ipaadmin_password: "{{ item.value }}" ipaadmin_password: "{{ item.value }}"
hbacsvc: hbacsvc:
- sshd - sshd
no_log: true
loop: "{{ ipa_server_admin_passwords | dict2items }}" loop: "{{ ipa_server_admin_passwords | dict2items }}"
## Host group- & host-specific rules ## Host group- & host-specific rules

View file

@ -29,7 +29,7 @@
# }, ... # }, ...
# } # }
# #
# ipa_server_passwords: -> # ipa_server_admin_passwords ->
# { # {
# "ipa_server_1": "ipa_password_1", # "ipa_server_1": "ipa_password_1",
# "ipa_server_2": "ipa_password_2", # "ipa_server_2": "ipa_password_2",

View file

@ -14,6 +14,7 @@
runasgroupcategory: "all" runasgroupcategory: "all"
group: group:
- sysadmin-main - sysadmin-main
no_log: true
loop: "{{ ipa_server_admin_passwords | dict2items }}" loop: "{{ ipa_server_admin_passwords | dict2items }}"
- name: Give certain groups sudo access to anything per host group - name: Give certain groups sudo access to anything per host group