--- - name: install pam_url package: name=pam_url state=present tags: - packages when: ansible_distribution_major_version|int < 22 - name: install pam_url dnf: name=pam_url state=present tags: - packages when: ansible_distribution_major_version|int > 21 - name: /etc/pki/tls/private/totpcgi.pem copy: src="{{ private }}/files/2fa-certs/keys/{{ inventory_hostname }}.pem" dest=/etc/pki/tls/private/totpcgi.pem mode=0400 tags: - config - name: /etc/pki/tls/private/totpcgi-ca.cert copy: src="{{ private }}/files/2fa-certs/keys/ca.crt" dest=/etc/pki/tls/private/totpcgi-ca.cert mode=0400 tags: - config - name: /etc/pam_url.conf - split for staging/phx2/everyone else template: src={{ item }} dest=/etc/pam_url.conf mode=0644 with_first_found: - "{{ files }}/2fa/pam_url.conf.{{ inventory_hostname }}" - "{{ files }}/2fa/pam_url.conf.{{ ansible_domain }}" - "{{ files }}/2fa/pam_url.conf.{{ datacenter }}" - "{{ files }}/2fa/pam_url.conf.j2" tags: - config - pam_url - name: /etc/pam.d/sudo copy: src={{ item }} dest=/etc/pam.d/sudo mode=0644 with_first_found: - "{{ files }}/2fa/sudo.pam.{{ inventory_hostname }}" - "{{ files }}/2fa/sudo.pam.{{ ansible_domain }}" - "{{ files }}/2fa/sudo.pam" tags: - config