{"repo":"geerlingguy/ansible-role-security","free":true,"listed":false,"github":"https://github.com/geerlingguy/ansible-role-security","clone":"git clone https://github.com/geerlingguy/ansible-role-security.git","description":"Ansible Role - Security","language":"Jinja","stars":958,"topics":["ansible","role","security","centos","rhel","linux","ubuntu","debian","fedora","redhat"],"license":"MIT","category":"security-tools","readme_excerpt":"Ansible Role: Security (Basics) First, a major, MAJOR caveat : the security of your servers is YOUR responsibility. If you think simply including this role and adding a firewall makes a server secure, then you're mistaken. Read up on Linux, network, and application security, and know that no matter how much you know, you can always make every part of your stack more secure. That being said, this role performs some basic security configuration on RedHat and Debian-based linux systems. It attempts to: - Install software to monitor bad SSH access (fail2ban) - Configure SSH to be more secure (disabling root login, requiring key-based authentication, and allowing a custom SSH port to be set) - Set up automatic updates (if configured to do so) There are a few other things you may or may not want to do (which are not included in this role) to make sure your servers are more secure, like: - Use logwatch or a centralized logging server to analyze and monitor log files - Securely configure user accounts and SSH keys (this role assumes you're not using password authentication or logging in as root) - Have a well-configured firewall (check out the geerlingguy.firewall role on Ansible Galaxy for a flexible example) Again: Your servers' security is your responsibility. Requirements For obvious reasons, sudo must be installed if you want to manage the sudoers file with this role. On RedHat/CentOS systems, make sure you have the EPEL repository installed (you can include the geerlingguy.repo","default_branch":null,"files":null,"tree":[],"storefront":"/r/geerlingguy","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/geerlingguy/ansible-role-security/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}