diff --git a/tasks/unpriv-user.yml b/tasks/unpriv-user.yml index 1e8c409..91f659c 100644 --- a/tasks/unpriv-user.yml +++ b/tasks/unpriv-user.yml @@ -10,28 +10,28 @@ skeleton: /etc/skel append: true -- name: Check the primary key for the unprivileged user - ansible.posix.authorized_key: - user: "{{ interactive_user }}" - key: "{{ lookup('file', '../home/ssh-keys/' ~ interactive_user ~ '/' ~ interactive_user ~ '-yubi-1.pub') }}" - state: present - exclusive: false - register: setkey +# - name: Check the primary key for the unprivileged user +# ansible.posix.authorized_key: +# user: "{{ interactive_user }}" +# key: "{{ lookup('file', '../home/ssh-keys/' ~ interactive_user ~ '/' ~ interactive_user ~ '-yubi-1.pub') }}" +# state: present +# exclusive: false +# register: setkey -- name: Re-set the primary key as exclusive, if we found that the key was not present yet # noqa: no-handler - when: setkey.changed - ansible.posix.authorized_key: - user: "{{ interactive_user }}" - key: "{{ lookup('file', '../home/ssh-keys/' ~ interactive_user ~ '/' ~ interactive_user ~ '-yubi-1.pub') }}" - state: present - exclusive: true +# - name: Re-set the primary key as exclusive, if we found that the key was not present yet # noqa: no-handler +# when: setkey.changed +# ansible.posix.authorized_key: +# user: "{{ interactive_user }}" +# key: "{{ lookup('file', '../home/ssh-keys/' ~ interactive_user ~ '/' ~ interactive_user ~ '-yubi-1.pub') }}" +# state: present +# exclusive: true -- name: Set the secondary key for the unprivileged user - ansible.posix.authorized_key: - user: "{{ interactive_user }}" - key: "{{ lookup('file', '../home/ssh-keys/' ~ interactive_user ~ '/' ~ interactive_user ~ '-yubi-2.pub') }}" - state: present - exclusive: false +# - name: Set the secondary key for the unprivileged user +# ansible.posix.authorized_key: +# user: "{{ interactive_user }}" +# key: "{{ lookup('file', '../home/ssh-keys/' ~ interactive_user ~ '/' ~ interactive_user ~ '-yubi-2.pub') }}" +# state: present +# exclusive: false - name: Install required package to become unprivileged users ansible.builtin.apt: