diff --git a/roles/sshd/tasks/algorithms.yml b/roles/sshd/tasks/algorithms.yml index 65008c9..4de445f 100644 --- a/roles/sshd/tasks/algorithms.yml +++ b/roles/sshd/tasks/algorithms.yml @@ -15,7 +15,7 @@ path: /etc/ssh/sshd_config regexp: '^HostKey /etc/ssh/ssh_host_ed25519_key' line: 'HostKey /etc/ssh/ssh_host_ed25519_key' - validate: sshd -f %s -t + validate: /usr/sbin/sshd -t -f %s - name: "Algorithms | enable the RSA authentication algorithm" notify: "Restart ssh" @@ -23,7 +23,7 @@ path: /etc/ssh/sshd_config regexp: '^HostKey /etc/ssh/ssh_host_rsa_key' line: 'HostKey /etc/ssh/ssh_host_rsa_key' - validate: sshd -f %s -t + validate: /usr/sbin/sshd -t -f %s - name: "Algorithms | disable the ECDSA algorithm (deemed to be less safe)" notify: "Restart ssh" @@ -31,7 +31,7 @@ path: /etc/ssh/sshd_config regexp: '^HostKey /etc/ssh/ssh_host_ecdsa_key' state: absent - validate: sshd -f %s -t + validate: /usr/sbin/sshd -t -f %s - name: "Algorithms | disable the DSA algorithm (considered to be defunct)" notify: "Restart ssh" @@ -39,4 +39,4 @@ path: /etc/ssh/sshd_config regexp: '^HostKey /etc/ssh/ssh_host_dsa_key' state: absent - validate: sshd -f %s -t + validate: /usr/sbin/sshd -t -f %s diff --git a/roles/sshd/tasks/main.yml b/roles/sshd/tasks/main.yml index 2af59f3..a24c5cb 100644 --- a/roles/sshd/tasks/main.yml +++ b/roles/sshd/tasks/main.yml @@ -23,4 +23,4 @@ path: /etc/ssh/sshd_config regexp: '^#?LogLevel' line: 'LogLevel VERBOSE' - validate: sshd -f %s -t + validate: /usr/sbin/sshd -t -f %s diff --git a/roles/sshd/tasks/restrictions.yml b/roles/sshd/tasks/restrictions.yml index 86e3703..1d6f0c2 100644 --- a/roles/sshd/tasks/restrictions.yml +++ b/roles/sshd/tasks/restrictions.yml @@ -36,7 +36,7 @@ path: /etc/ssh/sshd_config regexp: '^#?UsePAM' line: "UsePAM {{ sshd_disable_pam | ternary('no', 'yes') }}" - validate: sshd -f %s -t + validate: /usr/sbin/sshd -t -f %s - name: "Restrictions | ensure the SSHD config is restricted to the root user" notify: "Restart ssh" diff --git a/roles/sshd/tasks/whitelists.yml b/roles/sshd/tasks/whitelists.yml index 9a3d410..03f0136 100644 --- a/roles/sshd/tasks/whitelists.yml +++ b/roles/sshd/tasks/whitelists.yml @@ -6,7 +6,7 @@ path: /etc/ssh/sshd_config regexp: '^#?\s*AllowUsers\s+' line: "AllowUsers {{ sshd_allow_users }}" - validate: sshd -f %s -t + validate: /usr/sbin/sshd -t -f %s - name: "Configure AllowGroups" when: sshd_allow_groups is defined @@ -15,4 +15,4 @@ path: /etc/ssh/sshd_config regexp: '^#?\s*AllowGroups\s+' line: "AllowGroups {{ sshd_allow_groups }}" - validate: sshd -f %s -t + validate: /usr/sbin/sshd -t -f %s