dotfiles/dot_scripts/ansible/mac_playbook.yaml

25 lines
776 B
YAML
Raw Normal View History

2019-06-22 16:12:13 +00:00
---
- hosts: localhost
connection: local
become_method: sudo
become: yes
tasks:
- name: Ensure yubikey is needed for authentication at login screen
2019-06-22 16:12:13 +00:00
lineinfile:
path: "{{ item }}"
2019-06-22 16:12:13 +00:00
regexp: '^auth.*pam_yubico.so.*'
line: "auth required /usr/local/lib/security/pam_yubico.so mode=challenge-response"
insertbefore: "^account required pam_opendirectory.so"
with_items:
- /etc/pam.d/screensaver
- /etc/pam.d/authorization
- name: Ensure touch id is enough to authenticate with sudo
lineinfile:
path: "{{ item }}"
regexp: '^auth.*sufficient.*pam_tid.so.*'
line: "auth sufficient pam_tid.so"
insertafter: "^#.*"
with_items:
- /etc/pam.d/sudo