Wazuh manager: Enable or not ossec-authd (default: disabled)
This commit is contained in:
parent
aaca36420d
commit
63f3eb3c24
@ -2,6 +2,7 @@
|
|||||||
wazuh_manager_fqdn: "wazuh-server"
|
wazuh_manager_fqdn: "wazuh-server"
|
||||||
|
|
||||||
wazuh_manager_config:
|
wazuh_manager_config:
|
||||||
|
enable_authd: false
|
||||||
email_notification: no
|
email_notification: no
|
||||||
mail_to:
|
mail_to:
|
||||||
- admin@example.net
|
- admin@example.net
|
||||||
|
|||||||
@ -106,7 +106,10 @@
|
|||||||
owner=root
|
owner=root
|
||||||
group=root
|
group=root
|
||||||
mode=0755
|
mode=0755
|
||||||
when: ansible_service_mgr == "upstart" and ansible_os_family != "CoreOS"
|
when:
|
||||||
|
- ansible_service_mgr == "upstart"
|
||||||
|
- ansible_os_family != "CoreOS"
|
||||||
|
- wazuh_manager_config.enable_authd == true
|
||||||
tags:
|
tags:
|
||||||
- init
|
- init
|
||||||
- config
|
- config
|
||||||
@ -115,11 +118,20 @@
|
|||||||
template:
|
template:
|
||||||
src: ossec-authd.service
|
src: ossec-authd.service
|
||||||
dest: /lib/systemd/system/ossec-authd.service
|
dest: /lib/systemd/system/ossec-authd.service
|
||||||
when: ansible_service_mgr == "systemd" and ansible_os_family != "CoreOS"
|
when:
|
||||||
|
- ansible_service_mgr == "systemd"
|
||||||
|
- ansible_os_family != "CoreOS"
|
||||||
|
- wazuh_manager_config.enable_authd == true
|
||||||
tags:
|
tags:
|
||||||
- init
|
- init
|
||||||
- config
|
- config
|
||||||
|
|
||||||
|
- name: Ensure ossec-authd service is started and enabled
|
||||||
|
service: name=ossec-authd enabled=yes state=started
|
||||||
|
when: wazuh_manager_config.enable_authd == true
|
||||||
|
tags:
|
||||||
|
- config
|
||||||
|
|
||||||
- name: Wazuh-api User
|
- name: Wazuh-api User
|
||||||
template:
|
template:
|
||||||
src: api_user.j2
|
src: api_user.j2
|
||||||
@ -145,7 +157,7 @@
|
|||||||
shell: /usr/bin/base64 /var/ossec/agentless/.passlist_tmp > /var/ossec/agentless/.passlist && rm /var/ossec/agentless/.passlist_tmp
|
shell: /usr/bin/base64 /var/ossec/agentless/.passlist_tmp > /var/ossec/agentless/.passlist && rm /var/ossec/agentless/.passlist_tmp
|
||||||
when: agentless_creeds is defined
|
when: agentless_creeds is defined
|
||||||
|
|
||||||
- name: Ensure Wazuh Manager, wazuh api and ossec-authd service is started and enabled
|
- name: Ensure Wazuh Manager, wazuh api service is started and enabled
|
||||||
service:
|
service:
|
||||||
name: "{{ item }}"
|
name: "{{ item }}"
|
||||||
enabled: yes
|
enabled: yes
|
||||||
@ -153,7 +165,8 @@
|
|||||||
with_items:
|
with_items:
|
||||||
- wazuh-manager
|
- wazuh-manager
|
||||||
- wazuh-api
|
- wazuh-api
|
||||||
- ossec-authd
|
tags:
|
||||||
|
- config
|
||||||
|
|
||||||
- include: "RMRedHat.yml"
|
- include: "RMRedHat.yml"
|
||||||
when: ansible_os_family == "RedHat"
|
when: ansible_os_family == "RedHat"
|
||||||
|
|||||||
Loading…
Reference in New Issue
Block a user